Engineer IV, Cyber DevSecOps
Job in
Rockville, Montgomery County, Maryland, 20849, USA
Listed on 2026-08-05
Listing for:
X-Energy, LLC
Full Time
position Listed on 2026-08-05
Job specializations:
-
IT/Tech
Cybersecurity, AWS, Cloud Computing: Infrastructure & Operations
Job Description & How to Apply Below
Job Overview
Provide security engineering support, cyber‑informed engineering support, and Dev Ops lifecycle management from a security perspective as a mid‑level (Level IV) engineer. Lead the integration of security practices into development and operations workflows leveraging AWS cloud infrastructure and Git Lab platforms to ensure security is embedded throughout the SDLC and OT environments.
Key Responsibilities- Support the design, implementation, and maintenance of secure CI/CD pipelines incorporating security scanning, vulnerability assessment, and compliance validation.
- Integrate security tools and practices into Dev Ops workflows, including SAST, DAST, SCA, container security, and infrastructure‑as‑code scanning.
- Contribute to cyber‑informed engineering by embedding security requirements into system design, architecture decisions, and operational technology environments under guidance of senior engineers.
- Develop and maintain security automation scripts, tools, and frameworks to enhance detection, response, and remediation capabilities.
- Collaborate with development teams to implement secure coding practices, conduct security code reviews, and provide remediation guidance with moderate independence.
- Assist in designing and implementing infrastructure security controls across AWS, including identity management, network segmentation, and secrets management.
- Support security incident response activities by providing technical expertise in forensic analysis, root cause determination, and remediation implementation.
- Contribute to establishing and maintaining security metrics, dashboards, and reporting mechanisms to track security posture across development and production environments.
- Support development and maintenance of documentation for security processes, procedures, and architectural decisions.
- Maintain professional demeanor and behavior at all times in all forms of communication.
- Perform other duties as assigned by manager.
- Bachelor’s degree in Computer Science, Cybersecurity, or related field.
- 3+ years Dev Ops/security experience.
- 1–2 years Dev Sec Ops experience.
- Security+ or equivalent;
Certified Dev Sec Ops Professional (CDP) (Required/Preferred). - Security certifications such as CISSP, CISM, AWS Security Specialty, Azure Security Engineer, or CKS (Preferred/Optional).
- Skills typically demonstrated by approximately 8–10 years of relevant experience.
- U.S. Citizenship and ability to obtain a Secret security clearance.
- AWS Certified Security – Specialty (strongly preferred).
- AWS Solutions Architect – Associate or Professional certification.
- Extensive hands‑on experience with AWS security services: IAM, Security Groups, NACLs, Guard Duty, Security Hub, Config, Cloud Trail, KMS, Secrets Manager, WAF, Shield, VPC security architecture.
- Deep proficiency with AWS infrastructure‑as‑code tools including Cloud Formation, AWS CDK, and Terraform.
- Strong experience with Git Lab CI/CD pipelines, Git Lab Runner configuration, pipeline security, artifact management, and Git Lab security scanning features.
- Experience architecting and implementing AWS‑native security controls for containerized workloads (ECS, EKS) and serverless architectures (Lambda, API Gateway).
- Experience implementing security automation and orchestration using Lambda, Step Functions, Event Bridge, and Systems Manager.
- Proficiency with AWS monitoring and logging for security operations using Cloud Watch, Log Insights, and SIEM integration.
- Proven track record of securing AWS network architectures:
Transit Gateway, Private Link, VPN, Direct Connect. - Experience with Git Lab administrative functions: user/group management, compliance frameworks, security policies, merge request approval workflows.
- Diverse enterprise experience across multiple organizational types.
- Experience with AWS compliance frameworks (SOC 2, FedRAMP, PCI‑DSS, NIST).
- Hands‑on experience with containerization security in AWS environments, including Docker hardening, ECR scanning, and EKS security best practices.
- Proficiency in scripting and automation using Python, Bash, or Power Shell for AWS security operations and Git Lab pipeline…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×