Site Reliability Engineer/DevSecOps Engineer
Listed on 2026-09-06
-
IT/Tech
Cybersecurity, Systems Engineer
Who We Are
Every organization runs on intelligence: years of accumulated knowledge, decisions, and context. As AI takes on more of that work, companies face a choice: rent that intelligence from vendors who keep the data, the context, and the results, or own it.
Open Teams exists to make ownership possible.
Founded by Travis Oliphant, creator of Num Py and Sci Py, and built by people with deep roots across the open-source ecosystem, including Num Py, Sci Py, PyTorch, and Jupyter, we help enterprises and governments build AI they control, govern, and evolve themselves.
If that sounds like your kind of work, we'd like to meet you.
Site Reliability Engineer / Dev Sec Ops EngineerLocation:
Washington, DC;
Denver, CO; or Colorado Springs, CO preferred (hybrid). Highly qualified candidates outside these locations may also be considered for unclassified work.
Work Authorization: U.S. citizenship required
Clearance:
An active TS/SCI clearance with CI polygraph is strongly preferred. Candidates without an active clearance may be considered for unclassified work but must be eligible to obtain and maintain a U.S. security clearance.
Salary Range: $145,000-$250,000 USD, dependent on experience level and location
About the RoleWe're looking for a SRE/Dev Sec Ops Engineer to build and own the secure delivery pipeline for an AI/ML platform deployed into tightly controlled environments. This is a role for someone who treats security as something you build into the delivery path, not something you inspect for at the end of it.
You own the supply chain end to end – pipelines that produce hardened, signed release artifacts with a software bill of materials attached, with scanning, policy enforcement, and secrets handling built into the path rather than bolted alongside it. That path has to survive promotion into isolated and limited-connectivity environments, which means it works when the network doesn't and can prove what it shipped when nobody can reach back to check.
It also has to produce the compliance evidence - audit and accreditation artifacts that fall out of the build automatically instead of getting assembled by hand under deadline.
Reliability comes with the territory. Once the platform is deployed, you're part of keeping it healthy: observability, alerting, and incident response are shared work on this team, and the person who built the release path is usually the one who can tell you what changed.
The engineers who do well here have worked inside a formal compliance framework and know the difference between a pipeline that passes a security review and one that produces the review. Experience packaging or promoting software into air-gapped or otherwise disconnected environments matters a lot - it's the part that's hardest to learn on the fly.
This position is contingent upon contract award. Travel of up to 15% may be required, primarily to Government facilities and between company locations. Unclassified work may be performed remotely, while classified promotion and validation activities require onsite work in an accredited facility and the appropriate security clearance.
Key Responsibilities- Build and operate the CI/CD pipeline that produces versioned, signed release packages with SBOM manifests, hardened container images, deployment runbooks, and validation procedures for each promotion gate
- Execute the recurring low-to-high promotion cadence through Government-approved transfer mechanisms, including cross-domain solution submission packages, and verify environment parity after each promotion
- Integrate vulnerability management, image signing, dependency scanning, and continuous monitoring into the pipeline so accreditation evidence is generated once and reused at each promotion
- Work with the program's security engineers to keep pipeline outputs aligned to the RMF body of evidence
- Define and track service level objectives, and build monitoring, logging, and alerting with tools such as Prometheus, Grafana, and Open Telemetry
- Lead incident response and run postmortems to closure
- Operate sanitized defect and telemetry feedback paths so issues observed in production environments are reproduced and fixed where the full toolchain is available
- Enforce the constraint that platform dependencies are limited to services confirmed available in the target environments, with development-only dependencies gated behind feature flags
- Maintain deployment runbooks, validation procedures, and operational documentation to a standard suitable for Government review and for execution by other cleared personnel
- U.S. citizenship and eligibility to obtain and maintain a U.S. security clearance
- 6+ years of experience in Dev Sec Ops , site reliability engineering, platform engineering, or production operations
- 3+ years of experience supporting Department of Defense, Intelligence Community, or similarly regulated programs
- Hands-on experience packaging or promoting software into classified, air-
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).