More jobs:
DevSecOps Engineer
Job in
Stafford, Stafford County, Virginia, 22554, USA
Listed on 2026-09-25
Listing for:
Wilcore Technologies, Inc.
Full Time
position Listed on 2026-09-25
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
We are hiring a Dev Sec Ops to support a pivotal federal program making a positive impact on millions of Americans’ daily lives.
What You’ll Be Doing- Design, implement, maintain, and document secure CI/CD pipelines using modern Dev Sec Ops practices.
- Develop and maintain Infrastructure as Code (IaC) solutions using AWS Cloud Formation.
- Build, configure, secure, and support AWS environments and serverless computing services.
- Integrate security controls, vulnerability scanning, and automated compliance checks throughout the software development lifecycle.
- Establish vulnerability patching and remediation plans and work directly with engineers to resolve identified findings.
- Develop and execute actionable Plans of Action and Milestones (POA&Ms), including priorities, owners, dependencies, target completion dates, and measurable milestones.
- Proactively track POA&M progress, identify blockers, and communicate changes to projected remediation timelines.
- Assess new security findings as they are identified and determine their scope, severity, ownership, dependencies, and required remediation actions.
- Identify duplicate, overlapping, inherited, or externally owned findings to prevent unnecessary remediation efforts.
- Determine when findings are outside the program’s control or result from externally imposed technical constraints and coordinate appropriate risk-acceptance or disposition requests.
- Develop level-of-effort estimates for core program POA&Ms and help prioritize remediation activities based on risk, effort, dependencies, and operational impact.
- Maintain an accurate, real-time dashboard or tracker for security findings, POA&Ms, remediation activities, risks, dependencies, owners, and target dates.
- Conduct or support Security Impact Assessments (SIAs) for proposed system, infrastructure, application, and configuration changes.
- Support activities required to achieve and maintain an ATO while ensuring program operations adhere to applicable federal software-development and cybersecurity requirements.
- Help reduce the program’s administrative and operational burden associated with managing ATOs and POA&Ms through automation, documentation, and repeatable processes.
- Implement Zero Trust best practices, including data tagging and other mechanisms that improve data tracking, classification, and sensitivity management.
- Collaborate with Dev Ops engineers to establish secure, modern development and data-science environments.
- Engage proactively with developers, infrastructure engineers, security personnel, product owners, program leadership, and external stakeholders to drive findings through resolution.
- Create and maintain technical documentation, remediation evidence, operating procedures, implementation plans, and security-related artifacts.
- Support and secure Linux-based development and production environments.
- Investigate Docker containers, container images, configurations, dependencies, and potential security vulnerabilities.
- Participate effectively in an Agile software-development environment.
- Perform other related duties as assigned.
- Hands-on experience designing, developing, and supporting CI/CD pipelines.
- Experience with Git Hub Actions, AWS Cloud Formation, Amazon Cloud Watch, or comparable technologies.
- Experience creating, configuring, and supporting AWS services, including ECS, S3, RDS, and Lambda.
- Experience developing and improving CI/CD scripts and automated services supporting software development and deployment.
- Experience identifying, assessing, prioritizing, and remediating infrastructure, application, container, and cloud-security vulnerabilities.
- Demonstrated experience developing vulnerability-patching and remediation plans.
- Experience managing or supporting POA&Ms, including defining corrective actions, owners, dependencies, milestones, target dates, and closure evidence.
- Ability to translate security findings into practical engineering tasks and work directly with technical teams through remediation and closure.
- Experience supporting ATO activities, Security Impact Assessments, or federal security-authorization processes.
- Knowledge of federal cybersecurity and secure software-development requirements.
- Experience with Infrastructure as Code and configuration-management practices.
- Experience supporting and securing Linux-based environments.
- Experience working with Docker and investigating container configurations and vulnerabilities.
- Understanding of Zero Trust principles and their application within cloud-based…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×