DevSecOps
Listed on 2026-09-28
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, AWS
Steer Bridge is a modern technology company delivering innovative, mission‑focused solutions to the U.S. Government and private sector. Leveraging deep expertise in federal acquisition, digital transformation, and emerging technologies, we deliver agile, commercial‑grade capabilities that accelerate operational effectiveness and drive measurable mission success.
At the core of Steer Bridge is our people—especially the veterans whose leadership, problem‑solving mindset, and commitment to excellence elevate every project we support. We don’t simply hire exceptional talent;
we cultivate it
, creating meaningful career pathways for veterans, military spouses, and professionals who share our passion for advancing technology and strengthening the missions we serve.
Steer Bridge is seeking a Dev Sec Ops Engineer to own the security infrastructure and automation behind a mission‑critical VA Disability Claims platform that supports Veterans and federal customers in AWS Gov Cloud. This role builds and runs the systems that security depends on: the log pipelines that feed our SIEM, the CI/CD and infrastructure‑as‑code pipelines that deploy every environment, and the scanning, patching, and security services deployed across our accounts.
The engineer partners closely with our security team, which monitors the environment, triages alerts, and leads incident response. This role makes sure that team has complete, reliable data and working tools, and turns their requirements into code, guardrails, and pipelines that run automatically. The engineer will also work with cloud engineers, solutions and security architects, application developers, and program leadership.
This is a hands‑on role. The ideal candidate writes Terraform and pipeline code, onboards new log sources end to end, keeps security tooling deployed and healthy, and fixes the root cause when a pipeline, agent, or integration breaks. They are comfortable reviewing a merge request, debugging a broken data connector, and documenting how a control is implemented.
This is a hybrid position based in Vienna, VA.
KEY RESPONSIBILITIES Security Log Pipelines- Own the end‑to‑end security log pipelines from AWS and SaaS sources into Microsoft Sentinel, including Cloud Trail, VPC flow logs, DNS query logs, Guard Duty, WAF, identity provider, and zero‑trust platform logs
- Onboard new log sources using native delivery paths (data collection endpoints and rules, S3 and SQS connectors, vendor streaming) and validate that data lands, parses, and stays complete
- Monitor pipeline health and ingestion gaps so a silent feed is caught and fixed before the security team loses visibility
- Manage log retention, centralization, and immutability in line with federal logging requirements
- Own the Git Lab CI/CD pipelines that plan and apply Terraform and Terragrunt across multiple AWS Gov Cloud accounts and organizations
- Build security gates into pipelines, including IaC scanning, secrets detection, container image scanning, and dependency and SBOM checks
- Harden the pipelines themselves: least‑privilege deployment roles, protected branches, approval rules, and state and secrets handling
- Standardize container build and release practices for ECS and Fargate workloads, including immutable image tags, signed and scanned images, and ECR lifecycle policies
- Maintain the security baseline across accounts, including IAM Identity Center permission sets, least‑privilege roles, encryption, and network segmentation
- Support zero‑trust access (Zscaler ZPA and ZIA) and inline inspection (Palo Alto VM‑Series) configuration and change management
- Document how controls are implemented in infrastructure, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).