DevSecOps Engineer

Saic

Arlington (VA)

Hybrid

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SAIC is seeking a DevSecOps Engineer to integrate security into the software development and delivery lifecycle. You will design, implement, and operate secure CI/CD pipelines, cloud infrastructure, automation, and security controls enabling rapid, safe software delivery.

The role requires hands-on engineering with expertise in application and cloud security, infrastructure as code, and modern software delivery practices.

Qualifications

  • Bachelor's degree with 5+ years of experience or Master's with 3+ years (may accept additional experience in lieu of degree).
  • Experience integrating security into CI/CD pipelines and cloud infrastructure.
  • Proficiency with infrastructure as code tools such as Terraform, CloudFormation, or Ansible.
  • Strong understanding of application security, cloud security, and secure software delivery practices.
  • Ability to implement and manage automated security testing within the SDLC.
  • Experience collaborating with cross-functional teams including developers, architects, and cybersecurity professionals.
  • Familiarity with regulatory compliance frameworks and organizational security policies.

Responsibilities

  • Design, implement, and maintain secure CI/CD pipelines across development, test, and production environments.
  • Embed automated security testing into the software development lifecycle, including SAST, DAST, SCA, container scanning, and secrets detection.
  • Develop and manage infrastructure as code using Terraform, CloudFormation, or Ansible.
  • Implement security controls across cloud platforms, containers, Kubernetes, APIs, and enterprise applications.
  • Establish and enforce policy-as-code, secure configuration standards, and deployment guardrails.
  • Integrate vulnerability management findings into engineering workflows and support timely remediation.
  • Partner with development teams to identify security risks, perform threat modeling, and improve secure coding practices.
  • Automate security, compliance, and operational processes to improve consistency and reduce manual effort.
  • Monitor pipeline, infrastructure, and application security events; support investigation and remediation of security incidents.
  • Maintain technical documentation, runbooks, architecture diagrams, and control evidence.
  • Contribute to security architecture reviews, technology evaluations, and continuous improvement initiatives.
  • Support compliance with applicable organizational policies, contractual requirements, and regulatory frameworks.

Education

Bachelor's degree

Tools

Terraform
CloudFormation
Ansible

Job description

Description

SAIC has an opportunity for a DevSecOps Engineer to integrate security into the software development and delivery lifecycle. This role will design, implement, and operate secure CI/CD pipelines, cloud infrastructure, automation, and security controls that enable development teams to deliver reliable software quickly and safely. The ideal candidate combines hands‑on engineering expertise with a strong understanding of application security, cloud security, infrastructure as code, and modern software delivery practices. This role partners closely with software engineers, platform teams, architects, cybersecurity teams, and compliance stakeholders.

This role requires 1 day each week onsite in Rosslyn, VA.

Key Responsibilities:

  • Design, implement, and maintain secure CI/CD pipelines across development, test, and production environments.
  • Embed automated security testing into the software development lifecycle, including static application security testing, dynamic testing, software composition analysis, container scanning, and secrets detection.
  • Develop and manage infrastructure as code using tools such as Terraform, CloudFormation, or Ansible.
  • Implement security controls across cloud platforms, containers, Kubernetes, APIs, and enterprise applications.
  • Establish and enforce policy-as-code, secure configuration standards, and deployment guardrails.
  • Integrate vulnerability management findings into engineering workflows and support timely remediation.
  • Partner with development teams to identify security risks, perform threat modeling, and improve secure coding practices.
  • Automate security, compliance, and operational processes to improve consistency and reduce manual effort.
  • Monitor pipeline, infrastructure, and application security events; support investigation and remediation of security incidents.
  • Maintain technical documentation, runbooks, architecture diagrams, and control evidence.
  • Contribute to security architecture reviews, technology evaluations, and continuous improvement initiatives.
  • Support compliance with applicable organizational policies, contractual requirements, and regulatory frameworks.

Qualifications

Required Education & Experience:

  • Bachelors and 5+ years or more experience; Masters and 3+ years; may accept additional experience in lieu of degree.
  • Demonstrated experience integrating security into CI/CD pipelines and cloud infrastructure.
  • Proficiency with infrastructure as code tools such as Terraform, CloudFormation, or Ansible.
  • Strong understanding of application security, cloud security, and secure software delivery practices.
  • Ability to implement and manage automated security testing within the software development lifecycle.
  • Experience collaborating with cross-functional teams including developers, architects, and cybersecurity professionals.
  • Familiarity with regulatory compliance frameworks and organizational security policies.

Required Clearance:

  • US Citizenship.
  • Active secret clearance.

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps & Systems Engineer (Full Stack)
Senior DevSecOps & Systems Engineer (Full Stack)

Saic • Sterling (VA)

Hybrid
USD 120,000 - 160,000
DevSecOps Engineer Principal
DevSecOps Engineer Principal

Saic • Reston (VA)

On-site
USD 160,000 - 200,000
DevSecOps Engineer Principal - Platform
DevSecOps Engineer Principal - Platform

Saic • Arlington (VA)

Hybrid
USD 160,000 - 200,000
DevSecOps Engineer
DevSecOps Engineer

GovCIO • Arlington (VA)

Hybrid
USD 220,000 - 230,000
DevSecOps Engineer: Build Secure Cloud CI/CD Pipelines
DevSecOps Engineer: Build Secure Cloud CI/CD Pipelines

Saic • Arlington (VA)

Hybrid
USD 120,000 - 160,000
DevSecOps Engineer Principal - Cyber
DevSecOps Engineer Principal - Cyber

SAIC • Arlington (VA)

On-site
USD 160,000 - 200,000
DevSecOps Engineer
DevSecOps Engineer

Unknown Company • United States

Hybrid
USD 220,000 - 230,000
DevSecOps Engineer
DevSecOps Engineer

Dark Wolf Solutions, LLC • Arlington (VA)

Hybrid
USD 155,000 - 185,000
DevSecOps Engineer Principal - Cyber
DevSecOps Engineer Principal - Cyber

Socket.dev • Arlington (VA)

Hybrid
USD 120,000 - 190,000
Principal Cloud DevSecOps Engineer
Principal Cloud DevSecOps Engineer

Saic • Colorado Springs (CO)

On-site
USD 160,000 - 200,000