DevSecOps Engineer – Huntsville, AL
Implement solutions to support platform and tool development, automation, and AI/ML integrations for Cybersecurity and Cyber Space Operations Teams.
Responsibilities
- Provide leadership in DevSecOps areas including incident response, vulnerability scanning and management, problem management, certificate management, penetration testing, password policy management, data analysis of network security, remediation patching coordination, and compliance efforts.
- Choose and implement automated application security testing tools, educating users on best practices.
- Collaborate to develop an automated security framework for strong deployment tools and processes, leveraging scripting languages and open-source solutions.
- Recommend automation improvements to replace manual operational tasks.
- Gather requirements, design, implement solutions, manage technical operations, and triage and fix operational issues.
- Perform network or security analysis and troubleshooting; diagnose root cause using monitoring tools and system analytics; apply system patches to DevOps tooling.
- Provide technical support and guidance to users and DevOps Engineers, resolving issues within network and security domains.
- Update security procedures, create and maintain operations runbooks to prevent recurring issues.
- Set up, conduct risk assessments, monitor, and maintain proxy servers, systems, and firewalls.
- Perform application penetration testing and manual security code reviews.
- Support development of value stream mapping, backlog management, and metrics for operational effectiveness.
- Utilize Jira, Azure DevOps, and ServiceNow to enable automated pipelines, tracking, and synchronization of development and security workflows.
- Ensure alignment with DoD enterprise Agile guidance and modernization initiatives.
- Collaborate to tailor DevSecOps frameworks to government security, policy, and operational environments.
- Automate deployment processes to enhance the release management lifecycle.
- Resolve validation and deployment errors promptly.
- Work productively within an agile, sprint-based environment, adhering to all applicable levels of reporting to the project manager.
- Promote the use of modern, cloud-native development tools aligned with government enterprise cloud and digital initiatives.
- Other duties as assigned.
Qualifications
- Bachelor's degree in science, technology, engineering, mathematics, IT, or business-related programs.
- 8+ years of experience in Software Development, Agile, DevOps, or Lean process transformation.
- 8+ years of experience in automation development or systems integration.
- 5+ years of experience with scripting or programming languages (e.g., Python, PowerShell, JavaScript).
- DoD 8140/8570 baseline security certification (e.g., CompTIA Security+, CASP+, CISSP) or a cloud-specific security certification (e.g., AWS Certified Security – Specialty).
- Active Secret clearance with the ability to obtain TS with SCI eligibility.
Preferred Qualifications
- 5+ years of experience supporting DoD or federal programs.
- Cloud-specific ML Certifications such as Azure AI Engineer Associate (AI-102) or AWS Certified Machine Learning – Specialty.
- 3+ years of experience with Vantage or Gabbriel Nimbus.
Knowledge, Skills, and Abilities
- Experience with tools such as Jira, Azure DevOps, Git, and CI/CD platforms.
- Experience interpreting data and presenting analysis and recommendations to management.
- High proficiency in Microsoft Office suite (Word, Excel, PowerPoint, Outlook).
- Experience deploying and securing containers.
- Experience utilizing Terraform.
- Understand cloud technologies (AWS, Azure, GCP, Oracle) and hybrid cloud environments.
- Proficiency in multiple scripting and programming languages (Python, Java, Bash, Go).
- Hands‑on experience with infrastructure automation tools.
- Experience with agile methodologies and DevSecOps practices.
- Knowledge of cloud security best practices.
- Excellent interpersonal communication, facilitation, and leadership skills for team coordination and stakeholder communication.
- Experience with SIEM systems, firewalls, VPNs, data encryption, cloud platforms, and endpoint protection.
- Strong time management and organizational skills to meet deadlines.
- Ability to work independently and within a team.
- Ability to meet minimum clearance requirements.
- Availability to work nights, weekends, and holidays as required.
- Willingness to travel up to 10%.