DevSecOps Engineer

SOC LLC

Malibu (CA)

On-site

USD 67,502 - 117,096

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading cybersecurity firm is seeking a DevSecOps Engineer for a contract-to-hire position in Malibu, CA. The role requires expertise in cybersecurity controls, GitLab, and security automation. A Top Secret (TS/SCI) security clearance is mandatory, along with at least 7 years of experience in a cybersecurity capacity. The ideal candidate will design, implement, and maintain security measures in DevSecOps pipelines and provide expertise in secure coding and vulnerability management.

Qualifications

  • Active Top Secret (TS/SCI) security clearance required.
  • Minimum of 7 years experience in cybersecurity roles.
  • Hands-on experience securing DevSecOps pipelines.

Responsibilities

  • Design and maintain cybersecurity controls within DevSecOps pipelines.
  • Integrate and optimize security tools for vulnerability detection.
  • Provide guidance on secure coding and vulnerability remediation.

Skills

Active TS/SCI
Cybersecurity expertise
GitLab proficiency
Experience with containers
Scripting skills (Python, Bash)
Secure coding practices
Collaboration skills

Education

Bachelor’s degree in computer science or related field
DoD 8570.01-M IAT Level II certification

Tools

GitLab
Docker
SonarQube
Artifactory

Job description

1 week ago Be among the first 25 applicants

This range is provided by SOC LLC. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.

Base pay range

$65.00/hr - $85.00/hr

Direct message the job poster from SOC LLC

Technical Recruiter at SOC LLC, Expert in #TechnicalRecruiting #SecurityClearanceTalent #FederalServices #Cybersecurity

DevSecOps Engineer needed for a contract to hire opportunity with SOC’s client to work onsite in Malibu, CA

*Active TS/SCI is required for the role*

RESPONSIBILITIES:

  • Design, implement, and maintain advanced cybersecurity controls and solutions directly within DevSecOps pipelines and associated toolchains (e.g., GitLab, Artifactory, Ansible, SonarQube)
  • Configure, integrate, and optimize security tools such as GitLab's SAST/DAST, Artifactory X-Ray, Tenable, Cortex XSIAM, and SonarQube to automate vulnerability detection, code quality analysis, and artifact security
  • Translate complex security requirements, including those derived from Risk Management Framework (RMF) and Information Assurance (IA) policies, into actionable technical designs and implementation strategies for software systems
  • Provide expert-level technical guidance and hands-on assistance to DevSecOps engineers and software developers on secure coding practices, vulnerability remediation, threat modeling, and building security into CI/CD workflows
  • Develop and implement automated security testing procedures (e.g., unit tests, integration tests, fuzzing, penetration testing) to ensure continuous security validation
  • Conduct technical deep dives into software architectures and development practices to identify security weaknesses and propose effective mitigation strategies across multi-classification networks
  • Collaborate with ISSOs to ensure technical security implementations align with overall security policy, accreditation requirements, and compliance standards
  • Manage security configurations of development, test, and production environments, ensuring adherence to baselines and addressing configuration drift
  • Research, evaluate, and recommend new security technologies, tools, and best practices to enhance the security posture of our DevSecOps ecosystem
  • Develop custom security scripts, automation, and integrations to streamline security processes and improve operational efficiency
  • Participate in incident response activities related to software vulnerabilities and security breaches within the development and deployment pipelines
  • Document technical security implementations, architectural designs, and standard operating procedures for secure DevSecOps practices

REQUIRED QUALIFICATIONS:

  • Active Top Secret (TS/SCI) security clearance
  • Minimum of 7 years of experience in a highly technical cybersecurity role, such as Security Engineer, DevSecOps Engineer, or Software Security Engineer
  • Minimum of 3 years of hands-on, in-depth experience securing DevSecOps pipelines and integrating security tools
  • Demonstrable expertise with GitLab, including extensive experience configuring and utilizing its SAST and DAST capabilities
  • Proven experience with Artifactory, specifically leveraging Artifactory X-Ray for software composition analysis (SCA) and vulnerability management
  • Deep technical knowledge and hands-on experience with SonarQube for static code analysis and code quality gates
  • Expertise in implementing and enforcing the Secure Software Development Framework (SSDF) and secure SDLC principles
  • Strong understanding of secure coding practices, common vulnerabilities (e.g., OWASP Top 10), and remediation techniques
  • Proficiency in scripting and automation using languages such as Python, Bash, PowerShell, or similar
  • Experience securing systems operating on multiple government networks with varying classification levels and understanding of data diode security implications
  • Comprehensive technical understanding of the Risk Management Framework (RMF) and Information Assurance (IA) principles as they apply to system implementation and security control mapping
  • Familiarity with containerization technologies (e.g., Docker, Kubernetes) and their security best practices
  • Excellent problem-solving skills, with the ability to diagnose and resolve complex technical security issues
  • Strong collaboration and communication skills, capable of working effectively with development, operations, and security teams

PREFFERED QUALIFICATIONS:

  • A current Top Secret/SCI security clearance
  • Experience with other security testing tools (e.g., dynamic application security testing (DAST) tools, penetration testing tools, fuzzing tools)
  • Background in software development or system administration is a plus, providing a stronger foundation for DevSecOps integration
  • Experience with Infrastructure as Code (IaC) and its security implications
  • Knowledge of supply chain security best practices for software

EDUCATION:

  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related technical discipline. (Relevant experience and certifications may be considered in lieu of a degree for exceptionally qualified candidates.)
  • DoD 8570.01-M IAT Level II (or higher) certification (e.g., CompTIA Security+, CySA+, GICSP, GSEC, CISSP)
  • Relevant technical security certifications such as CSSLP, GCSA, GWAPT, OSCP, or equivalent

Employment Prerequisites

The following requirements must be met to be eligible for this position: successful completion of a background investigation and drug urinalysis.

SOC, a Day & Zimmermann company, is an Equal Opportunity Employer, EOE AA M/F/Vet/Disability.

Note: Any pay ranges displayed are estimations, which may have been provided by job boards. Actual pay is determined by an applicant’s experience, technical expertise, and other qualifications as listed in the job description. All qualified applicants are welcome to apply.

Estimated Min Rate: $49.00

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Industries
    Defense and Space Manufacturing

Referrals increase your chances of interviewing at SOC LLC by 2x

Sign in to set job alerts for “Cyber Security Engineer” roles.
Analyst, Information Security - Training & Awareness

Culver City, CA $70,000.00-$93,000.00 2 weeks ago

Beverly Hills, CA $120,000.00-$150,000.00 1 week ago

Burbank, CA $126,400.00-$169,500.00 2 weeks ago

Security & Governance Analyst - Identity & Access Management

Burbank, CA $114,900.00-$154,100.00 1 week ago

Camarillo, CA $120,000.00-$153,000.00 2 weeks ago

We're Hiring! Cybersecurity Analyst (Mid-Level)

Santa Monica, CA $95,000.00-$120,000.00 6 days ago

Cybersecurity Operations Specialist - Hybrid

Beverly Hills, CA $94,390.40-$151,028.80 2 weeks ago

Sr. Engineer, Information Security (Cloud Security)

Culver City, CA $120,000.00-$150,000.00 2 weeks ago

Security Engineer (Identity and Access Management)

Hawthorne, CA $130,000.00-$150,000.00 3 weeks ago

Malibu, CA $99,705.00-$124,683.00 1 week ago

Information Security Analyst II - FT Days

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Engineer
Information Security Engineer

I.T. Solutions, Inc. • Irvine (CA)

On-site
USD <1,000
Security Analyst
Security Analyst

DirectDefense • United States

On-site
USD 70,000 - 80,000
401(k)
Health insurance
Disability insurance
+2
Cyber Security Engineer
Cyber Security Engineer

Insight Global • Irvine (CA)

On-site
Medical insurance
Vision insurance
401(k)
Security Operations Specialist
Security Operations Specialist

Triune Infomatics Inc • California (MO)

On-site
Senior Information Security Analyst
Senior Information Security Analyst

Insight Global • United States

Remote
Medical insurance
Vision insurance
401(k) retirement plan with employer matching
Security DevOps Engineer - 25-03328
Security DevOps Engineer - 25-03328

LeadStack Inc. • United States

On-site
Security Engineer
Security Engineer

Jobright.ai • Washington

On-site
USD 125,000 - 213,000
Medical insurance
Vision insurance
401(k)
Cybersecurity Security Engineer
Cybersecurity Security Engineer

Cornerstone Concilium, Inc. • Los Angeles (CA)

Hybrid
USD 156,000 - 238,000
Senior Cyber Red Team Operator (Penetration Testing)
Senior Cyber Red Team Operator (Penetration Testing)

Command Post Technologies, Inc • United States

On-site
USD 120,000 - 180,000
Leadership training
Career professional development
Tuition reimbursement
+4
Security Engineering Manager
Security Engineering Manager

Corporate Tools • United States

On-site
USD 78,000 - 152,000