DevSecOps Engineer

TISTA Science and Technology Corporation

United States

Remote

USD 161,000 - 176,000

Full time

40 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Remote working options
Paid Time Off
401K Match
Tuition Reimbursement
Healthcare Benefits
Life Insurance
Disability

Job summary

TISTA Science and Technology Corporation seeks a seasoned DevSecOps Engineer to secure CI/CD pipelines, enable SBOM generation, and enforce policy gates across cloud environments (AWS/Azure). You will mentor teams on secure coding, manage Secrets, and drive compliance with RMF/ATO requirements for VA systems.

Location: Rockville, MD or remote CONUS. Travel up to 10%. Competitive compensation and benefits, plus opportunities for growth and training.

Qualifications

  • 7+ years in IT security or DevSecOps for federal Agile/SAFe programs.
  • 3+ years automating pipeline security (SAST/DAST, container scanning, secrets management).
  • Experience automating infrastructure hardening to meet DISA STIG/CIS benchmarks.

Responsibilities

  • Embed Guardrails-as-Code into all CI/CD pipelines with security scans and SBOM generation.
  • Triage and remediate vulnerabilities within deadlines to prevent production risk.
  • Automate evidence collection for ATO and ensure VA/FedRAMP compliance.

Skills

CI/CD security
DevSecOps
RMF/ATO experience
Cloud security
Secure coding guidance

Education

Bachelor's degree in Cybersecurity/CS/Engineering
Master's degree preferred

Tools

Ansible
Terraform
Splunk
HashiCorp Vault

Job description

Overview

TISTA is seeking a DevSecOps Engineer to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This role will partner with VA stakeholders and Agile delivery teams to translate business needs into clear, actionable requirements supporting supply chain and logistics solutions.

The DevSecOps Engineer / Security Specialist is the hands-on pipeline security engineer for TISTA's prime contract performance on the Department of Veterans Affairs Supply Chain Management DevSecOps (SCMDSO) task order supporting VA's supply chain and logistics Product Line. Where the Cyber Security Architect / Policy Lead defines the security architecture, policy interpretation, and Guardrails-as-Code standard, and the Engineer Solution Lead owns the platform and pipeline infrastructure, the DevSecOps Engineer / Security Specialist makes security real inside every build. This position embeds automated security scanning, software bill of materials generation, container and configuration hardening, secrets management, and vulnerability remediation tracking into the CI/CD pipelines used by every Scrum Team, and produces the security evidence that keeps every product's Authority to Operate current.

At TISTA, you’ll do meaningful, mission‑driven work that improves lives alongside teammates you trust and leaders who are transparent and supportive. We invest in your learning and internal mobility so you can build a career that keeps advancing. We’re proud to serve and hire Veterans, and we put people first in everything we do.

  • Industry Healthcare Benefits
  • Remote Working Options
  • Paid Time Off
  • Training/Certification opportunities
  • Healthcare Savings Account & Flexible Savings Account
  • Paid Life Insurance
  • Short-term & Long-term Disability
  • 401K Match
  • Tuition Reimbursement
  • Employee Assistance Program
  • Paid Holidays
  • Military Leave
  • and much more!
Responsibilities
  • Embed automated "Guardrails-as-Code" into all CI/CD pipelines, enforcing security scans (SAST/DAST), SBOM generation, and strict policy gates that block builds with critical vulnerabilities.
  • Manage secrets, cryptographic code signing, and artifact integrity while maintaining hardened, compliant container images and automating configuration drift detection.
  • Triage and resolve security vulnerabilities within strict deadlines (5 days for Critical, 10 days for High), ensuring zero unaccepted high-level risks reach production.
  • Automate the collection of security evidence to support Continuous Assessment and Authorization (ATO) and ensure all systems meet VA and FedRAMP compliance standards.
  • Implement Zero Trust architecture, strict access controls, logging, and comprehensive cloud security measures across VA Enterprise Cloud, AWS, and Azure environments.
  • Mentor development teams on secure coding practices, guide security design reviews, and rigorously validate the safety of AI-generated code and test scripts.
  • Drive security incident response efforts—including rapid component isolation, forensics, and strict 1-hour reporting windows—and participate in after-hours escalation rotations.
  • Support business growth by contributing DevSecOps strategies to proposals, tracking pipeline security performance metrics, and interviewing technical talent to build a strong team bench.
  • Advance corporate thought leadership by developing reusable pipeline security templates, leading internal cybersecurity communities, and supporting corporate quality assessments.
Qualifications
  • 7+ years in IT security or DevSecOps, including at least 4 years integrating continuous security controls into CI/CD pipelines for federal Agile/SAFe programs.
  • 3+ years of hands‑on experience managing automated pipeline security, including SAST/DAST, container scanning, secrets management, and generating SBOMs (e.g., SPDX, CycloneDX).
  • Proven ability to automate infrastructure hardening and configuration compliance using tools like Ansible and Terraform to meet strict DISA STIG and CIS benchmarks.
  • Strong background supporting NIST Risk Management Framework (RMF) and Authority to Operate (ATO) processes, including managing POA&Ms and automating continuous control evidence collection.
  • Extensive experience implementing robust cloud security controls across AWS, Azure, and the VA Enterprise Cloud, covering IAM, encryption, and network segmentation.
  • Skilled in tracking, triaging, and remediating security vulnerabilities within strict deadlines while partnering directly with developers to resolve findings.
  • Proficient in setting up comprehensive security monitoring and logging (e.g., Splunk) as well as strict identity and access controls (e.g., HashiCorp Vault, mutual TLS, ICAM/PIV).
  • Capable of guiding secure coding practices across multiple languages (Java, .NET, Python, legacy MUMPS) and embedding automated Section 508 accessibility testing into build pipelines.
  • Highly preferred experience includes securing VA supply chain systems, protecting HL7/FHIR healthcare APIs, managing one-hour incident responses, and validating AI-generated code.
Certifications
  • ISC2 CISSP, or Security+
  • AWS Solutions Architect Associate or AWS Developer Associate, or Azure Solutions Architect or Azure Developer Associate Red Hat Certified.
  • Specialist in Ansible Automation or Red Hat Certified Architect.
Education
  • Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Information Systems, or related field.
  • Master's degree preferred.
Clearance
  • Tier 2 / Moderate Risk Background Investigation; ability to obtain a VA PIV credential.
Location
  • Rockville, MD / Remote (CONUS).
  • Travel: Up to 10%.
Pay Range
  • The suggested pay for this position ranges from $161,00 to $176,000.
  • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.
  • Also, certain positions are eligible for additional forms of compensation, such as bonuses.
  • TISTA associates are eligible to participate in our comprehensive benefits plan! More information can be found here: https://tistatech.com/working-at-tista/
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Risk Lead
Cyber Security Risk Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 193,000 - 201,000
Healthcare benefits
Remote working
Paid time off
+9
Solution Technical Lead
Solution Technical Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 173,000 - 187,000
Industry healthcare benefits
Remote working options
Paid time off
+9
Cybersecurity Architect / Policy Lead
Cybersecurity Architect / Policy Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 183,000 - 199,000
Healthcare Benefits
Remote Work Options
Paid Time Off
+9
Engineer Solution Lead
Engineer Solution Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 171,000 - 183,000
Remote working options
Healthcare benefits
Paid time off
+6
Overarching Program Lead
Overarching Program Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 186,000 - 202,000
Healthcare benefits
Remote work options
Paid time off
+9
Enterprise/Solution System Architect
Enterprise/Solution System Architect

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 172,000 - 190,000
Remote Working Options
Paid Time Off
Training/Certification opportunities
+10
Quality Manager
Quality Manager

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 129,000 - 142,000
Healthcare benefits
Remote work
Paid time off
+9
Supply Chain Lead
Supply Chain Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 89,000 - 102,000
Healthcare Benefits
Remote Working Options
Paid Time Off
+9
Solution System Architect
Solution System Architect

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 171,000 - 183,000
Healthcare benefits
Remote work options
Paid time off
+2
Deputy IT Program Manager
Deputy IT Program Manager

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 172,000 - 187,000
Healthcare benefits
Remote work options
Paid time off
+9