DevSecOps Engineer

Socket.dev

Virginia (MN)

Hybrid

USD 99,000 - 168,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ICF is seeking a DevSecOps Engineer to harden CI/CD pipelines, automate deployment, and embed security into cloud and application delivery for a federal client.

You will work with DevOps, security, and application teams to implement automated tests, code-quality checks, and compliance controls in AWS/Azure GovCloud environments, following NIST/FedRAMP guidance.

Qualifications

  • Degree in a technical field and active federal security clearance preferred.
  • Strong fundamentals in CI/CD concepts and DevSecOps practices.
  • Experience with GitLab or Jenkins in cloud environments.
  • Familiarity with cloud platforms (AWS/Azure GovCloud) and security tooling.

Responsibilities

  • Develop, monitor, and support CI/CD pipelines and artifact management.
  • Automate deployment, testing, and quality gates per contract targets.
  • Integrate security scanning (SAST/DAST, dependencies, containers) into pipelines.
  • Support AWS/Azure GovCloud infrastructure and IaC (Terraform, CloudFormation).
  • Collaborate with security, dev, and ops teams in an Agile/Scrum setting.
  • Document configurations and controls for ATO and audits.

Skills

CI/CD concepts
GitLab/Jenkins
Linux scripting
DevSecOps basics

Education

Bachelor's degree in CS/IS/Cybersecurity
Federal security clearance

Tools

GitLab CI
Jenkins
Nexus
Terraform
CloudFormation
Splunk
Snyk
Trivy
Checkov
Prisma Cloud
Docker
Kubernetes/OpenShift
Appian

Job description

ICF’s Digital Modernization division is a rapidly growing, entrepreneurial, technology department, seeking a DevSecOps Engineer to support upcoming needs with our federal customers.

Our Digital Modernization division is an information technology and management consulting department that offers integrated, strategic solutions to its public and private-sector clients. ICF has the expertise, agility, and commitment to design, build, and operate high-performance IT engines to support all aspects of our client’s business.

We are seeking a DevSecOps Engineer to support a federal client by helping integrate security practices into modern cloud and application delivery workflows. You will work alongside senior DevOps, security, and application teams to support CI/CD pipelines, cloud infrastructure, automated testing, and security controls in alignment with federal standards. Work is fully remote within the United States on government-furnished equipment, with core collaboration hours in Eastern Time.

Job Location: Remote work is authorized. Must support US Eastern time zone working hours.

*If you accept this position, you should note that ICF does monitor employee work locations blocks access from foreign locations/foreign IP addresses and prohibits personal VPN connections.

What You Will Do:
  • Assist in the development, maintenance, and monitoring of CI/CD pipelines using tools such as GitLab CI or Jenkins, including artifact management (e.g., Nexus)
  • Support automated deployment and environment promotion for applications built on a COTS/low-code platform (e.g., Appian), from development through test and production
  • Help implement automated quality gates in pipelines — unit/integration test execution, automated regression suites, and code-quality/static analysis — in support of contract quality targets
  • Help integrate security scanning and compliance checks into build and deployment pipelines (SAST, DAST, dependency scanning, container scanning)
  • Support cloud infrastructure in AWS or Azure, including GovCloud regions, with an emphasis on security best practices; support infrastructure as code (IaC) using tools like Terraform, CloudFormation, or platform-native tooling
  • Support monitoring and observability — log aggregation and streaming to enterprise monitoring (e.g., Splunk), alerting, performance testing (e.g., JMeter) — and assist with troubleshooting and incident response
  • Support backup/recovery operations and availability, recovery-time, and recovery-point objectives
  • Document configurations, processes, and security controls to support audits, Assessment & Authorization (ATO) activities, and continuous-monitoring evidence
  • Collaborate with development, operations, and security teams in an Agile/Scrum environment
  • Learn and apply federal security frameworks such as NIST 800-53, FISMA, and FedRAMP
What You Will Bring:
  • U.S. citizenship, required due to federal contract requirements
  • Must reside in the United States (U.S.) and the work must be performed in the United States (U.S.), as this work is for a federal contract and laws do apply
  • Ability to obtain and maintain a favorable federal agency background investigation / suitability determination
  • 5+ years of experience in DevOps, cloud engineering, systems engineering, or cybersecurity
What We Would Like You To Have:
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related technical field
  • An active federal security clearance or a prior favorable federal background investigation (supports reciprocity and faster onboarding)
  • Basic understanding of CI/CD concepts and DevOps practices; experience with GitLab and/or Jenkins specifically
  • Familiarity with at least one cloud platform (AWS or Azure preferred, including GovCloud)
  • Working knowledge of Linux (e.g., RHEL) and Windows Server environments, and basic scripting (Bash, Python, PowerShell, or similar)
  • Exposure to DevSecOps and security tooling (e.g., SonarQube, Tenable, Snyk, Trivy, Checkov, Prisma Cloud)
  • Experience with Docker and basic Kubernetes or OpenShift concepts
  • Familiarity with SIEM/log-analysis platforms such as Splunk
  • Exposure to low-code or COTS application platforms (e.g., Appian, Salesforce, ServiceNow) and their deployment/release models
  • Basic familiarity with relational databases (e.g., SQL Server)
  • Familiarity with NIST 800-53, FedRAMP, or other federal security standards
  • Entry-level certifications such as AWS Cloud Practitioner, Azure Fundamentals, Security+, or similar
  • Experience supporting applications in a regulated or government environment
Working at ICF

ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.

We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share theirexpertiseand collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy.

We will consider for employment qualified applicants with arrest and conviction records.

Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

Read more about workplacediscriminationrights or our benefit offerings which are included in the Transparency in (Benefits) CoverageAct.

Candidate AI Usage Policy

At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.

However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.

Pay Range

There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position.

The pay range for this position based on full-time employment is:

$98,614.00 - $167,644.00Nationwide Remote Office (US99)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer - Remote
Senior DevOps Engineer - Remote

ICF • Reston (VA)

On-site
USD 108,000 - 185,000
Cloud Platform Engineer
Cloud Platform Engineer

ICF • Annapolis (MD)

Hybrid
USD 108,000 - 184,000
Cloud Platform Engineer
Cloud Platform Engineer

ICF • Richmond (VA)

Hybrid
USD 108,000 - 184,000
Threat Detection & Response Engineer, Senior (High Level Clearance Required)
Threat Detection & Response Engineer, Senior (High Level Clearance Required)

ICF • Arlington (VA)

Hybrid
USD 119,000 - 203,000
Data Integration Engineer
Data Integration Engineer

Socket.dev • Virginia (MN)

Hybrid
USD 99,000 - 168,000
Software Test Engineer
Software Test Engineer

Socket.dev • Virginia (MN)

Hybrid
USD 81,000 - 139,000
Service Desk Manager
Service Desk Manager

ICF • Annapolis (MD)

Hybrid
USD 91,000 - 152,000
Service Desk Manager
Service Desk Manager

ICF • Richmond (VA)

Hybrid
USD 89,000 - 152,000
IAM Lead
IAM Lead

ICF • Annapolis (MD)

Hybrid
USD 108,000 - 184,000
IAM Lead
IAM Lead

ICF • Washington

Hybrid
USD 108,000 - 184,000