DevSecOps Engineer

Socket.dev

Washington (District of Columbia)

On-site

USD 110,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health benefits
401k match
Free daily lunch
Unlimited PTO
Relocation assistance

Job summary

CHAOS Industries is hiring a DevSecOps Engineer to embed security across the software development and delivery lifecycle. You will own CI/CD security, automate compliance checks, and harden cloud and on-premise environments while partnering with engineering and operations teams to make secure-by-default a reality.

You’ll lead security toolchains in CI/CD pipelines, drive shift-left security, and streamline evidence collection for RMF/ATO across classified and unclassified environments.

Qualifications

  • Bachelor’s degree in a technical field or equivalent experience.
  • 4–7 years of hands-on DevOps, software eng., or cybersecurity with security tooling in CI/CD and cloud environments.
  • Proficiency in scripting languages used for automation and tooling.
  • Hands-on experience with container technologies and security hardening.
  • Experience with cloud security on AWS GovCloud or Azure Government and IAM, network security, secrets management.
  • Familiarity with SAST/DAST/SCA tools and CI/CD integrations.
  • Eligibility for Security Clearance.

Responsibilities

  • Design, implement, and maintain secure CI/CD pipelines with automated security scanning across workflows.
  • Automate security and compliance controls (STIG/SRG, vulnerability scanning, policy-as-code).
  • Collaborate with engineers to triage and remediate vulnerabilities; promote secure coding practices.
  • Build and manage container security posture (image hardening, runtime protection, Kubernetes configs).
  • Design and maintain infrastructure-as-code with integrated security controls; enforce least-privilege.
  • Support RMF/ATO activities; automate evidence collection and continuous monitoring for cloud/on-prem environments.
  • Monitor tooling telemetry, dashboards, and provide remediation backlogs to leadership.
  • Coordinate with ISSM/ISSO and ensure DevSecOps aligns with CMMC/DFARS controls.
  • Evaluate new DevSecOps tooling; create playbooks and runbooks for automation.
  • Travel up to 15% CONUS for site integrations and reviews.

Skills

Security automation
Scripting (Python/Bash/Go)
Threat modeling
Compliance automation

Education

Bachelor’s degree in Computer Science / Software Engineering / Cybersecurity

Tools

Docker
Kubernetes
GitHub Actions
GitLab CI
Jenkins

Job description

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats.

CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit www.chaosinc.com.

Role Overview:

Chaos Industries is hiring a DevSecOps Engineer to embed security into every layer of our software development and infrastructure delivery lifecycle. This is a broad, hands‑on engineering role; you’ll own CI/CD pipeline security, automate compliance and vulnerability checks, harden cloud and on‑premise environments, and partner with development and operations teams to make “secure by default” a reality, not a checkbox. You’ll work across classified and unclassified environments, applying the same engineering rigor to security that our developers apply to product - fast, repeatable, and built to scale.

  • You’ll sit at the intersection of the Engineering and Cybersecurity divisions; collaborating daily with software engineers, cloud architects, ISSMs, and platform teams to keep the development pipeline moving without compromising the security posture. You’re not a gatekeeper; you’re an accelerant who happens to care deeply about what gets through.
  • From day one you’ll own the security toolchain integrated into our CI/CD pipelines, lead the shift‑left security initiative across active development programs, and drive the automation of compliance controls that today require manual effort. Your work directly reduces risk, accelerates delivery, and makes the whole team faster.
Responsibilities:
  • Design, implement, and maintain secure CI/CD pipelines integrating automated security scanning tools (SAST, DAST, SCA, secrets detection) across development workflows using GitHub Actions, GitLab CI, Jenkins, or equivalent.
  • Automate security and compliance controls including STIG/SRG validation, vulnerability scanning (ACAS/Nessus), and policy‑as‑code enforcement (OPA, Conftest) within pipeline and infrastructure workflows.
  • Collaborate with software engineers to identify, triage, and remediate application security vulnerabilities; champion secure coding practices, threat modeling, and developer security training across engineering teams.
  • Build and manage container security posture including image hardening, runtime protection, Kubernetes security configurations (RBAC, Pod Security Admission, network policies), and registry scanning.
  • Design and maintain infrastructure‑as‑code (Terraform, CloudFormation, Ansible) with integrated security controls; enforce least‑privilege, secrets management (Secrets Manager), and configuration compliance.
  • Support RMF/ATO activities by automating evidence collection, generating compliance reports, and maintaining continuous monitoring artifacts for cloud and on‑premise systems operating within classified or CUI environments.
  • Monitor security tooling telemetry, pipeline health dashboards, and vulnerability metrics; produce trend reports and actionable remediation backlogs for engineering and security leadership.
  • Coordinate with ISSM/ISSO teams and system administrators to ensure DevSecOps practices align with authorization boundary requirements, CMMC Level 2/3 controls, and DFARS obligations.
  • Evaluate and introduce new DevSecOps tooling, frameworks, and practices; build internal documentation, runbooks, and playbooks to operationalize security automation across teams.
  • Travel up to 15% CONUS to support program site integrations, government customer engagements, and security architecture reviews.
Minimum Requirements:
  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field. Equivalent experience considered.
  • 4–7 years of experience in DevOps, software engineering, or cybersecurity, with demonstrated hands‑on experience integrating security tooling into CI/CD pipelines and cloud environments.
  • Proficiency in at least one scripting or programming language (Python, Bash, Go, or equivalent) used to build automation, security tooling integrations, or infrastructure‑as‑code.
  • Hands‑on experience with container technologies (Docker, Kubernetes) including security hardening, image scanning, and runtime protection in a production environment.
  • Working knowledge of cloud security on AWS GovCloud or Azure Government including IAM, network security groups, security monitoring services, and secrets management.
  • Familiarity with SAST, DAST, and SCA tooling (SonarQube, Checkmarx, Snyk, OWASP ZAP, Black Duck, or equivalent) and their integration into automated pipelines.
  • Eligibility for Security Clearance.
Preferred Requirements:
  • Active TS clearance.
  • Experience supporting NIST RMF ATO processes for software systems or cloud environments, including automated evidence collection and continuous monitoring workflows.
  • Familiarity with CMMC Level 2/3 practices, DFARS 252.204-7012, and their application to software development and CI/CD pipeline security controls.
  • Experience with GitOps workflows and policy‑as‑code frameworks (OPA/Gatekeeper, Kyverno, Conftest) for automated governance enforcement.
  • Knowledge of software supply chain security practices: SBOM generation, artifact signing (Sigstore/Cosign), and dependency provenance tracking.
  • Experience operating in classified or air‑gapped environments with disconnected CI/CD toolchains and offline artifact repositories.
  • Relevant certifications: Security+, AWS Security Specialty, or equivalent.
Why CHAOS?
  • Health Benefits: Medical, dental, and vision benefits 100% paid for by the company
  • Additional benefits: 401k (+ 50% company match up to 6% of pay), FSA, HSA, life insurance, and more
  • Our Perks: Free daily lunch, ‘No meeting Fridays’, unlimited PTO, casual dress code
  • Compensation Components: Competitive base salaries, generous pre‑IPO stock option grants, relocation assistance, and (coming soon!) annual bonuses
  • Team Growth: 250 employees and counting across 5 global offices

Salary Range: $110,000 - $160,000

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

CHAOS Industries • Washington

On-site
USD 110,000 - 160,000
Health benefits
401k with company match
Free daily lunch
+2
DevSecOps Engineer
DevSecOps Engineer

CHAOS Industries • El Segundo (CA)

On-site
USD 110,000 - 160,000
Health benefits 100% paid
Free daily lunch
Unlimited PTO
Cloud DevSecOps Engineer - (Software Engineering Focused)
Cloud DevSecOps Engineer - (Software Engineering Focused)

3M HEALTHCARE • Hawthorne (CA)

On-site
USD 140,000 - 220,000
Health benefits 100% paid
401k with company match
Free daily lunch
+1
Senior Cybersecurity Engineer, Product Security
Senior Cybersecurity Engineer, Product Security

CHAOS Industries • San Francisco (CA)

On-site
USD 110,000 - 190,000
Health benefits
401k matching
Free daily lunch
+3
Senior Cybersecurity Engineer, Product Security
Senior Cybersecurity Engineer, Product Security

CHAOS Industries • Los Angeles (CA)

On-site
USD 110,000 - 190,000
Health benefits
401k + company match
Free daily lunch
+2
Senior Cybersecurity Engineer, Product Security
Senior Cybersecurity Engineer, Product Security

CHAOS Industries • Washington

On-site
USD 110,000 - 190,000
Health benefits
401k matching
Relocation assistance
+1
Senior Cybersecurity Engineer, Product Security
Senior Cybersecurity Engineer, Product Security

CHAOS Industries • El Segundo (CA)

On-site
USD 114,000 - 190,000
Free daily lunch
No meeting Fridays
401k match
+2
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Chaos, Inc. • El Segundo (CA)

Hybrid
USD 120,000 - 150,000
Health benefits
401k with company match
Free daily lunch
+2
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

CHAOS Industries • El Segundo (CA)

On-site
USD 120,000 - 150,000
Health benefits
401k with company match
Free daily lunch
+4
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

CHAOS Industries • Washington

On-site
USD 110,000 - 150,000
Health benefits
401k match
Free daily lunch
+3