DevSecOps Engineer / Cyber Engineer

Signal Hill Technologies

Fairfax (VA)

On-site

USD 150,000 - 185,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Company health plan
401(k) plan with employer match
Paid holidays and paid time off

Job summary

Signal Hill Technologies is seeking a DevSecOps Engineer to embed security across the software lifecycle for government and commercial clients. You will build security into CI/CD pipelines, review code and pipelines, and guide teams to ship secure, resilient systems.

You’ll work across the stack to ensure security is built in, not gated at release, pairing with engineering to deploy secure software and drive DSOMM/ASVS-aligned practices.

Qualifications

  • Public Trust eligible (U.S. citizenship or green card) and ability to pass background investigation.
  • 6+ years in cybersecurity/DevSecOps with at least 2 years hands-on application security experience.
  • Proficiency in DevSecOps concepts, including CI/CD pipelines, Jenkins and/or GitHub Actions, and SAST/DAST integration and automation.
  • Scripting proficiency in Python and/or PowerShell.
  • Experience with APIs, API security, and databases.
  • Strong communication of technical findings to both technical and non-technical audiences.
  • Hands-on experience with code analysis and vulnerability scanning tools (Burp Suite or similar).

Responsibilities

  • Develop secure software testing and validation procedures for applications in CI/CD pipelines (e.g., Jenkins, GitHub Actions).
  • Integrate and tune SAST/DAST tooling within build/release pipelines; validate findings as true positives.
  • Perform secure code review and testing to identify and mitigate vulnerabilities per OWASP ASVS/DSOMM.
  • Perform risk analysis (threat, vulnerability, probability) for major changes.
  • Address security implications across software acceptance, including risk and documentation.
  • Prepare security assessment documentation and translate findings into secure coding guidance for stakeholders.
  • Consult with engineering to evaluate hardware/software/infrastructure interfaces for security risks.
  • Support DevSecOps processes, gate security, and reporting standards.

Skills

CI/CD pipelines
Jenkins
GitHub Actions
SAST/DAST
Python
PowerShell
APIs
Communication

Education

Bachelor's degree in CS/Cybersecurity

Tools

Burp Suite
SAST/DAST tooling

Job description

Employment Type: Full-time

Status: Immediate

About the Role

Signal Hill Technologies is seeking a DevSecOps Engineer / Cyber Engineer to embed security throughout the software development and delivery lifecycle for our government and commercial clients. This is both a hands‑on engineering role and a technical advisory role — you'll build security directly into CI/CD pipelines, assess the applications and infrastructure moving through them, and help our teams ship secure, resilient systems faster.

You’ll work across the hardware‑to‑application stack: reviewing code and pipeline configurations, running and triaging security scans, and partnering with engineering teams so that security is a built‑in property of what we ship - not a gate at the end.

About Signal Hill Technologies

Founded and led by veteran cyber operators, Signal Hill Technologies delivers advanced cybersecurity solutions to DoD, Intelligence Community, financial services, and critical infrastructure clients, with many years of experience defending both US Government and commercial clients against sophisticated, well‑funded, motivated adversaries. We are relentless about real results and operationally proven expertise. Our mission is to provide the best technical solutions and hands‑on support to address each customer's unique cyber risks.

Position Responsibilities
  • Develop secure software testing and validation procedures for applications moving through the CI/CD pipeline (e.g., Jenkins, GitHub Actions).
  • Integrate and tune SAST/DAST tooling within build and release pipelines; reconcile scan output and validate findings as true positives.
  • Perform secure code review and program testing to identify flaws and mitigate vulnerabilities prior to release, applying standards such as OWASP ASVS and the DevSecOps Maturity Model (DSOMM).
  • Perform risk analysis — threat, vulnerability, and probability of occurrence — whenever an application or system undergoes a major change.
  • Address security implications across the software acceptance phase, including completion criteria, risk acceptance and documentation, and independent testing methods.
  • Prepare security assessment and authorization documentation and communicate findings and secure‑coding guidance clearly to both technical and non‑technical stakeholders.
  • Consult with engineering and development staff to evaluate the interface between hardware, software, and infrastructure, and to identify security issues around steady‑state operation and end‑of‑life management.
  • Support the development and refinement of DevSecOps processes, pipeline security gates, and reporting standards.
Minimum Qualifications
  • Public Trust eligible (U.S. citizenship or green card required and ability to pass a background investigation).
  • Minimum of 6 years of relevant cybersecurity/DevSecOps engineering experience, including at least 2 years of hands‑on application security experience.
  • Proficiency in DevSecOps concepts, including CI/CD pipelines, Jenkins and/or GitHub Actions, and SAST/DAST integration and automation.
  • Scripting proficiency in Python and/or PowerShell.
  • Experience with systems integration, including APIs, API security, and databases.
  • Strong collaborative and interpersonal skills, with the ability to clearly communicate technical findings and secure‑coding guidance to both technical and non‑technical audiences.
  • Working knowledge of cybersecurity and privacy principles, risk management processes, and common system/application vulnerabilities (e.g., injection, buffer overflow, cross‑site scripting).
  • Hands‑on experience with code analysis and vulnerability scanning tools (e.g., Burp Suite Professional or similar SAST/DAST tooling).
Preferred Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity Engineering, Computer Engineering, Systems Engineering, Computer Information Systems, or a related field.
  • Cloud security engineering experience in AWS and/or Azure, including IAM policy and configuration.
  • Familiarity with infrastructure automation and configuration management tooling (e.g., Ansible, Terraform).
  • Familiarity with the Risk Management Framework and related security/privacy controls (NIST SP 800-37, NIST SP 800-53) and/or FedRAMP.
  • Experience with enterprise security tooling such as SIEM, WAF, IPS, or endpoint security.
  • Certifications: e.g., CompTIA CASP+, (ISC)² CISSP/CSSLP/SSCP, GIAC (GICSP, GISF, GSSP), or a cloud security certification such as AWS Certified Security – Specialty.
Bonus: We Love Multi‑Talented Engineers

This posting is focused on DevSecOps engineering, but Signal Hill supports a range of cybersecurity engineering functions for our clients — including cloud security architecture, identity and access management, and systems security engineering — and those needs shift as our contracts evolve. We don't have a defined cross‑training path mapped out yet, but if you're the kind of engineer who's comfortable picking up adjacent disciplines and growing into new responsibilities over time, we want to know that about you. Tell us in your application where else you've stretched beyond your core role.

  • Compensation: $150k-185k annually (depending on experience)
  • Company health plan
  • 401(k) plan with employer match
  • Paid holidays and paid time off

Signal Hill Technologies is an equal opportunity employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

electro soft • Arlington (VA)

On-site
USD 140,000 - 190,000
DevSecOps Engineer
DevSecOps Engineer

Socket.dev • Arlington (VA)

On-site
USD 120,000 - 150,000
DevSecOps Engineer
DevSecOps Engineer

Dark Wolf • Arlington (VA)

Hybrid
USD 155,000 - 185,000
DevSecOps Engineer
DevSecOps Engineer

ECS • Fairfax (VA)

Hybrid
USD 125,000 - 150,000
DevSecOps Engineer
DevSecOps Engineer

CACI International Inc • Fairfax (VA)

On-site
USD 82,000 - 173,000
Lead Security Engineer
Lead Security Engineer

Dev Technology • Suitland (MD)

On-site
USD 120,000 - 190,000
Generous time-off policy
Flexible work schedules
401K matching
+1
DevSecOps Engineer
DevSecOps Engineer

Chenega Corporation • Huntsville (AL)

On-site
USD 95,000 - 130,000
DevSecOps Engineer
DevSecOps Engineer

Dark Wolf Solutions, LLC • Arlington (VA)

Hybrid
USD 155,000 - 185,000
Security-Driven DevSecOps Engineer for CI/CD
Security-Driven DevSecOps Engineer for CI/CD

Signal Hill Technologies • Fairfax (VA)

On-site
USD 150,000 - 185,000
Company health plan
401(k) plan with employer match
Paid holidays and paid time off
DevSecOps Engineer
DevSecOps Engineer

Integrated Solutions for Systems, Inc. (IS4S) • Auburn (AL)

On-site
USD 90,000 - 150,000
Competitive salary
Employee ownership
401(k) retirement plan