DevSecOps Engineer-Experienced

oshkoshcorporation

United States

Hybrid

USD 130,000 - 170,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Pratt Miller, an Oshkosh company, seeks a DevSecOps Engineer to design and maintain secure pipelines for defense projects under CMMC Level 2. You will embed security controls across cloud and on‑prem environments, using GitLab and related tooling to automate tests and compliance.

This hands‑on role partners with software, IT, and security teams to deliver auditable, resilient systems hosting CUI, while ensuring DoD cyber standards are met and continuous monitoring is maintained.

Qualifications

  • Bachelor’s degree in CS/IT/cybersecurity or related field; advanced degree preferred.
  • Must meet U.S. Government clearance requirements; active Secret or higher preferred.
  • Experience developing secure CI/CD pipelines with GitLab, Jenkins, or Azure DevOps.
  • Experience implementing automated security testing tools (SAST, DAST, SCA) and vulnerability management.
  • Experience with CMMC Level 2 or NIST 800-171 compliance in defense or government environments.
  • Experience managing secure infrastructure in AWS GovCloud, Azure Government, or on‑prem DoD‑accredited environments.

Responsibilities

  • Design, implement, and maintain secure DevSecOps infrastructure and delivery pipelines to support defense programs under CMMC Level 2 compliance.
  • Implement security controls and automation within CI/CD pipelines using GitLab and related DevSecOps tooling.
  • Ensure adherence to secure coding practices, compliance with NIST SP 800-171/172, and CMMC Level 2 cybersecurity standards across software development and infrastructure management.
  • Collaborate with defense software and cybersecurity teams to integrate automated testing, vulnerability management, and secure deployment strategies into cloud and on‑prem environments.
  • Assist in identifying technologies and tools that enhance security posture, automation, and compliance monitoring capabilities.

Skills

DevSecOps
CI/CD pipelines
GitLab
NIST SP 800-171
CMMC Level 2
AWS GovCloud
Azure Gov
Security testing
Vulnerability management
Automation

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field
Active U.S. Government clearance preferred

Tools

GitLab
Jenkins
Azure DevOps
Terraform
Ansible
AWS GovCloud
Azure Government

Job description

About Pratt Miller, an Oshkosh company

Pratt Miller is a product development company in motorsports, defense, and mobility industries providing clients with product engineering and low-volume production solutions. Our range of research & development, engineering, prototype manufacturing, test & validation, and low-rate production capability help our customers bring their high-quality products to market faster.

The DevSecOps Engineer is responsible for implementing secure development pipelines, automation frameworks, and compliant infrastructure to support defense programs operating under CMMC Level 2 and NIST 800-171/172 requirements. This role integrates security controls into cloud and on-prem environments, supports continuous monitoring and vulnerability management, and ensures systems hosting Controlled Unclassified Information (CUI) meet mission-critical performance and cybersecurity standards. This is a hands‑on position that will work closely with software, IT, and security teams to deliver resilient, secure, and auditable solutions across defense projects.

ESSENTIAL FUNCTIONS AND SKILLS

Typical responsibilities include, but are not limited to:

Project Execution
  • Responsible for the design, implementation, and maintenance of secure DevSecOps infrastructure and delivery pipelines to support defense programs under CMMC Level 2 compliance.
  • Implement security controls and automation within CI/CD pipelines using GitLab and related DevSecOps tooling.
  • Ensure adherence to secure coding practices, compliance with NIST SP 800-171/172, and CMMC Level 2 cybersecurity standards across software development and infrastructure management.
  • Collaborate with defense software and cybersecurity teams to integrate automated testing, vulnerability management, and secure deployment strategies into cloud and on-prem environments.
  • Assist in identifying technologies and tools that enhance security posture, automation, and compliance monitoring capabilities.
Customer Focus
  • Maintain a customer‑focused view of system security and DevSecOps process effectiveness across defense project initiatives.
  • Participate in technical and compliance reviews with customers and stakeholders to ensure systems meet mission‑critical availability, reliability, and security requirements.
Research
  • Research and implement new technologies, security tools, and methodologies to enhance automation, compliance, and system resilience.
  • Stay informed on evolving DoD cybersecurity standards, cloud governance models, and zero‑trust architectures to ensure continuous compliance.
Collaboration
  • Work across multidisciplinary engineering and IT teams, integrating security controls within development and operational environments.
  • Collaborate with network, software, and security engineers to ensure end‑to‑end protection of systems hosting Controlled Unclassified Information (CUI).
  • Participate in design and code reviews, infrastructure planning meetings, and post‑implementation security assessments.
  • Work effectively with remote and hybrid teams using collaboration tools such as MatterMost and GitLab.
Problem Solving
  • Demonstrate strong analytical thinking and problem‑solving skills with the ability to address complex infrastructure and cybersecurity challenges.
  • Leverage automation and monitoring to proactively identify and resolve performance or compliance issues within DevSecOps pipelines.
ADDITIONAL REQUIREMENTS
  • Strong documentation skills for configurations, compliance evidence, and SOPs.
  • Ability to clearly explain complex security concepts to both technical and non‑technical audiences.
  • Self‑starter with a security‑first mindset and the ability to manage multiple projects with minimal supervision.
  • Collaborative and communicative, with consistent effectiveness working across disciplines.
EDUCATION / CERTIFICATION / YEARS OF EXPERIENCE
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; advanced degree preferred.
  • Must meet the requirements for obtaining a U.S. Government clearance; active Secret or higher clearance preferred.
  • Experience developing and maintaining secure CI/CD pipelines using GitLab, Jenkins, or Azure DevOps.
  • Experience implementing automated security testing tools (SAST, DAST, SCA) and vulnerability management systems.
  • Experience with CMMC Level 2 or NIST 800-171 compliance in defense or government environments.
  • Experience managing secure infrastructure in AWS GovCloud, Azure Government, or on‑prem DoD‐accredited environments.
DESIRED SPECIALIZED SKILLS AND KNOWLEDGE
Technical Expertise
  • Deep understanding of DevSecOps principles, CI/CD, and automation frameworks.
  • Expertise in network architecture and security (TCP / IP, VLANs, VPNs, firewalls, IDS / IPS systems).
  • Active Directory and Group Policy administration for secure identity and access management.
  • Experience implementing zero‑trust and least‑privilege access models.
  • Knowledge of cloud security configurations, infrastructure‑as‑code (Terraform, Ansibl
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer-Experienced
DevSecOps Engineer-Experienced

Oshkosh Corporation, Inc. • Michigan

On-site
USD 120,000 - 150,000
DevSecOps Engineer-Experienced
DevSecOps Engineer-Experienced

Pratt Miller • New Hudson (MI)

On-site
USD 120,000 - 180,000
DevSecOps Engineer — Secure Pipelines for Defense
DevSecOps Engineer — Secure Pipelines for Defense

oshkoshcorporation • United States

Hybrid
USD 130,000 - 170,000
Secure DevSecOps Engineer | DoD Compliance & CI/CD
Secure DevSecOps Engineer | DoD Compliance & CI/CD

Pratt Miller • New Hudson (MI)

On-site
USD 120,000 - 180,000
Security Software Engineer
Security Software Engineer

Eccalon, LLC • Hanover (MD)

On-site
USD 110,000 - 140,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 170,000
SecDevOps Engineer
SecDevOps Engineer

Jobtailor • Colorado

On-site
USD 150,000 - 190,000
DevSecOps Engineer: Secure CI/CD for DoD Projects
DevSecOps Engineer: Secure CI/CD for DoD Projects

Oshkosh Corporation, Inc. • Michigan

On-site
USD 120,000 - 150,000
DevSecOps Engineer
DevSecOps Engineer

electro soft • Arlington (VA)

On-site
USD 140,000 - 190,000
DevOps Engineer
DevOps Engineer

Arcessio • San Francisco (CA)

On-site
USD 140,000 - 170,000