DevSecOps Engineer

Matrixspace

Burlington, Northern (MA, KY)

On-site

USD 125,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

MatrixSpace is seeking a hands-on DevSecOps Engineer to join our Release Engineering team. You’ll build secure AWS environments, automate deployments, and ensure compliance for government customers.

You’ll work across DevOps, security, and compliance to embed FedRAMP and NIST controls into architecture and pipelines, while partnering with engineers and assessors. This role offers opportunities to influence cloud platform reliability and security from inception through ongoing operations.

Qualifications

  • 3-6 years of experience in security engineering, cloud security, DevSecOps, infrastructure security, or a related field.
  • Hands-on AWS experience, including networking, Linux, IAM, encryption, logging, vulnerability management, and security monitoring.
  • Experience with security frameworks such as FedRAMP, NIST 800-53, NIST 800-171, CMMC, RMF, or similar standards.
  • Experience translating security and compliance requirements into practical technical controls with engineering teams.
  • Hands-on experience with DevOps practices, Infrastructure as Code, source control, CI/CD pipelines, and automated deployment workflows.
  • Knowledge of system hardening vulnerability remediation, secure configurations, and security control lifecycle management.
  • Strong problem-solving, communication, and cross-functional collaboration skills.

Responsibilities

  • Build, operate, and secure AWS environments against security baselines, FedRAMP requirements, and other applicable standards.
  • Partner with Software Engineering and AI teams to incorporate security and compliance into system architecture, CI/CD, deployment, and operations.
  • Support FedRAMP authorization and continuous monitoring activities, including evidence collection, POA&Ms, and remediation tracking.
  • Perform security architecture reviews, risk and gap assessments, vulnerability management, and DISA STIGs.
  • Implement security controls across networking, Linux systems, IAM, encryption, logging, and security monitoring.
  • Build and maintain Infrastructure as Code, CI/CD, deployment, and release automation using Terraform, Pulumi, and Python.
  • Maintain security documentation, system diagrams, asset inventories, and control implementation details.
  • Work with engineering teams, external assessors, compliance partners, and 3PAOs to support assessments and evidence requests.
  • Contribute to broader Release Engineering initiatives, including CI/CD pipelines, deployment automation, and platform reliability.

Skills

Security mindset
Cross-functional collaboration
Hands-on problem solving

Tools

AWS
Terraform
Pulumi
Python
DISA STIGs
FedRAMP controls

Job description

Help build, operate, and secure the cloud infrastructure that enables MatrixSpace to deliver trusted technology to U.S. government customers.

MatrixSpace develops AI-enabled radar and sensing systems that help people understand what's happening in the world around them. By combining advanced radar, edge computing, and AI, we deliver situational awareness in environments where traditional sensing solutions struggle.

We're looking for a hands-on DevSecOps Engineer to join our Release Engineering team. You’ll work across DevOps, cloud infrastructure, security, and compliance, to build secure AWS environments, improve deployment and release workflows, and support FedRAMP and other government security requirements.

What You'll Do
  • Build, operate, assess, and secure AWS environments against established security baselines, FedRAMP requirements, and other applicable security standards.
  • Partner with Software Engineering and AI teams to incorporate security and compliance requirements into system architecture, CI/CD, deployment, and operational workflows.
  • Support FedRAMP authorization and continuous monitoring activities, including evidence collection, control maintenance, audit preparation, Plans of Action and Milestones (POA&Ms), and remediation tracking.
  • Perform and support security architecture reviews, risk and gap assessments, vulnerability management, and system hardening, including applicable DISA STIGs.
  • Implement security controls across networking, Linux systems, IAM, encryption, logging, and security monitoring.
  • Build and maintain Infrastructure as Code, CI/CD, deployment, and release automation using tools such as Terraform, Pulumi, and Python, incorporating security and compliance into repeatable infrastructure deployments.
  • Maintain required security documentation, system diagrams, asset inventories, and control implementation details.
  • Work with engineering teams, external assessors, compliance partners, and 3PAOs to support assessments, audits, evidence requests, and ongoing authorization requirements.
  • Contribute to broader Release Engineering initiatives, including CI/CD pipelines, deployment automation, release workflows, cloud infrastructure, developer tooling, and platform reliability.
What We're Looking For

This position requires working directly or indirectly with the US Government in restricted environments. Candidates must be legally authorized to work in the United States without employer sponsorship and may be required to obtain and maintain a U.S. government security clearance in the future.

Required
  • 3-6 years of experience in security engineering, cloud security, DevSecOps, infrastructure security, or a related technical field.
  • Hands-on AWS experience, including networking, Linux, IAM, encryption, logging, vulnerability management, and security monitoring.
  • Experience working with one or more security frameworks such as FedRAMP, NIST 800-53, NIST 800-171, CMMC, RMF, or similar standards.
  • Experience translating security and compliance requirements into practical technical controls alongside engineering teams.
  • Hands-on experience with DevOps practices, Infrastructure as Code, source control, CI/CD pipelines, and automated deployment workflows.
  • Knowledge of system hardening vulnerability remediation, secure configurations, and security control lifecycle management.
  • Strong problem-solving, communication, and cross-functional collaboration skills.
Someone Who Will Thrive in This Role
  • Enjoys being hands-on with infrastructure, automation, security, and release engineering.
  • Can move comfortably between technical implementation, compliance requirements, documentation, and conversations with engineers and assessors.
  • Take ownership of issues from identification through remediation and closure.
  • Prefers building security into engineering workflows rather than treating it as a separate audit function.
  • Is curious about how complex systems work and looks for ways to make security and compliance more automated, repeatable, and scalable.
Bonus Points
  • Direct experience supporting a FedRAMP authorization, particularly within a FedRAMP High environment.
  • Familiarity with AWS GovCloud and NIST 800-53 Experience working directly with external assessors, compliance partners, or a Third-Party Assessment Organization (3PAO).
  • Understanding FIPS 140, encryption and key management, secure system boundaries, and requirements associated with Controlled Unclassified Information (CUI).
  • Experience hardening Linux operating systems using DISA STIGs or similar security configuration standards.
  • Experience with Infrastructure as Code technologies such as Terraform or Pulumi, and/or Python automation.

At MatrixSpace, Release Engineering plays a key role in building the infrastructure, automation, and security foundation behind the systems we deliver to our government customers. You'll help build and operate our cloud platform, improve how we deploy and release software, and ensure security and compliance are built into our infrastructure from the start.

Compensation range: $125,000 - $150,000. Actual position within the range will be determined based on experience level of the candidate.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

Credence • Illinois

On-site
USD 150,000 - 180,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Credence • McLean (VA)

On-site
USD 150,000 - 180,000
ME00631-Senior DevSecOps Engineer Lead (Hybrid)
ME00631-Senior DevSecOps Engineer Lead (Hybrid)

Momentum Engineering, Inc • Washington

Hybrid
USD 130,000 - 170,000
11 paid holidays
3 weeks PTO
Medical plan
+4
DevSecOps Engineer
DevSecOps Engineer

Occam Solutions, Inc • Arlington (VA)

On-site
USD 150,000 - 190,000
Devsecops Engineer
Devsecops Engineer

TEKsystems • Reston (VA)

On-site
USD 117,000 - 145,000
Medical, dental & vision
401(k) plan
Life Insurance
+2
DevSecOps Engineer
DevSecOps Engineer

Air • Pittsburgh

On-site
USD 120,000 - 150,000
InfraSec Engineer
InfraSec Engineer

ASI • Washington

On-site
USD 120,000 - 180,000
InfraSec Engineer
InfraSec Engineer

ASI • Boston (MA)

On-site
USD 120,000 - 190,000
Jr DevSecOps Engineer
Jr DevSecOps Engineer

The Phoenix Group • Arlington (VA)

On-site
USD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

ShorePoint • Herndon (VA)

On-site
USD 120,000 - 180,000
Health insurance
401k
Education assistance