DevSecOps Engineer II

Attainx Inc

Herndon (VA)

Hybrid

USD 104,000 - 107,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

AttainX, Inc. is seeking a DevSecOps Engineer II in Herndon, VA to integrate security across the DocuSign implementation and supporting infrastructure.

You will contribute to secure automation, IaC, and CI/CD practices, working both independently and with architects, developers, and security engineers. Role requires 3-5 years in DevSecOps or related fields, a BS in a computing discipline, and experience with SAST/DAST/SCA and security testing.

Qualifications

  • 3-5 years of DevSecOps, software engineering, infrastructure automation, or security engineering.
  • A bachelor’s degree in computer science, cybersecurity, information systems, engineering, or a related field.
  • Proficiency with CI/CD tools such as Jenkins, GitLab, or Azure DevOps, including pipeline automation, IaC, and controlled deployments.
  • Experience with SAST, DAST, SCA, vulnerability scanning, and penetration testing frameworks.
  • Experience programming or scripting in Python, Perl, Bash, PHP, PowerShell, Java, SQL, or C++.
  • Knowledge of security principles, encryption, authentication, authorization, and secret handling.
  • Experience with REST APIs, connectors, webhooks, SaaS integrations; DocuSign integration preferred.
  • Experience supporting lifecycle testing, Federal security requirements, and Section 508 compliance.
  • Ability to work independently and collaborate with architects, developers, and security engineers.
  • Must be a US Citizen able to obtain DHS CISA Public Trust clearance.

Responsibilities

  • Integrate security practices throughout development, testing, deployment, and operation of DocuSign integrations and supporting infrastructure.
  • Design, implement, and maintain security controls across CI/CD pipelines; automate SAST/DAST/SCA and other checks.
  • Perform regular security assessments, vulnerability scanning, and authorized penetration testing within approved scope.
  • Implement Infrastructure as Code, automated testing, and controlled release procedures for secure delivery.
  • Configure and maintain DocuSign accounts, groups, templates, routing, policies, and security settings.
  • Build and maintain plugins, connectors, and custom APIs for DocuSign integrations with Microsoft 365 and enterprise identity platforms.
  • Implement encryption, secure authentication, authorization, RBAC, network protection, and secret handling; monitor threats.
  • Develop and enforce security policies aligned with Federal, DHS, and CISA requirements.
  • Execute tests; document defects, findings, remediation, and deployment readiness.
  • Automate document conversion and records capture with NARA-compliant formats and metadata.

Skills

CI/CD tools
Jenkins
GitLab
Azure DevOps
SAST
DAST
SCA
Python
PowerShell
DocuSign

Education

Bachelor's degree

Tools

DocuSign
Microsoft 365
APIs

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Full Time Professional Herndon, VA, US

Salary Range: $104,000.00 To $107,000.00 Annually

Location:

Remote/Hybrid - DHS CISA; approved remote work location within the 50 United States or the District of Columbia. Government facility attendance may be required.

Work Schedule:

Monday through Friday, 8:00 a.m. to 5:00 p.m. Eastern Time; core availability 9:00 a.m. to 3:00 p.m., excluding federal holidays.

Security Requirements:

Must obtain and maintain a favorable DHS/CISA Entry on Duty or fitness determination and complete the background investigation appropriate to the position’s sensitivity and required access.

Work Authorization:

Must be authorized to work in the United States and meet DHS/CISA personnel and system access requirements.

AttainX is seeking a DevSecOps Engineer II to integrate security practices throughout the DevOps lifecycle for CISA’s DocuSign implementation and integrations, ensuring secure deployment of high-quality IT infrastructure. This role works independently and collaboratively, contributes to moderately complex project activities, and applies secure automation, Infrastructure as Code, and continuous integration and deployment practices.

Qualifications and Education Requirements:
  • 3-5 years of related experience in DevSecOps, software engineering, infrastructure automation, or security engineering.
  • A bachelor’s degree in computer science, cybersecurity, information systems, engineering, or a related field.
  • Proficiency with CI/CD tools such as Jenkins, GitLab, or Azure DevOps, including pipeline automation, version control, Infrastructure as Code, and controlled deployments.
  • Experience with static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), vulnerability scanning, and penetration testing frameworks.
  • Experience programming or scripting in one or more languages such as Python, Perl, Bash, PHP, PowerShell, Java, SQL, or C++.
  • Knowledge of security principles, practices, and technologies, including encryption, authentication, authorization, network security, and secure handling of credentials and secrets.
  • Experience with REST APIs, connectors, webhooks, SaaS integrations, and Microsoft 365 or enterprise identity platforms; DocuSign integration experience is preferred.
  • Experience supporting lifecycle testing, technical documentation, Federal security requirements, and Section 508 accessibility compliance.
  • Ability to work independently and collaborate with architects, developers, security engineers, and stakeholders on moderately complex project activities.
  • Must be a US Citizen able to obtain a DHS CISA Public Trust clearance.
Job Duties:
  • Integrate security practices throughout the development, testing, deployment, and operation of DocuSign integrations and supporting infrastructure.
  • Design, implement, and maintain security controls across CI/CD pipelines; automate SAST, DAST, SCA, and other security checks to identify risks before deployment.
  • Perform regular security assessments, vulnerability scanning, and authorized penetration testing within approved scope; prioritize findings and coordinate remediation with development and security teams.
  • Implement Infrastructure as Code, automated testing, and controlled release and rollback procedures to support secure, reliable delivery.
  • Configure and maintain DocuSign accounts, groups, templates, routing rules, administrative settings, policies, alerts, and approved branding.
  • Build and maintain plugins, connectors, and custom APIs for automated envelope creation, routing, and archival; integrate DocuSign with Microsoft 365, enterprise identity systems, and contract or case platforms.
  • Implement encryption, secure authentication, authorization, role-based access, network and boundary protection, and secure credential handling; monitor logs and systems for threats and elevate findings.
  • Develop, maintain, and enforce security policies and procedures aligned with Federal, DHS, and CISA requirements and approved development and deployment practices.
  • Execute developmental and operational tests; document defects, security findings, remediation, test results, and deployment readiness.
  • Automate document conversion and records capture while preserving NARA-compliant formats, metadata consistency, and disposition requirements.
  • Document configurations, deployment procedures, integration architecture, and exception handling; support secure releases and knowledge transfer to system administrators.
  • Stay current with security trends, tools, and technologies; proactively recommend and implement approved improvements to pipeline security, automation, and threat monitoring.
Non-Essential Functions:

Other related duties as assigned.

About Us:

AttainX, Inc. delivers technology solutions, software products, and professional services to Federal Government customers. Our people are central to achieving our customers’ missions. We support quality, collaboration, and employee growth through teamwork and professional development.

  • We are proud to offer competitive compensation and benefits packages, including paid vacation, medical, dental, and vision insurance, a matching 401(k) plan, tuition/training reimbursement, and long- and short-term disability coverage, subject to plan terms and eligibility.
EEO Commitment:

AttainX is an equal employment opportunity employer committed to a workplace free from discrimination. We provide equal opportunity to applicants and employees without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, or any other status protected by applicable law.

Accommodations:

Applicants and employees who need a reasonable accommodation for the application process or to perform essential job functions may contact Human Resources at HR@attainx.com.

Physical Demands:

This position primarily involves computer-based work, reviewing technical materials, and communicating with team members and stakeholders. Essential functions may be performed with or without reasonable accommodation.

Work is performed primarily at an approved remote work location with reliable connectivity, a secure workspace, and proper protection of Government equipment and sensitive information. Government facility attendance may be required, and remote work is subject to DHS and CISA approval. General work hours are 8:00 a.m. to 5:00 p.m. Eastern Time, Monday through Friday, excluding federal holidays, with core availability from 9:00 a.m. to 3:00 p.m. Office noise is generally moderate. Occasional work outside normal hours, including weekends and holidays, may be required for crisis response or critical IT issues.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps Engineer II
DevSecOps Engineer II

Attainx,inc- • Herndon (VA)

Hybrid
USD 104,000 - 107,000
Paid vacation
401(k) matching
Tuition reimbursement
+1
DevSecOps Engineer II
DevSecOps Engineer II

Attainx Inc. • Herndon (VA)

Remote
USD 104,000 - 107,000
Competitive compensation
Paid vacation
Medical, dental, and vision insurance
+3
Cybersecurity Analyst
Cybersecurity Analyst

Attainx Inc • Herndon (VA)

Hybrid
USD 115,000 - 128,000
Applications Architect - Level V
Applications Architect - Level V

Attainx Inc • Herndon (VA)

Hybrid
USD 188,000 - 197,000
Cyber Security Engineer II
Cyber Security Engineer II

Cybersecurity Jobs • Herndon (VA)

Hybrid
USD 115,000 - 128,000
Health insurance
401(k) plan
Tuition reimbursement
+2
Applications Architect - Level V
Applications Architect - Level V

Attainx Inc. • Herndon (VA)

Hybrid
USD 188,000 - 197,000
Paid vacation
Medical, dental, and vision insurance
401(k) with match
+2
Applications Architect - Level V
Applications Architect - Level V

Attainx,inc- • Herndon (VA)

Hybrid
USD 188,000 - 197,000
Paid vacation
Medical insurance
Dental insurance
+4
Software Engineer II
Software Engineer II

Attainx Inc • Herndon (VA)

Hybrid
USD 101,000 - 105,000
Paid vacation
Medical, dental, and vision insurance
401(k) plan with matching
+2
DevSecOps Engineer II — Remote (DHS/CISA)
DevSecOps Engineer II — Remote (DHS/CISA)

Attainx,inc- • Herndon (VA)

Hybrid
USD 104,000 - 107,000
Paid vacation
401(k) matching
Tuition reimbursement
+1
Software Engineer II
Software Engineer II

Attainx Inc. • Herndon (VA)

Hybrid
USD 101,000 - 105,000