DevSecOps Engineer II

ERT, Inc.

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Entarian is seeking a DevSecOps Engineer II to design, secure, and optimize CI/CD pipelines across development, test, and production environments. You will integrate security controls with automated scans, manage containerized workloads in Kubernetes, and implement IaC-based infrastructure provisioning for cloud and hybrid setups.

You will collaborate with cybersecurity teams, maintain test coverage, and contribute to the evolution of DevSecOps practices in line with federal security

Qualifications

  • Bachelor's degree and 8+ years in DevOps, software engineering, or related field.
  • Experience supporting federal agencies or government contracting with security requirements.
  • Expertise delivering CI/CD pipelines across multi-environment architectures.
  • Ability to remediate STIG findings and ensure federal standards.
  • Hands-on with container orchestration and security hardening.
  • Proficiency with IaC (Terraform) and testing strategies.
  • Experience with SAST/DAST tools and secure coding practices.
  • Strong Linux scripting and automation capabilities.

Responsibilities

  • Design, develop, secure, and optimize CI/CD pipelines using industry-leading orchestrator tools.
  • Remediate STIG findings and verify compliance with federal cybersecurity standards.
  • Architect scalable, reliable DevSecOps infrastructure for Kubernetes environments.
  • Maintain automated deployment and configuration workflows with Docker, Kubernetes, Helm.
  • Enforce secure coding, dependency management, and performance improvements.
  • Integrate continuous security controls into pipelines with automated scanning and governance.

Skills

CI/CD pipelines
DevSecOps
SRE practices
Agile Scrum
Communication

Education

Bachelor's degree in Computer Science or related discipline

Tools

Kubernetes
Docker
Helm
Terraform
Jenkins
GitLab
Harness
OpenShift
Buildah
apko

Job description

DevSecOps Engineer II

ID 2026-9743

Type Full Time W/Benefits Ret Match

Location : Location

US-Washington, D.C.

Security Clearance DHS Suitability

Overview/ Job Responsibilities
  • Design, develop, secure, and optimize CI/CD pipelines using industryleading orchestrator tools to enable automated builds, testing, security scanning, and deployments across multiple environments.
  • Analyze, remediate, and verify Security Technical Implementation Guide (STIG) findings, working handson with system stakeholders to ensure compliance, security hardening, and alignment with federal cybersecurity standards.
  • Architect and implement scalable, reliable, and secure DevSecOps infrastructure, including version control systems, automated testing frameworks, and continuous monitoring solutions to support endtoend delivery.
  • Build and maintain automated deployment and configuration management workflows, leveraging containerization technologies (e.g., Docker, Kubernetes) to ensure consistent, repeatable, and secure deployments.
  • Develop, document, and enforce engineering best practices for code quality, secure coding, dependency management, application performance, and compliance with federal regulatory and security requirements.
  • Partner closely with cybersecurity teams to integrate continuous security controls into the pipeline, including automated vulnerability scanning, static/dynamic code analysis, dependency checks, and policy enforcement.
  • Continuously enhance software development processes and procedures, ensuring alignment with evolving mission needs, technology updates, and federal security mandates.
  • Support updates to unit and integration tests, ensuring the test suites and corresponding CI/CD pipelines remain reliable, comprehensive, and aligned with software updates and new feature development.
  • Assist in establishing and maintaining application platform environments across development, test, staging, and preproduction, ensuring proper configuration, monitoring, and performance tuning.
  • Design, develop, maintain, and secure OCIcompliant container images tailored for Kubernetes environments, ensuring compliance with DoD, DHS, or agencyspecific container hardening requirements.
  • Develop Infrastructure as Code (IaC) (e.g., Terraform, CloudFormation, Ansible) to provision scalable, secure, cloudbased environments and automate infrastructure lifecycle management.
  • Support deployment of microservices to cloud or onpremises Kubernetes platforms, ensuring resiliency, fault tolerance, advanced networking configuration, and policybased traffic management.
  • Contribute to new development and continuous enhancement of existing applications, including security patches, feature development, and defect resolution, following Agile SCRUM ceremonies and workflows.
Minimum Qualifications
  • Bachelor's degree in Computer Science or a related technical discipline, with 8+ years of progressive, hands-on experience in DevOps, Software Engineering, or a closely aligned discipline.
  • Demonstrated experience as a Software Developer, DevOps Engineer, or similar role, preferably supporting federal agencies or government contracting environments with stringent security and compliance requirements.
  • Expertise developing, maintaining, and optimizing CI/CD pipelines, enabling automated build, test, security scanning, and deployment workflows across multi-environment architectures.
  • Proven ability to implement, monitor, analyze, remediate, and verify STIG (Security Technical Implementation Guide) findings, ensuring compliance with federal cybersecurity standards.
  • Handson experience with container orchestration and container technologies, including Kubernetes, OpenShift, Docker, and Helm charts, supporting missioncritical workloads in secure environments.
  • Advanced experience with Infrastructure as Code (IaC) and associated testing strategies, particularly using Terraform to provision, scale, and secure cloud and hybrid infrastructure.
  • Proficiency with enterprise DevOps automation platforms such as Harness, Jenkins, and GitLab, with a strong understanding of CI/CD best practices, branching strategies, and pipeline governance.
  • Experience using SAST tools (e.g., Fortify, SonarQube, Xray) to enforce secure coding standards and detect vulnerabilities early in the development lifecycle.
  • Experience using DAST tools (e.g., OWASP ZAP) to continuously assess application security posture in dynamic runtime environments.
  • Background in Site Reliability Engineering (SRE) practices, including reliability automation, SLIs/SLOs, service health monitoring, and production resilience engineering.
  • Experience containerizing applications using OCI-compliant tools such as Docker, Buildah, apko, and applying secure containerization practices aligned with federal compliance.
  • Demonstrated capability securing containerized environments, including applying imagehardening controls, scanning dependencies, and enforcing runtime governance.
  • High proficiency with Linux, including system administration, performance tuning, and shell environment management in production contexts.
  • Proficiency in scripting languages such as Bash, Python, or comparable languages to automate operational workflows and integrate DevSecOps toolchains.
  • Strong understanding of the complete Software Development Lifecycle (SDLC), including secure development practices, quality gates, and release management.
  • Proven experience developing software in an Agile Scrum environment, collaborating with multidisciplinary teams to deliver iterative, highquality software.
  • Experience with systems reliability, load balancing, monitoring, and logging, leveraging enterprise tools to maintain service health and ensure observability across distributed systems.
  • Familiarity with Agile/Scrum methodologies, actively contributing to ceremonies, sprint planning, and continuous improvement initiatives.
  • Excellent communication and collaboration skills, with the ability to interface effectively with both technical and nontechnical stakeholders, translating complex technical concepts into clear actionable insights.

Security Clearance: Must be able to provide proof of US Citizenship and have or are able to attain a Government Agency Suitability Clearance.

Desired Qualifications
  • Handson experience with cyber, information security, and application security tools, including platforms such as Twistlock/Prisma Cloud Compute, SonarQube, Splunk, and similar technologies used for vulnerability detection, monitoring, and compliance enforcement.
  • Proficiency in modern programming and scripting languages, including Groovy, Python, Spring Boot Java, and JavaScript, with the ability to develop automation, tooling, and secure application components.
  • Demonstrated experience applying DevSecOps principles, integrating security throughout the CI/CD pipeline, and implementing automated scanning, compliance checks, and shiftleft security practices.
  • Working knowledge of AWS cloud services, including RDS and other AWS databases, IAM identity and access management, and VPC networking, with the ability to design secure, scalable, cloud-native architectures.
  • Strong understanding of EverythingasCode methodologies, such as InfrastructureasCode, ConfigurationasCode, and PolicyasCode, and familiarity with implementing automated governance, repeatable deployments, and environment consistency.
About Us

Formed through the strategic union of Sev1Tech and ERT, Entarian is a premier provider of mission-critical engineering and technology solutions. Founded on a legacy of excellence dating back to 1993, Entarian is a product of an evolved and fully diversified engineering and federal technology leader. From deep space to defense and civilian missions, Entarian delivers secure, mission-aligned digital solutions that drive national resilience and operational effectiveness. We don't just support modernization; we define it.

Join the Mission and Start your Career Journey:

Entarian is an Equal Opportunity and Aff

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

ERT, Inc. • Mechanicsburg

On-site
USD 120,000 - 170,000
Retirement match
Full benefits
DevSecOps Engineer
DevSecOps Engineer

Worky • Yorktown (VA)

On-site
USD 110,000 - 160,000
Technical Lead
Technical Lead

ERT, Inc. • Arlington (VA)

On-site
USD 120,000 - 170,000
Senior Software Engineer
Senior Software Engineer

Worky • New Orleans (LA)

On-site
USD 120,000 - 160,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Entarian • North Charleston (SC)

On-site
USD 100,000 - 140,000
DevSecOps Engineer
DevSecOps Engineer

Essnova Solutions, Inc. • Washington

Hybrid
USD 120,000 - 180,000
Cybersecurity Compliance Analyst
Cybersecurity Compliance Analyst

ERT, Inc. • Suitland (MD)

On-site
USD 105,000 - 115,000
Medical Insurance
401(k) Retirement Plan with match
Paid Federal Holidays
+1
DevOps Engineer
DevOps Engineer

By Light Professional IT Services • Orlando (FL)

On-site
USD 80,000 - 110,000
Medical, Dental & Vision Coverage
401(k) Matching
Generous Leave Policy
Engineering Technician I/II
Engineering Technician I/II

ERT, Inc. • San Diego (CA)

On-site
USD 68,770,000 - 91,693,000
Senior DevSecOps Engineer - Active TS/SCI with CI Poly
Senior DevSecOps Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLC • Reston (VA), Northern (KY)

On-site
USD 190,000 - 240,000
Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+4