DevSecOps Engineer (SMA 3)

E-Logic, Inc.

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

E-Logic, Inc. is seeking a highly skilled DevSecOps Engineer to support the Congressional Budget Office (CBO) under the SENTRY BPA. The role involves IaC, CaC, CI/CD, and container orchestration with a focus on Shift-Left security, NIST SP 800-53, and FISMA compliance.

You will integrate with CBO's engineering teams, extending Terraform/OpenTofu, Ansible, GitHub Actions, Docker, and Kubernetes, while ensuring secure code delivery and secret management using vaults.

Qualifications

  • Active Top Secret (TS) security clearance required.
  • Hands-on experience with core DevSecOps toolchain.
  • Experience with Terraform/OpenTofu and Ansible.
  • Experience with GitHub Actions and CI/CD pipelines.
  • Experience with Docker and Kubernetes; container security scanning.
  • Familiarity with security scanning tools (Trivy, Grype, Checkov, Semgrep, Gitleaks).
  • Scripting in Python and Bash; Git workflows.

Responsibilities

  • Maintain and improve Terraform and OpenTofu to provision cloud/hybrid infra.
  • Develop Ansible playbooks and roles for config automation and deployment.
  • Build and refine GitHub Actions workflows for CI/CD and security gates.
  • Manage Docker images and Kubernetes manifests and Helm charts.
  • Integrate SAST/DAST tools and enforce CIS benchmarks and baselines.
  • Use Vault for secrets management within pipelines and infrastructure.

Skills

Scripting (Python & Bash)
Git-based workflows
Security by design
Threat modeling

Tools

Terraform
OpenTofu
Ansible
GitHub Actions
Docker
Kubernetes
Helm
HashiCorp Vault
Trivy
Grype
Checkov
Semgrep
Gitleaks

Job description

Job Description

We are looking for a highly skilled and proactive DevSecOps Engineer to join our team supporting the Congressional Budget Office (CBO) under the SENTRY Blanket Purchase Agreement (BPA). As a DevSecOps Engineer, you will integrate seamlessly with CBO's engineering team to build upon established procedures and guidelines, contributing meaningfully across Infrastructure as Code (IaC), Configuration as Code (CaC), CI/CD pipeline development, and container orchestration. You will inherit existing patterns, adhere to CBO engineering standards, and incrementally enhance capabilities within an active production environment. You will integrate security practices throughout the software delivery lifecycle (Shift-Left security) and support NIST SP 800-53 and FISMA compliance requirements.

Job Description

We are looking for a highly skilled and proactive DevSecOps Engineer to join our team supporting the Congressional Budget Office (CBO) under the SENTRY Blanket Purchase Agreement (BPA). As a DevSecOps Engineer, you will integrate seamlessly with CBO's engineering team to build upon established procedures and guidelines, contributing meaningfully across Infrastructure as Code (IaC), Configuration as Code (CaC), CI/CD pipeline development, and container orchestration. You will inherit existing patterns, adhere to CBO engineering standards, and incrementally enhance capabilities within an active production environment. You will integrate security practices throughout the software delivery lifecycle (Shift-Left security) and support NIST SP 800-53 and FISMA compliance requirements.

Key Responsibilities
  • Infrastructure as Code (IaC): Maintain, extend, and improve existing Terraform and OpenTofu codebases used to provision and manage CBO's cloud and hybrid infrastructure.
  • Configuration as Code (CaC): Develop and maintain Ansible playbooks and roles to automate system configuration, compliance enforcement, patch management, and application deployment.
  • CI/CD Pipeline Development: Build, maintain, and improve GitHub Actions workflows to automate build, test, security scanning, and deployment processes.
  • Container Management: Support containerized application delivery using Docker for image builds and Kubernetes for orchestration; manage Kubernetes manifests and Helm charts.
  • Security Integration: Incorporate SAST/DAST scanning tools into pipelines; enforce CIS benchmarks and CBO security baselines; support NIST SP 800-53 and FISMA compliance requirements.
  • Secrets Management: Utilize secrets management tools (e.g., HashiCorp Vault) to secure sensitive information within pipelines and infrastructure.
Required Qualifications
  • Clearance: Active Top Secret (TS) security clearance is required.
  • Experience: Hands-on experience with the core DevSecOps toolchain.
  • Technical Proficiency: Demonstrated hands-on experience with:
  • Terraform and OpenTofu (module development, remote state management)
  • Ansible (playbook and role development, dynamic inventories)
  • GitHub Actions (workflow development, matrix builds, security gate integration)
  • Docker and Kubernetes (image authoring, Helm charts, container security scanning)
  • Security scanning tools (Trivy, Grype, Checkov, Semgrep, Gitleaks)
  • Scripting: Proficiency in Python and Bash scripting.
  • Version Control: Experience with Git-based workflows, branching strategies, and pull request reviews.
Desired Experience
  • Experience in federal or highly regulated environments.
  • Familiarity with NIST SP 800-53, FISMA, and FedRAMP compliance.
  • Experience with policy-as-code frameworks (OPA/Rego).
  • Cloud platform experience (AWS).

Clearance Requirement: Active Top Secret (TS) security clearance required

Citizenship: U.S. Citizenship is required

Job Type: Full-time

E-Logic, Inc. is an equal opportunity employer and is committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer (SMA 3)
DevSecOps Engineer (SMA 3)

E Logic • Washington

On-site
USD 140,000 - 200,000
DevSecOps Engineer - TS Clearance & Cloud Security
DevSecOps Engineer - TS Clearance & Cloud Security

E Logic • Washington

On-site
USD 140,000 - 200,000
TS-Cleared DevSecOps Engineer: IaC, CI/CD & Security
TS-Cleared DevSecOps Engineer: IaC, CI/CD & Security

E-Logic, Inc. • Washington

On-site
USD 140,000 - 190,000
Dev/Sec Ops Engineer
Dev/Sec Ops Engineer

All Native Group • Washington

On-site
USD 120,000 - 165,000
Cybersecurity Engineer (SMA 5)
Cybersecurity Engineer (SMA 5)

E-Logic, Inc. • Washington

On-site
USD 140,000 - 190,000
Cybersecurity Engineer (SMA 5)
Cybersecurity Engineer (SMA 5)

E Logic • Washington

On-site
USD 150,000 - 190,000
Full Stack Software Developer (SMA 2)
Full Stack Software Developer (SMA 2)

E-Logic, Inc. • Washington

On-site
USD 120,000 - 160,000
DevSecOps Engineer
DevSecOps Engineer

Basecamp Consulting & Solutions LLC • Washington

On-site
USD 120,000 - 180,000
Dev/Sec Ops Engineer
Dev/Sec Ops Engineer

All Native Group, The Federal Services Division of Ho-Chunk Inc. • Washington

Hybrid
USD 120,000 - 170,000
DevSecOps Engineer
DevSecOps Engineer

Info Gain Consulting • McLean (VA)

On-site
USD 120,000 - 170,000