DevSecOps Engineer (TS Cleared Only)

HyerTek

Brookeville (MD)

Hybrid

USD 150,000 - 190,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision insurance
401(k) with employer contribution
PTO and holidays
Professional development and certs
Employee assistance program

Job summary

HyerTek is seeking a Sr. DevSecOps Engineer to own the software supply chain and delivery pipeline behind federal solutions, from commit to accreditation in Azure Government enclaves.

The role is hybrid on‑site at Fort Meade, with 2‑3 days in accredited facilities and relocation within commuting distance of Baltimore–Washington. You will design and maintain secure CI/CD pipelines, build hardened container images for AKS/OpenShift, integrate automated security checks, manage SBOMs and artifact

Qualifications

  • 5+ years of hands‑on DevOps or DevSecOps engineering experience in security‑sensitive environments.
  • Strong knowledge of GitHub Enterprise, Actions, and self‑hosted runners.
  • Experience designing and maintaining CI/CD pipelines in GitHub Enterprise and Azure DevOps.
  • Experience building secure container images with hardened base images and non‑root runtimes.
  • Production experience with Kubernetes platforms (AKS/OpenShift) including deployments and secrets integration.
  • Experience integrating automated security controls into CI/CD pipelines (source, dependencies, secrets, containers).
  • Familiarity with SBOM generation, artifact signing, provenance, and artifact promotion.
  • Proficiency with Terraform, Bicep/ARM or similar IaC.
  • Experience with Azure services like Key Vault, Monitor, and Sentinel.
  • Strong scripting/automation skills (Python, PowerShell, Node.js, C#/.NET).
  • Excellent troubleshooting and documentation skills.
  • DoD 8570/8140 IAT II certification and TS‑clearance preferred.

Responsibilities

  • Design, maintain, and improve secure CI/CD pipelines across repositories and environments.
  • Build and maintain secure containerized apps for Kubernetes platforms such as AKS/OpenShift.
  • Integrate automated security and compliance checks to ensure findings are resolved before release.
  • Manage SBOMs, artifact signing, provenance, and controlled promotion between environments.
  • Manage secrets and configuration with approved vault solutions.
  • Automate RMF/ATO evidence, monitoring, and security reporting.
  • Improve observability, reliability, and disaster recovery practices.
  • Partner with developers and cybersecurity teams to resolve vulnerabilities and optimize delivery.
  • Create technical runbooks and customer‑handoff materials.

Skills

DevSecOps engineering
CI/CD pipelines
GitHub Actions
Azure DevOps
Kubernetes
SBOMs / software supply chain
Terraform
Scripting / automation
Security controls
RMF / ATO

Education

Bachelor's degree in a related field

Tools

GitHub Enterprise Server
OpenShift
AKS
Azure Key Vault

Job description

HyerTek is a federal technology consulting firm delivering secure enterprise applications, data analytics, and modernization services to federal government agencies. HyerTek is hiring a Sr. DevSecOps Engineer to own the software supply chain and delivery pipeline behind our federal solutions — from a developer's commit through hardened container build, automated security gating, signed artifact, and accredited release into Azure Government enclaves at DoD Impact Levels 5, 6. and into sensitive compartmented environments. You will make security a property of the pipeline rather than a review at the end of it, and you will produce the continuous evidence that keeps an Authority to Operate current.

Location: This is a hybrid on‑site position at Fort George G. Meade, Maryland. Candidates must be located in, or willing to relocate to, the Baltimore–Washington corridor within commuting distance of Fort Meade. Work is performed in accredited/SCIF facilities at least 2-3 days per week.

Requirements
  • Design, maintain, and improve secure CI/CD pipelines using GitHub Actions and Azure DevOps across multiple repositories and environments, including disconnected or air‑gapped deployments.
  • Build and maintain secure containerized applications for Kubernetes platforms such as AKS and OpenShift.
  • Integrate automated security and compliance checks into development pipelines, ensuring critical findings are resolved before release.
  • Implement secure artifact management practices, including software bills of materials (SBOMs), artifact signing, provenance, and controlled promotion between environments.
  • Manage secrets and environment‑specific configuration using approved vault and configuration‑management solutions.
  • Automate compliance evidence, configuration monitoring, audit logging, and security reporting in support of RMF and ATO requirements.
  • Improve application and pipeline observability, reliability, and operational readiness through logging, monitoring, testing, and incident‑response practices.
  • Develop and validate backup, recovery, and disaster‑recovery procedures with documented recovery objectives.
  • Partner with developers, cybersecurity engineers, and operations teams to resolve vulnerabilities, improve delivery processes, and support production deployments.
  • Create clear technical documentation, operational runbooks, and customer-handoff materials.
Required Qualifications
  • 5+ years of hands‑on DevOps or DevSecOps engineering experience, including responsibility for production CI/CD pipelines in a regulated or security‑sensitive environment.
  • Strong working knowledge of GitHub Enterprise, including GitHub Actions, repository and organization configuration, access controls, branch protection or rulesets, reusable workflows, and self‑hosted runners.
  • Experience designing and maintaining CI/CD pipelines in GitHub Enterprise and Azure DevOps across multiple repositories and environments.
  • Experience building secure container images using hardened base images, multi‑stage builds, vulnerability scanning, minimal dependencies, and non‑root runtimes.
  • Production experience with Kubernetes platforms such as AKS or OpenShift, including deployment configuration, health probes, secrets integration, and admission‑policy requirements.
  • Experience integrating automated security controls into CI/CD pipelines, including source‑code, dependency, secret, container, and infrastructure‑as‑code scanning.
  • Working knowledge of secure software supply‑chain practices, including SBOM generation, artifact signing, provenance, and controlled artifact promotion.
  • Proficiency with Infrastructure as Code using Terraform, Bicep/ARM, or a comparable technology.
  • Experience with Azure services such as Key Vault, managed identities, Azure Policy, Azure Monitor, Log Analytics, or Microsoft Sentinel.
  • Strong scripting and automation skills using Python, PowerShell, JavaScript/Node.js, C#/.NET, or a comparable language.
  • Strong Linux fundamentals and command‑line troubleshooting skills.
  • Familiarity with secrets management, centralized logging, monitoring, backup, recovery, and disaster‑recovery practices.
  • Excellent troubleshooting, documentation, and stakeholder communication skills.
  • Ability to work independently and manage priorities across multiple concurrent engagements.
  • DoD 8570/8140 IAT Level II certification, with Security+ CE or an accepted equivalent.
  • Active Department of Defense Top Secret clearance. Candidates must maintain their clearance and be SCI‑eligible and willing to be read in.
Preferred Qualifications
  • Active TS/SCI clearance.
  • Experience with GitHub Enterprise Server in disconnected or air‑gapped environments.
  • Experience delivering solutions in Azure Government or DoD Impact Level 5 or higher environments.
  • Familiarity with RMF, NIST SP 800-53, DISA STIGs, and the DoD Cloud Computing SRG.
  • Experience with DoD Iron Bank, Platform One, or comparable hardened‑container programs.
  • Experience supporting an RMF authorization, continuous ATO initiative, or automated compliance‑evidence pipeline.
  • Experience transferring software artifacts into air‑gapped or cross‑domain environments.
  • Experience with Kubernetes policy tools such as OPA/Gatekeeper or Kyverno.
  • Experience implementing artifact attestation, signing, provenance, or software supply‑chain policy enforcement.
  • Experience with production secrets rotation, SIEM integration, audit‑log retention, and tested disaster‑recovery procedures.
  • CISSP, CASP+, or another advanced security certification.
HyerTek Offers a Comprehensive Benefits Package, Including
  • Medical, dental, and vision insurance
  • 401(k) with employer contribution
  • Paid time off (PTO) and company holidays
  • Professional development and certification support
  • Employee assistance program (EAP)
  • Life and disability insurance
Clearance & Work Authorization

This position requires U.S. citizenship and an active TS clearance with the Department of Defense. TS/SCI is strongly preferred, and candidates holding TS must be SCI‑eligible; the work is expected to require SCI access, and HyerTek will sponsor the read‑in for an otherwise qualified candidate. Candidates must be authorized to work in the United States without the need for employment‑based visa sponsorship now or in the future.

Salary Range

$150,000 – $190,000 annually, depending on experience and clearance status.

Equal Employment Opportunity (EEO)

HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer (TS Cleared Only)
DevSecOps Engineer (TS Cleared Only)

HyerTek, Inc. • Northern (KY)

Hybrid
USD 150,000 - 190,000
Medical, dental, and vision insurance
401(k) with employer contribution
Paid time off and company holidays
+3
Full Stack Developer (TS Cleared Only)
Full Stack Developer (TS Cleared Only)

HyerTek, Inc. • Fort Meade (MD)

On-site
USD 140,000 - 180,000
Medical, dental, and vision insurance
401(k) with employer contribution
Paid time off
+4
Full Stack Developer (TS Cleared Only)
Full Stack Developer (TS Cleared Only)

Worky • Fort Meade (MD)

On-site
USD 140,000 - 180,000
Medical, dental, and vision insurance
401(k) with employer contribution
Paid time off and company holidays
+1
Microsoft Azure Cloud Engineer (TS Cleared)
Microsoft Azure Cloud Engineer (TS Cleared)

HyerTek, Inc. • Fort Meade (MD)

On-site
USD 160,000 - 180,000
Medical, dental, and vision insurance
401(k) with employer contribution
PTO and company holidays
+3
Microsoft Azure Cloud Engineer (TS Cleared)
Microsoft Azure Cloud Engineer (TS Cleared)

HYERTEK INC • Fort Meade (MD)

On-site
USD 160,000 - 180,000
Medical, dental, vision insurance
401(k) with employer contribution
Paid time off and holidays
+1
Talent Specialist
Talent Specialist

HyerTek • Rockville (MD)

Hybrid
USD 80,000 - 90,000
Medical, dental, and vision insurance
401(k) with employer contribution
Paid time off and holidays
+4
Systems Business Analyst / Requirements Lead (TS Cleared Only)
Systems Business Analyst / Requirements Lead (TS Cleared Only)

HyerTek • Brookeville (MD)

On-site
USD 125,000 - 140,000
Medical, dental, and vision insurance
401(k) with employer contribution
Paid time off and holidays
+3
DevOps Engineer (Senior) w/Secret Clearance
DevOps Engineer (Senior) w/Secret Clearance

TekSynap • United States

Remote
USD 100,000 - 140,000
Health insurance
Dental insurance
Vision insurance
+6
Senior DevSecOps Engineer: DoD Cloud & Secure CI/CD
Senior DevSecOps Engineer: DoD Cloud & Secure CI/CD

HyerTek • Brookeville (MD)

Hybrid
USD 150,000 - 190,000
Medical, dental, and vision insurance
401(k) with employer contribution
PTO and holidays
+2
Senior DevOps Engineer - 28026
Senior DevOps Engineer - 28026

Wyetech • Fort Meade (MD)

On-site
20% gross compensation to SEP IRA
Up to 200 hours PTO annually
Various voluntary benefit plans