Government and Infrastructure - Cybersecurity - DevSecOps Senior Engineer

Cybersecurity Jobs

McLean (VA)

On-site

USD 105,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical and dental coverage
Pension and 401(k) plans
Paid time off and flexible vacation

Job summary

EY is hiring a Senior DevSecOps Engineer to support its Government & Infrastructure cybersecurity team in McLean, VA. You will design secure CI/CD pipelines, automate evidence for authorization, and ensure security is embedded throughout the software lifecycle with mapping to authorization and control traceability.

The role focuses on evaluating delivery toolchains, security postures, and governance for continuous authorization to operate (cATO) and NIST SP 800-53 compliance.

Qualifications

  • Bachelor's degree or equivalent practical experience.
  • 3–6+ years of experience in DevOps, software engineering, or security engineering.
  • Hands-on CI/CD pipeline engineering with Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
  • Experience with at least one application security scanning tool (Fortify, Checkmarx, SonarQube, Snyk, Trivy, OWASP ZAP).
  • Working knowledge of containers and Infrastructure-as-Code.
  • Scripting skills in Python, PowerShell, or Bash.
  • Understanding of NIST RMF, NIST SP 800-53, and secure software development lifecycle practices.
  • Ability to obtain and maintain a secret clearance.
  • Willingness to work in-person in the Washington, DC area.

Responsibilities

  • Assess application delivery toolchain and practices, including CI/CD and artifact management, and identify gaps.
  • Evaluate security posture and POA&Ms to inform rationalization.
  • Design, build, and maintain secure CI/CD pipelines with SAST/DAST, software composition analysis, and image scanning.
  • Implement policy-as-code and automated evidence collection for continuous cATO and NIST-53 traceability.
  • Harden container images and environments to DISA STIGs/CIS benchmarks.
  • Integrate governance gates for AI-assisted development and traceability of AI-generated code.
  • Define DevSecOps patterns and reusable pipeline templates; report on DORA metrics and vulnerabilities.
  • Support vulnerability triage and remediation with client cybersecurity stakeholders.
  • Own DevSecOps architecture and toolchain standards for the team.
  • Lead security-posture assessment methodology and ensure consistent scoring across portfolio.
  • Serve as primary security engineering contact for client stakeholders and prepare authorization artifacts.
  • Mentor Staff DevSecOps engineer and promote secure engineering practices.

Skills

DevOps
Security engineering
CI/CD pipelines
Python scripting

Education

Bachelor's degree or equivalent

Tools

Jenkins
GitHub Actions
GitLab CI
Azure DevOps
Fortify
Checkmarx
SonarQube
Snyk
Trivy
OWASP ZAP
Terraform
Ansible
Datadog

Job description

EY is hiring a Senior DevSecOps Engineer to support its Government & Infrastructure cybersecurity team in McLean, VA. In this role, you will evaluate how applications are delivered and how mature their security practices are, then help modernize software delivery by designing secure CI/CD pipelines and automated evidence for authorization activities. The work focuses on ensuring security is embedded into the software lifecycle and mapped to authorization and control traceability requirements.

This position will be based onsite in the Washington, DC area as needed, with responsibilities spanning application delivery toolchain assessment, security posture evaluation, and governance-driven automation for continuous Authorization to Operate (cATO) and NIST SP 800-53.

Responsibilities
  • Assess each application’s delivery toolchain and practices, including source control, build and release automation (for example, Jenkins and Bitbucket), artifact management (Artifactory), code quality (SonarQube), Infrastructure-as-Code and configuration management (Terraform, Ansible), and monitoring (Datadog), and identify manual release steps and gaps.
  • Assess application security posture as an input to rationalization, including open vulnerabilities, outdated or vulnerable dependencies, SBOM availability, secrets handling, authentication patterns, and POA&Ms.
  • Design, build, and maintain secure CI/CD pipelines for the modernization factory with integrated SAST/DAST, software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection, and quality gates.
  • Implement policy-as-code and automated evidence collection to support continuous cATO and NIST SP 800-53 control traceability.
  • Harden container images and environments against applicable security configuration benchmarks such as DISA STIGs or CIS Benchmarks.
  • Integrate governance gates for AI-assisted development, covering provenance, human review, and traceability for AI-generated code.
  • Define reference DevSecOps patterns and reusable pipeline templates for future modernization waves, and report delivery and security metrics such as DORA metrics and vulnerability aging.
  • Support vulnerability triage and remediation guidance and collaborate with client cybersecurity and authorization stakeholders.
  • Own the team’s DevSecOps architecture and toolchain standards.
  • Lead the security-posture assessment methodology and ensure findings are scored consistently across the portfolio.
  • Serve as the primary security engineering contact for client cybersecurity stakeholders and prepare artifacts for authorization reviews.
  • Mentor the Staff DevSecOps engineer and promote secure engineering practices across the team.
Requirements
  • Bachelor’s degree in computer science, software engineering, information systems, computer engineering, or a related field, or equivalent practical experience.
  • 3-6+ years of experience in DevOps, software engineering, or security engineering.
  • Hands-on CI/CD pipeline engineering with tools such as Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
  • Experience with at least one application security scanning tool, for example Fortify, Checkmarx, SonarQube, Snyk, Trivy, or OWASP ZAP.
  • Working knowledge of containers and Infrastructure-as-Code.
  • Scripting skills in Python, PowerShell, or Bash.
  • Understanding of the NIST Risk Management Framework, NIST SP 800-53, and secure software development lifecycle practices.
  • Must be able to obtain and maintain a secret level clearance.
  • Comfort with working in-person as needed in the Washington, DC area.
Technologies
  • Jenkins, Bitbucket, Artifactory, SonarQube
  • Terraform, Ansible, Datadog
  • SAST, DAST, software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection
  • Policy-as-code, cATO, NIST SP 800-53, DISA STIGs, CIS Benchmarks
  • AI-assisted development, DORA metrics
  • GitHub Actions, GitLab CI, Azure DevOps
  • Fortify, Checkmarx, Snyk, Trivy, OWASP ZAP
  • NIST Risk Management Framework, Python, PowerShell, Bash
  • Kubernetes security and policy engines (OPA/Gatekeeper, Azure Policy)
  • CycloneDX, SPDX, SBOM, SBOM tooling
Benefits
  • Comprehensive compensation and benefits package
  • Medical and dental coverage
  • Pension and 401(k) plans
  • Paid time off options, including a flexible vacation policy
  • Time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence

Location: McLean (onsite). Salary range: USD 104,800 - 209,700 per year. Date: Oct 2, 2026. Requisition ID: 1749123.

Due to the nature of government and public sector work, completion may be required at client, EY, and/or contractor sites, and travel of 20-30% or more may be required based on client and project needs. Assignments may be within a commutable distance of the office.

Ideally, You’ll Also Have
  • Experience supporting continuous ATO or FedRAMP authorizations and managing POA&Ms.
  • Kubernetes security and policy engines (OPA/Gatekeeper, Azure Policy).
  • SBOM tooling and standards (CycloneDX, SPDX).
  • Certifications such as CompTIA Security+, CISSP, CCSP, Certified Kubernetes Security Specialist (CKS), or relevant GIAC certifications.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Government and Infrastructure - Cybersecurity - DevSecOps Engineer
Government and Infrastructure - Cybersecurity - DevSecOps Engineer

Ernst & Young Advisory Services Sdn Bhd • McLean (VA)

On-site
USD 83,000 - 136,000
Government and Infrastructure - Cybersecurity - DevSecOps Senior Engineer
Government and Infrastructure - Cybersecurity - DevSecOps Senior Engineer

Ernst & Young Advisory Services Sdn Bhd • McLean (VA)

On-site
USD 105,000 - 192,000
Senior DevSecOps Engineer - Government & Infra
Senior DevSecOps Engineer - Government & Infra

Cybersecurity Jobs • McLean (VA)

On-site
USD 105,000 - 210,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off and flexible vacation
Government and Infrastructure - Digital Engineering - Cloud Modernization Engineer
Government and Infrastructure - Digital Engineering - Cloud Modernization Engineer

Ernst & Young Advisory Services Sdn Bhd • McLean (VA)

On-site
USD 90,000 - 150,000
Government and Infrastructure - Service Delivery Center - Cybersecurity - ISSO Analyst
Government and Infrastructure - Service Delivery Center - Cybersecurity - ISSO Analyst

Ernst & Young Advisory Services Sdn Bhd • San Antonio (TX)

Hybrid
USD 61,000 - 105,000
Government and Infrastructure - Digital Engineering - Application Modernization Engineering Manager
Government and Infrastructure - Digital Engineering - Application Modernization Engineering Manager

Ernst & Young Advisory Services Sdn Bhd • McLean (VA)

On-site
USD 140,000 - 240,000
Medical and dental coverage
Pension/401(k)
Paid time off
SDC BCM Tech DevOps Engineer-Senior-Dallas
SDC BCM Tech DevOps Engineer-Senior-Dallas

Ernst & Young Oman • Fort Worth (TX)

Remote
USD 67,000 - 137,000
Hybrid work model
Total rewards package
Paid time off
SDC BCM Tech DevOps Engineer-Senior-Dallas
SDC BCM Tech DevOps Engineer-Senior-Dallas

Ernst & Young Oman • Charlotte (NC)

Remote
USD 67,000 - 137,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1
DevSecOps Engineer
DevSecOps Engineer

Softek Llc • Rockville (MD)

On-site
USD 90,000 - 120,000
SDC BCM Tech DevOps Engineer-Senior-Dallas
SDC BCM Tech DevOps Engineer-Senior-Dallas

Ernst & Young Oman • Chattanooga (TN)

Hybrid
USD 67,000 - 137,000
Total Rewards package
Hybrid work model
Paid time off