Jr DevSecOps Engineer

The Phoenix Group

Arlington (VA)

On-site

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Phoenix Group in Arlington, VA seeks a SecDevOps Engineer to design and automate secure cloud infrastructure and CI/CD pipelines across AWS, Azure, and GCP. You will implement Zero Trust architectures, manage credentials with Vault, and integrate identity providers to enforce strict least-privilege controls.

You will build secure deployment workflows, embed SAST/SCA, and support FedRAMP compliance, monitoring, and incident response across multi-cloud environments.

Qualifications

  • 1–2 years of professional SecDevOps, Cloud Security Engineering, Platform Engineering, or DevSecOps experience.
  • Hands-on with at least one major hyperscaler (AWS preferred); working knowledge of Azure and GCP.
  • Advanced skills in Infrastructure as Code (Terraform, Ansible, CloudFormation) and scripting languages (Python, Bash, PowerShell).
  • Proven experience managing enterprise identity/access solutions (Okta, Entra ID) and secrets management platforms (HashiCorp Vault, AWS KMS, Azure Key Vault).
  • Familiarity with security tooling such as endpoint protection (EDR), CSPM, and vulnerability scanners.
  • Strong understanding of containerization and orchestration platforms (Docker, Kubernetes).
  • Practical knowledge of FedRAMP, NIST 800-53, SOC 2 frameworks, or comparable compliance standards.

Responsibilities

  • Support and operate Zero Trust Network Access (ZTNA) architectures, including app connectors, privileged remote access, and private application boundaries, utilizing tools like Zscaler ZPA.
  • Manage privileged credentials, API tokens, and secret lifecycle workflows using HashiCorp Vault, establishing automated credential rotation and lifecycle management.
  • Integrate federated identity providers (Okta, Azure AD / Entra ID, AWS IAM Identity Center) and support multi-cloud identity migration.
  • Enforce least-privilege access policies across cloud environments, automating role-based access controls and credential rotation.
  • Build, automate, and maintain multi-tenant cloud infrastructure across AWS, Azure, and GCP using Terraform as primary, Ansible, CloudFormation.
  • Automate cloud provisioning, configuration management, and application deployment through secure CI/CD pipelines and GitOps processes (ArgoCD, Helm).
  • Configure and manage cloud networking, IAM roles, and network permissions aligning with FedRAMP IL4 controls.
  • Develop and uphold secure CI/CD pipelines using GitHub Actions, GitLab CI, Azure DevOps, or Jenkins, integrating Policy-as-Code frameworks (OPA, HashiCorp Sentinel, Azure Policy).
  • Embed SAST, SCA, and container vulnerability scanning into deployment workflows.
  • Build, deploy, and troubleshoot containerized workloads in Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomize.
  • Support FedRAMP continuous monitoring (ConMon), incident management, POA&M tracking, and remediation activities.
  • Automate audit evidence collection and compliance reporting for controls like CM-2, CM-6, AU-2, SC-.
  • Participate in enterprise change management processes, including documentation and technical review cycles (ServiceNow).
  • Maintain centralized observability infrastructure using Grafana, Prometheus, CloudWatch, and other cloud-native tooling.
  • Define, monitor, and report on SLIs/SLOs for critical cloud security services.
  • Lead incident response efforts, on-call troubleshooting, root cause analysis, and rapid resolution for security and operational issues.

Skills

Zero Trust
CI/CD automation
Cloud security
Infrastructure as Code
GitOps

Tools

Terraform
Ansible
CloudFormation
HashiCorp Vault
Okta

Job description

We are seeking a highly skilled SecDevOps Engineer to lead the design, automation, and maintenance of secure cloud infrastructure and CI/CD pipelines within multi-cloud environments. This role focuses on implementing Zero Trust architectures, continuous security monitoring, and ensuring compliance across federal cloud platforms, integrating security controls into deployment workflows through Infrastructure as Code (IaC) and Policy-as-Code frameworks. The ideal candidate will possess deep cloud architecture expertise, robust automation skills, and a strong security-operations mindset to support secure, compliant, and scalable cloud operations

.

Role Overvi

ewThe SecDevOps Engineer owns the development and management of secure, compliant cloud infrastructures across multiple cloud providers, enhancing automation, security, and observability to ensure robust federal cloud operations and continuous compliance with security standards such as FedRAMP and NIST 800-5

3.

Key Responsibilit
  • iesSupport and operate Zero Trust Network Access (ZTNA) architectures, including app connectors, privileged remote access, and private application boundaries, utilizing tools like Zscaler ZPA / P
  • RA.Manage privileged credentials, API tokens, and secret lifecycle workflows using HashiCorp Vault, establishing automated credential rotation and lifecycle manageme
  • nt.Integrate federated identity providers (Okta, Azure AD / Entra ID, AWS IAM Identity Center) and support multi-cloud identity migratio
  • ns.Enforce strict least-privilege access policies across cloud environments, automating role-based access controls and credential rotatio
  • ns.Build, automate, and maintain multi-tenant cloud infrastructure across AWS, Azure, and Google Cloud Platform (GCP) using Infrastructure as Code (Terraform as primary, Ansible, CloudFormatio
  • n).Automate cloud provisioning, configuration management, and application deployment through secure CI/CD pipelines and GitOps processes (ArgoCD, Hel
  • m).Configure and manage cloud networking, security groups, IAM roles, and network permissions aligning with FedRAMP IL4 contro
  • ls.Develop and uphold secure CI/CD pipelines using tools such as GitHub Actions, GitLab CI, Azure DevOps, or Jenkins, integrating Policy-as-Code frameworks (OPA, HashiCorp Sentinel, Azure Polic
  • y.Embed static application security testing (SAST), software composition analysis (SCA), and container vulnerability scanning into deployment workflo
  • ws.Build, deploy, and troubleshoot containerized workloads in Kubernetes environments (EKS, AKS, GKE) using Helm, ArgoCD, or Kustomi
  • ze.Support FedRAMP continuous monitoring (ConMon), incident management, POA&M tracking, and remediation activiti
  • es.Automate audit evidence collection and compliance reporting for controls like CM-2, CM-6, AU-2, SC-
  • 12.Participate in enterprise change management processes, including documentation and technical review cycles via tools such as ServiceN
  • ow.Maintain centralized observability infrastructure using Grafana, Prometheus, CloudWatch, and other cloud-native tooli
  • ng.Define, monitor, and report on SLIs/SLOs for critical cloud security servic
  • es.Lead incident response efforts, on-call troubleshooting, root cause analysis, and rapid resolution for security and operational issu

es.

Core Qualifications & Requirem
  • ents1-2 years of professional experience in SecDevOps, Cloud Security Engineering, Platform Engineering, or Dev
  • Ops.Hands-on experience with at least one major hyperscaler (preferably AWS); working knowledge of Azure and
  • GCP.Advanced skills in Infrastructure as Code (Terraform, Ansible, CloudFormation) and scripting languages (Python, Bash, PowerShe
  • ll).Proven experience managing enterprise identity/access solutions (Okta, Entra ID) and secrets management platforms (HashiCorp Vault, AWS KMS, Azure Key Vau
  • lt).Familiarity with security tooling such as endpoint protection (EDR), CSPM (Cloud Security Posture Management), and vulnerability scanners (CrowdStrike, Wiz, Qual
  • ys).Strong understanding of containerization and orchestration platforms (Docker, Kubernet
  • es).Practical knowledge of FedRAMP, NIST 800-53, SOC 2 frameworks, or comparable compliance standa

rds.

Nice-to-Have Qualifica
  • tionsCertifications such as HashiCorp Certified: Terraform Associate, AWS Certified SysOps Administrator, Solutions Architect, or Secur
  • ity+.Experience with additional cloud tools and automation framew
  • orks.Familiarity with enterprise change management and incident response processes in government or highly regulated environm

ents.

Core Technical
  • e, GCPInfrastructure as Code: Terraform, CloudFormation, A
  • nsibleScripting Languages: Python, Bash, Powe
  • ure ADSecurity & Compliance Tools: Wiz, Qualys, CrowdStrike, OPA, HashiCorp Se
  • ArgoCDMonitoring & Observability: Grafana, Prometheus, CloudWatch, PagerDuty, Serv
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

The Phoenix Group® • Arlington (VA)

On-site
USD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

The Phoenix Group • Arlington (VA)

On-site
USD 140,000 - 190,000
Sr. DevSecOps Engineer
Sr. DevSecOps Engineer

Oteemo, Inc • College Park (MD)

On-site
USD 120,000 - 160,000
DevSecOps Engineer
DevSecOps Engineer

electro soft • Arlington (VA)

On-site
USD 140,000 - 190,000
DevSecOps Engineer
DevSecOps Engineer

Socket.dev • Arlington (VA)

On-site
USD 120,000 - 150,000
DevSecOps Lead/Architect
DevSecOps Lead/Architect

UsefulBI • Alameda (CA)

Hybrid
USD 180,000 - 240,000
Onsite work 4 days/week
Exposure to regulatory compliance
DevSecOps Engineer
DevSecOps Engineer

Occam Solutions • Arlington (VA)

On-site
USD 140,000 - 190,000
DevSecOps Engineer
DevSecOps Engineer

Jobtailor • Washington

On-site
USD 140,000 - 210,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Smart Synergies • McLean (VA)

Hybrid
USD 170,000 - 230,000
DevSecOps Engineer
DevSecOps Engineer

Occam Solutions, Inc • Arlington (VA)

On-site
USD 150,000 - 190,000