Engineering Contract On-site, Washington, DC
XCell was born out of a passion for using the power of design to transform organizations in ways that build up our communities. We work in small, fast-paced agile teams that use Design Thinking to help Government, Non‑Profit and Educational organizations solve complex challenges. We value our team and culture — finding the right fit takes time, and we believe in hiring slow.
- U.S. citizenship is required.
- Must be U.S.-based and able to work on-site in Washington, DC.
- Must be able to pass a federal background investigation and suitability determination for access to the customer’s systems and facilities.
What it looks like
We are looking for a Mid‑Level DevSecOps Engineer to join a federal engineering team in Washington, DC and help extend its infrastructure automation, CI/CD pipelines, container orchestration, and secure delivery. This is not a build‑from‑scratch role. You will inherit existing patterns, adhere to the team’s standards, and improve capabilities inside an active production environment. Candidates must be U.S. citizens, U.S.-based, and able to work on‑site in DC.
In this role you will:
- Infrastructure as code: maintain, extend, and refactor Terraform and OpenTofu, including modular configurations, remote state, and workspace management.
- Configuration as code: develop and maintain Ansible playbooks and roles, using dynamic inventories and Ansible Vault for secrets.
- CI/CD: build and improve GitHub Actions workflows with security gates, including static analysis, dependency and secrets scanning, and policy‑as‑code validation.
- Containers: author and harden Dockerfiles, manage Kubernetes manifests and Helm charts, support namespace and RBAC configuration, and help with cluster health and image scanning.
- Security integration: embed SAST and DAST scanning in pipelines, enforce CIS benchmarks and customer security baselines, and support NIST and FISMA compliance.
- Team delivery: work within the team’s version control, change management, and peer‑review workflows; participate in stand‑ups, sprint planning, and technical reviews; and document your work.
What we are looking for
- Infrastructure as code: hands‑on Terraform and OpenTofu, including module development, remote state, and workspace management.
- Configuration as code: proficiency with Ansible, including playbook and role development, dynamic inventories, and Ansible Vault.
- CI/CD: experience designing and maintaining GitHub Actions workflows, including reusable workflows, matrix builds, and security‑gate integration.
- Containers: working knowledge of Docker image authoring and hardening, Kubernetes and Helm, and container scanning tools such as Trivy or Grype.
- Security integration: familiarity with SAST tools (Semgrep, Checkov, tfsec), secrets scanning (Gitleaks, Detect‑Secrets), and policy‑as‑code (OPA/Rego).
- Version control: strong Git workflow skills, including branching strategies, pull‑request reviews, and protected branches.
Nice‑to‑have
- Experience in a federal or highly regulated environment.
- Familiarity with NIST SP 800-53, FISMA, and FedRAMP compliance.
- Cloud platform experience (AWS).
- Experience with secrets management tools such as HashiCorp Vault.
- Scripting in Python and Bash.
Qualifications / Experience
- Three or more years of hands‑on DevSecOps, platform, or infrastructure engineering.
- Demonstrated experience across the full toolchain: IaC, CI/CD, containers, and security integration, not just one slice.
- Experience working inside an established team’s change‑control and peer‑review process.
- Strong collaboration and communication skills for an agile, cross‑functional team.
What we care about
- You, the person. Bring your whole, authentic self, not a version you think we want to see.
- Your passions, professional and personal, even if they have nothing to do with the job.
- Your honest thoughts on technology, teamwork, and how you approach problems.
Location & On‑site Requirement
- On‑site in Washington, DC. This is not a remote role.
- Applicants must be U.S. citizens, U.S.-based, and able to work on‑site in DC.
- Applicants must live in, or be willing to relocate to, the DC metro area.
Work Authorization
We participate in E‑Verify. Upon hire, we provide the federal government with your Form I‑9 information to confirm you are authorized to work in the U.S. XCell is a federal contractor, and all positions require work to be performed within the United States.
Benefits
- Health Insurance
- Paid Time Off
- Flex Schedule
- Training & Budget Tools
We participate in E-Verify. XCell is a federal contractor; all positions require work to be done within the United States. U.S. Citizenship or Naturalization is required.