Principal DevSecOps Engineer

Agentic Defense Solutions, Inc.

Tysons (VA)

On-site

USD 170,000 - 210,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Agentic Defense Solutions, Inc. is seeking a Principal DevSecOps Engineer to lead the delivery pipeline and cloud infrastructure for large-scale data ingest and analytics platforms in accredited environments.

The role blends hands-on engineering (60%) with leadership (40%), requiring security-first design, automation, and direct engagement with government customers. Strong experience with CI/CD, AWS, and compliance is essential.

Qualifications

  • Active TS/SCI with Full Scope Polygraph required.
  • Must be U.S. citizen and able to maintain clearance.
  • Minimum 12 years of progressive IT/engineering experience.
  • Minimum 6 years in DevOps/DevSecOps or SRE with production pipelines.
  • Minimum 3 years of formal technical leadership (people management).

Responsibilities

  • Own CI/CD pipeline architecture across multiple microservice teams.
  • Manage infrastructure-as-code and reproducible environment builds.
  • Design automated deployments for large-scale data/AI infra with scaling and upgrades.
  • Implement zero-downtime deployments with automated rollbacks.
  • Develop self-healing automation and observability for the platform.
  • Lead security integration across the pipeline (SAST/DAST/SCA, image scanning).
  • Oversee cloud infrastructure (AWS) and cost optimization.
  • Lead recruitment and staffing for a cleared labor market.
  • Coordinate with ISSM/ISSO and government customer on security posture.
  • Contribute to budget planning and proposal efforts as SME.

Skills

DevSecOps leadership
CI/CD automation
Python
Shell scripting
Automation engineering
Cloud architecture
Security tooling integration
Observability

Tools

Jenkins / GitLab CI
Git / GitLab
Nexus / Artifactory
Ansible
Terraform
CloudFormation
InSpec / OpenSCAP

Job description

This position requires an active TS/SCI clearance with a current Full Scope Polygraph at the time of application. Due to the nature of the work and U.S. Government contractual requirements, applicants must be U.S. citizens and must be able to maintain the required clearance for the duration of employment. Candidates without an active in-scope clearance and polygraph cannot be considered, and we are unable to sponsor clearances for this role.

About the Role

Agentic Defense Solutions, Inc. is seeking a Principal DevSecOps Engineer to lead the team that builds, secures, and operates the delivery pipeline and cloud infrastructure behind large-scale data ingest and analytics platforms in accredited environments.

This is a dual-track role. Roughly [60]% of your time is hands‑on engineering: you will design the pipelines, write the automation, and own the architecture. The remaining [40]% is leadership: you will manage a team of engineers, own their growth and performance, plan staffing against contract scope, and serve as a senior technical voice with the government customer.

The distinguishing requirement is that security is your job, not the job of a team you hand off to. We are looking for someone who builds pipelines where hardening, scanning, and control evidence are automated products of the build itself — and who can then sit across from an Authorizing Official and defend how it works.

What You’ll Do
Engineering & Architecture
  • Own the architecture of the CI/CD pipeline supporting multiple microservice development teams — build, artifact management, automated test and security gating, and promotion through environments to production.
  • Own infrastructure-as-code and configuration management; environment builds are reproducible, version-controlled artifacts, never hand‑tuned systems.
  • Design and operate automated deployments of large‑scale distributed data and AI infrastructure including capacity planning, scaling policy, and upgrade strategy.
  • Implement low‑and zero‑downtime deployment strategies with automated rollback driven by health and performance signals.
  • Build self‑healing automation: instrument the platform for known instability patterns and implement corrective actions that fire automatically instead of paging a human.
  • Engineer and tune cloud infrastructure (compute, object storage, load balancing, autoscaling, monitoring, notification) for throughput, resilience, and cost.
  • Build and maintain observability — metrics, logging, distributed tracing, alerting — and drive down mean time to detection and recovery.
Security Engineering
  • Embed security throughout the pipeline: SAST, DAST, software composition analysis, secrets scanning, IaC scanning, and container image scanning, with risk‑based gating and a defensible exception process.
  • Automate system hardening — STIG and benchmark application, drift detection, and remediation as code rather than as a checklist.
  • Own supply‑chain integrity: SBOM generation, dependency provenance, artifact signing, and trusted base image management.
  • Design and operate secrets and key management (vaulting, rotation, brokered credentials); eliminate static credentials from the pipeline.
  • Implement container and orchestration security — image hardening, admission control, network policy, runtime detection.
  • Drive vulnerability management end to end: discovery, triage, patch automation, and closure tracking against POA&M commitments.
  • Implement NIST SP 800‑53 controls as automated, continuously evidenced capabilities; generate accreditation artifacts from pipeline telemetry rather than assembling them by hand.
  • Partner with ISSM/ISSO staff and interface directly with the SCA and Authorizing Official on control implementation, risk positions, and the path toward continuous ATO.
  • Lead threat modeling of the build and deployment pipeline itself, and remediate what it surfaces.
  • Manage a team of [4–8] DevSecOps and platform engineers: set direction, assign work, review output, and hold the technical bar.
  • Own performance management for the team — goal setting, regular feedback, formal reviews, promotion and compensation recommendations, and corrective action when needed.
  • Own career development: identify growth paths, assign stretch work, and manage the team's training and certification plan (including clearance and 8140 currency).
  • Lead technical hiring for the team — define requirements, interview, assess, and close candidates in a very constrained cleared labor market.
  • Plan staffing and labor allocation against contract scope and funding; forecast needs and flag gaps to program management before they become schedule risk.
  • Contribute to budget planning, level‑of‑effort estimation, and basis‑of‑estimate development; manage subcontractor or teammate technical scope where applicable.
  • Serve as a senior technical interface to the government customer on architecture, roadmap, operational status, and security posture.
  • Establish engineering standards, reference patterns, and documentation that outlast any individual on the team.
  • Support capture and proposal efforts as a technical SME, including solution architecture and technical volume input.
Required Qualifications
  • Active TS/SCI with Full Scope Polygraph .
  • 12+ years of progressive IT/engineering experience
  • Minimum 6 years in DevOps, DevSecOps, platform engineering, or SRE, including direct ownership of production CI/CD pipelines.
  • Minimum 3 years of formal or acknowledged technical leadership — managing engineers, leading a team, or serving as the technical authority others elevate to. Direct people‑management experience strongly preferred.
  • Hands‑on depth building and operating CI/CD toolchains — e.g., Jenkins (or GitLab CI/equivalent), Git/GitLab, an artifact repository such as Nexus or Artifactory , and configuration management such as Ansible .
  • Production experience with AWS core services (EC2, S3, ELB/ALB, Auto Scaling, CloudWatch, SNS, IAM) and with automating their provisioning.
  • Demonstrated experience deploying and operating at least one large‑scale distributed data or AI technology in production
  • Demonstrated experience integrating security tooling into a delivery pipeline (SAST/DAST/SCA, image scanning, compliance scanning) with meaningful gating.
  • Strong automation engineering in Python and shell; you write and maintain real tooling, not just glue.
  • Working knowledge of NIST SP 800-53 , the RMF lifecycle, and STIG application in a classified or otherwise regulated environment.
  • Experience deploying and operating microservice architectures , including service discovery, gateway/routing patterns, and inter‑service resilience.
  • Experience taking a system to ATO in a cloud environment , or standing up a continuous ATO (cATO) pipeline.
  • Infrastructure-as-code with Terraform, CloudFormation, or equivalent; compliance-as-code with InSpec, OpenSCAP, or equivalent.
About Agentic Defense Solutions Inc

Agentic Defense Solutions exists to solve the real problem in mission‑critical AI: not better models, but the operational trust layer that makes AI governable, auditable, and safe to deploy in high‑consequence environments.

Our Mission

Most people think the challenge in mission‑critical AI is better models. It isn't. The real problem is there is no control plane for how AI reasons, makes decisions, and executes operations in high‑consequence environments.

Agentic Defense Solutions builds the ARIA product family: the operational trust layer for AI where decisions have real‑world impact. From the ARIA Platform foundation to the ARIA Hermes application, we provide the infrastructure that makes AI governable, auditable, and safe to deploy so that warfighters, analysts, operators, and decision‑makers can leverage AI with confidence.

We believe that AI accountability shouldn't be an afterthought. It should be the foundation. ARIA enforces policy, keeps an immutable audit trail, supports human‑in‑the‑loop, and is built for air‑gapped and classified deployment from day one.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Information Systems Security Engineer
Principal Information Systems Security Engineer

Agentic Defense Solutions, Inc. • Tysons (VA)

On-site
USD 150,000 - 230,000
Chief Technology & Product Officer
Chief Technology & Product Officer

Agentic Defense Solutions, Inc. • Northern (KY)

Hybrid
USD 250,000 - 400,000
Senior Product Engineer
Senior Product Engineer

Agentic Defense Solutions, Inc. • Tysons (VA)

On-site
USD 140,000 - 190,000
DevSecOps Engineer (TypeScript & Agentic AI)
DevSecOps Engineer (TypeScript & Agentic AI)

OpenTalent • United States

On-site
USD 140,000 - 190,000
Senior AI Engineer, Security Infrastructure
Senior AI Engineer, Security Infrastructure

Air • Arlington (VA), Pittsburgh

On-site
USD 170,000 - 250,000
Senior AI Engineer, Security Infrastructure
Senior AI Engineer, Security Infrastructure

artificial intelligence and robotics laboratory (itu air lab) • Arlington (VA)

Hybrid
USD 170,000 - 210,000
Agentic AI Security Engineer
Agentic AI Security Engineer

LTS • United States

Remote
USD 150,000 - 210,000
Comprehensive benefits
Remote work options
Cutting-edge tools
+1
Sales Engineer, Embedded AI
Sales Engineer, Embedded AI

Agile Defense • McLean (VA)

On-site
USD 125,000 - 155,000
Applied AI Lead - Infrastructure & Deployment
Applied AI Lead - Infrastructure & Deployment

Leonardo DRS • Beavercreek (OH)

Hybrid
USD 140,000 - 210,000
Medical, dental, vision coverage
HSA contribution
Telemedicine
+2
INFORMATION TECHNOLOGY
INFORMATION TECHNOLOGY

Solidigm Inc. • Rancho Cordova (CA)

On-site
USD 140,000 - 190,000