Senior DevSecOps Engineer

HyerTek

Brookeville (MD)

On-site

USD 145,000 - 187,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical insurance
401(k) with employer contribution
PTO and holidays
Professional development

Job summary

HyerTek is a federal technology consulting firm crafting secure enterprise applications, data analytics, cloud infrastructure, and modernization solutions for federal agencies. We seek a Senior DevSecOps Engineer to own the software supply chain and delivery pipeline behind our federal solutions, spanning from commit to controlled releases in Azure Government and accredited environments.

You will integrate AI coding agents to accelerate development and automation, embedding security into the

Qualifications

  • 5+ years in DevOps/DevSecOps in security-sensitive environments.
  • Proficient with GitHub Enterprise, Actions, and self-hosted runners.
  • Experience with Azure DevOps and multi-repo pipelines.
  • Ability to build secure container images and CI/CD workflows.
  • Kubernetes experience in AKS/OpenShift with security controls.
  • Knowledge of SBOMs, artifact signing, and provenance.
  • Scripting in Python/PowerShell/Node.js/.NET.
  • Strong Linux fundamentals and secret management.

Responsibilities

  • Design, maintain secure CI/CD pipelines across repos and environments.
  • Build secure containerized apps for Kubernetes platforms.
  • Incorporate automated security checks in pipelines and fix findings.
  • Manage SBOMs, artifact signing, provenance, and controlled promotion.
  • Handle secrets and config management with approved vaults.
  • Automate RMF/ATO evidence, logging, and reporting.

Skills

DevSecOps
GitHub Actions
Azure DevOps
Kubernetes
SBOM
Terraform
Python
Linux

Tools

GitHub Enterprise
AKS/OpenShift
Terraform/Bicep
Azure Key Vault

Job description

Description

HyerTek is a federal technology consulting firm delivering secure enterprise applications, data analytics, cloud infrastructure, and modernization solutions to federal government agencies.

HyerTek is a federal technology consulting firm delivering secure enterprise applications, data analytics, cloud infrastructure, and modernization solutions to federal government agencies.

HyerTek is hiring a Senior DevSecOps Engineer to own the software supply chain and delivery pipeline behind our federal solutions. The role spans the full delivery cycle from developer commit through hardened container builds, automated security and compliance gates, artifact signing, and controlled releases into Azure Government environments supporting DoW Impact Levels 5, 6, and 7, equivalent classification levels, and other accredited environments as required by the customer.

A successful candidate will incorporate approved AI coding agents into the engineering workflow to accelerate development and automation. These tools will be used to author pipeline and policy-as-code, triage findings, and generate technical documentation and control evidence. The DevSecOps Engineer will make security a built-in property of the pipeline rather than a review at the end of the process, while automating the collection of technical evidence needed to support and maintain an Authority to Operate (ATO).

Candidates must possess a Top Secret security clearance and reside in the Washington, DC, metropolitan area. Some work will be performed at customer facilities, including accredited Secure Areas and SCIFs at Ft. Meade.

Responsibilities
  • Design, maintain, and improve secure CI/CD pipelines using GitHub Actions and Azure DevOps across multiple repositories and environments, including disconnected or air-gapped deployments.
  • Build and maintain secure containerized applications for Kubernetes platforms such as AKS and OpenShift.
  • Integrate automated security and compliance checks into development pipelines, ensuring critical findings are identified, evaluated, and remediated or resolved before release.
  • Implement secure artifact management practices, including software bills of materials (SBOMs), artifact signing, provenance attestation, and controlled promotion between environments.
  • Manage secrets and environment-specific configuration using approved vault and configuration-management solutions.
  • Automate compliance evidence, configuration monitoring, audit logging, and security reporting in support of RMF and ATO requirements.
  • Improve application and pipeline observability, reliability, and operational readiness through logging, monitoring, testing, alerting, and incident-response practices.
  • Develop and validate backup, recovery, and disaster-recovery procedures with documented recovery objectives.
  • Partner with developers, cybersecurity engineers, and operations teams to resolve vulnerabilities, improve delivery processes and support production deployments.
  • Create clear technical documentation, operational runbooks, and customer-handoff materials.
  • Monitor and troubleshoot CI/CD pipelines, build infrastructure, container registries, deployment processes, and related development-platform services to maintain reliable delivery.
  • Establish reusable pipeline patterns, templates, and automation that promote consistent security and deployment practices across projects and environments.
Required Qualifications
  • 5+ years of hands-on DevOps or DevSecOps engineering experience, including responsibility for production CI/CD pipelines in a regulated or security-sensitive environment.
  • Strong working knowledge of GitHub Enterprise, including GitHub Actions, repository and organization configuration, access controls, branch protection or rulesets, reusable workflows, and self-hosted runners.
  • Experience designing and maintaining CI/CD pipelines in GitHub Enterprise and Azure DevOps across multiple repositories and environments.
  • Experience building secure container images using hardened base images, multi-stage builds, vulnerability scanning, minimal dependencies, and non-root runtimes.
  • Production experience with Kubernetes platforms such as AKS or OpenShift, including deployment configuration, health probes, secrets integration, and admission-policy requirements.
  • Experience integrating automated security controls into CI/CD pipelines, including source-code, dependency, secret, container, and infrastructure-as-code scanning.
  • Working knowledge of secure software supply-chain practices, including SBOM generation, artifact signing, provenance attestation, and controlled artifact promotion.
  • Proficiency with Infrastructure as Code using Terraform, Bicep/ARM, or a comparable technology.
  • Experience with Azure services such as Key Vault, managed identities, Azure Policy, Azure Monitor, Log Analytics, or Microsoft Sentinel.
  • Strong scripting and automation skills using Python, PowerShell, JavaScript/Node.js, C#/.NET, or a comparable language.
  • Strong Linux fundamentals and command-line troubleshooting skills.
  • Familiarity with secrets management, centralized logging, monitoring, backup, recovery, and disaster-recovery practices.
  • Strong proficiency in AI platforms including Open AI, Claude, Gemini, and Microsoft CoPilot.
  • Excellent troubleshooting, documentation, and stakeholder communication skills.
  • Ability to work independently and collaboratively across multiple concurrent engagements and manage priorities.
  • DoW 8140 aligned IAT Level II certification, with Security+ CE or an approved equivalent.
  • Active Top Secret security clearance required. Candidates must be eligible to obtain and maintain any additional customer-specific access requirements associated with their assigned work.
Preferred Qualifications
  • Active TS/SCI security clearance.
  • Experience with GitHub Enterprise Server in disconnected or air-gapped environments.
  • Experience delivering solutions in Azure Government or DoD Impact Level 5 or higher environments.
  • Familiarity with RMF, NIST SP 800-53, DISA STIGs, and the DoD Cloud Computing SRG.
  • Experience with DoD Iron Bank, Platform One, or comparable hardened-container programs.
  • Experience supporting an RMF authorization, continuous ATO initiative, or automated compliance-evidence pipeline.
  • Experience transferring software artifacts into air-gapped or cross-domain environments.
  • Experience with Kubernetes policy tools such as OPA/Gatekeeper or Kyverno.
  • Experience implementing artifact attestation, signing, provenance, or software supply-chain policy enforcement.
  • Experience with production secrets rotation, SIEM integration, audit-log retention, and tested disaster-recovery procedures.
  • CISSP, CASP+, or another advanced security certification.
HyerTek Offers a Comprehensive Benefits Package, Including
  • Medical, dental, and vision insurance
  • 401(k) with employer contribution
  • Paid time off (PTO) and company holidays
  • Professional development and certification support
  • Employee assistance program (EAP)
  • Life and disability insurance
Clearance & Work Authorization

This position requires U.S. citizenship and an active TS security clearance with the Department of War. The candidate must be able to obtain and maintain SCI eligibility; an active TS/SCI clearance is strongly preferred. Candidates must be authorized to work in the United States without the need for employment-based visa sponsorship now or in the future. HyerTek will not sponsor applicants for a U.S. work visa status for this opportunity.

Salary Range

The anticipated salary range for this position is $145,000 - $186,500 annually. Final compensation will be based on relevant experience, technical qualifications, certifications, clearance status, and contract requirements.

Equal Employment Opportunity (EEO)

HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other status protected by applicable federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer
Senior Software Engineer

HyerTek, Inc. • Washington, Northern (KY)

Hybrid
USD 145,000 - 213,000
Medical insurance
Dental insurance
Vision insurance
+3
Microsoft Azure Senior Cloud Architect
Microsoft Azure Senior Cloud Architect

HyerTek, Inc. • Washington, Northern (KY)

Hybrid
USD 145,000 - 187,000
Medical insurance
Dental insurance
Vision insurance
+4
Full Stack Developer (TS Cleared Only)
Full Stack Developer (TS Cleared Only)

Worky • Fort Meade (MD)

On-site
USD 140,000 - 180,000
Medical, dental, and vision insurance
401(k) with employer contribution
Paid time off and company holidays
+1
DevOps Engineer (Senior) w/Secret Clearance
DevOps Engineer (Senior) w/Secret Clearance

TekSynap • United States

On-site
USD 100,000 - 140,000
Health insurance
Dental insurance
Vision insurance
+6
Senior DevOps Engineer - 27620
Senior DevOps Engineer - 27620

Wyetech • Hanover (MD)

Hybrid
20% company contribution to SEP IRA
Generous PTO plan
Medical plan options
+5
DevOps Engineer 4
DevOps Engineer 4

Wyetech • Maryland

On-site
20% SEP IRA contribution
$5k bonus eligibility
Generous PTO plan up to 200 hours annually
+1
Cloud DevSecOps Engineer - Hybrid - Active or Interim Top Secret Required - Bonus Eligible
Cloud DevSecOps Engineer - Hybrid - Active or Interim Top Secret Required - Bonus Eligible

Worky • Maryland

Hybrid
USD 140,000 - 190,000
Generous PTO/Leave Package
11 Paid Federal Holidays
Medical, Dental, & Vision Plan
+7
Senior DevSecOps Engineer - Secure CI/CD for DoD Gov
Senior DevSecOps Engineer - Secure CI/CD for DoD Gov

HyerTek • Brookeville (MD)

On-site
USD 145,000 - 187,000
Medical insurance
401(k) with employer contribution
PTO and holidays
+1
Senior DevOps Engineer
Senior DevOps Engineer

FTI Defense - Frontier Technology Inc. • Dayton (OH)

Hybrid
USD 140,000 - 190,000
DevOps Engineer 4
DevOps Engineer 4

Wyetechllc • Maryland

On-site
USD 120,000 - 150,000
20% SEP IRA contribution
Generous PTO plan
Variety of voluntary benefit plans
+3