Senior DevSecOps Engineer

CACI

United States

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CACI is seeking a Senior DevSecOps Engineer to join a DoD/AF customer team focused on cloud-native platforms. You will drive Kubernetes platform engineering, IaC with Terraform, and GitOps-based deployment across mission-critical environments.

Responsibilities include building secure CI/CD pipelines, enforcing DISA STIGs/NIST RMF, and maintaining secure configurations while producing comprehensive security and operation documentation.

Qualifications

  • U.S. Citizen with eligibility for Secret Clearance.
  • 7+ years of relevant professional experience with a related degree.
  • Experience developing Terraform modules and reusable IaC patterns for cloud, network, and Kubernetes resources.
  • Experience implementing GitOps workflows with tools such as Argo CD, Flux, GitLab, GitHub, or similar platforms.
  • 3-5 years experience designing and deploying Kubernetes-based solutions; Big Bang is a plus.
  • Experience with CI/CD pipelines, containerization, and secure DevSecOps practices.
  • Strong familiarity with DISA STIGs, RMF, NIST SP 800-53, ATO processes, POA&M management, continuous monitoring, and security compliance evidence generation.

Responsibilities

  • Deploy, configure, and sustain Kubernetes-based platforms and mission applications using Big Bang, Helm, and GitOps deployment practices.
  • Develop and maintain Terraform-based Infrastructure as Code (IaC) for cloud infrastructure, Kubernetes resources, networking, IAM, and platform services.
  • Build, secure, and optimize CI/CD pipelines for application and infrastructure delivery, including reusable pipeline templates, automated testing, and controlled release promotion.
  • Triage, prioritize, remediate, and validate infrastructure, container, and application security findings in accordance with established vulnerability-management SLAs.
  • Implement and maintain hardened Kubernetes and cloud configuration baselines aligned with DISA STIGs, NIST RMF, and organizational security requirements.
  • Manage Kubernetes security controls, including RBAC, network policies, pod security standards, admission controls, secrets management, and secure ingress/egress configurations.
  • Maintain GitOps workflows using Git as the authoritative source for infrastructure and platform configuration; ensure deployed environments remain aligned with approved code.
  • Monitor CI/CD platforms, runners, deployments, and Kubernetes workloads; troubleshoot build, deployment, performance, and availability issues.
  • Develop automated patching, configuration management, and compliance-validation processes to reduce manual effort and configuration drift.
  • Produce security and operational documentation, including architecture diagrams, implementation procedures, scan evidence, remediation plans, and POA&M updates.
  • Support RMF and ATO lifecycle activities by collecting control evidence, addressing assessment findings, and maintaining continuous-monitoring artifacts.

Skills

DevSecOps
Terraform
GitOps
Kubernetes
CI/CD pipelines
Security compliance

Education

Related degree

Tools

Argo CD
Flux
GitLab
GitHub
AWS (EKS)
Terraform

Job description

Job Title: Senior DevSecOps Engineer

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: Secret

Employee Type: Regular

Percentage of Travel Required: Up to 10%

Type of Travel: Local

The Opportunity

Join a high-performing DevSecOps team supporting our DoD/AF customer in delivering, securing, and operating cloud-native enterprise platforms. This role centers on Kubernetes platform engineering, Big Bang deployment and sustainment, Terraform-based Infrastructure as Code, GitOps, and secure CI/CD automation across mission-critical environments.

Responsibilities
  • Deploy, configure, and sustain Kubernetes-based platforms and mission applications using Big Bang, Helm, and GitOps deployment practices.
  • Develop and maintain Terraform-based Infrastructure as Code (IaC) for cloud infrastructure, Kubernetes resources, networking, IAM, and platform services.
  • Build, secure, and optimize CI/CD pipelines for application and infrastructure delivery, including reusable pipeline templates, automated testing, and controlled release promotion.
  • Triage, prioritize, remediate, and validate infrastructure, container, and application security findings in accordance with established vulnerability-management SLAs.
  • Implement and maintain hardened Kubernetes and cloud configuration baselines aligned with DISA STIGs, NIST 800-53, RMF, and organizational security requirements.
  • Manage Kubernetes security controls, including RBAC, network policies, pod security standards, admission controls, secrets management, and secure ingress/egress configurations.
  • Maintain GitOps workflows using Git as the authoritative source for infrastructure and platform configuration; ensure deployed environments remain aligned with approved code.
  • Monitor CI/CD platforms, runners, deployments, and Kubernetes workloads; troubleshoot build, deployment, performance, and availability issues.
  • Develop automated patching, configuration management, and compliance-validation processes to reduce manual effort and configuration drift.
  • Produce security and operational documentation, including architecture diagrams, implementation procedures, scan evidence, remediation plans, and POA&M updates.
  • Support RMF and ATO lifecycle activities by collecting control evidence, addressing assessment findings, and maintaining continuous-monitoring artifacts.
Qualifications
Required
  • U.S Citizen with eligibility for Secret Clearance
  • At least 7 years of relevant professional experience with a related degree
  • Strong experience developing and maintaining Terraform modules and reusable Infrastructure as Code patterns for cloud, network, and Kubernetes resources.
  • Experience implementing GitOps workflows with tools such as Argo CD, Flux, GitLab, GitHub, or similar platforms.
  • 3-5 years experience designing and deploying Kubernetes-based solutions; Big Bang is a plus.
  • Experience with CI/CD pipelines, containerization, and secure DevSecOps practices.
  • Strong familiarity with DISA STIGs, RMF, NIST SP 800-53, ATO processes, POA&M management, continuous monitoring, and security compliance evidence generation.
Desired
  • 5-10 years of experience in DevSecOps, platform engineering, cloud engineering, SRE, or software delivery roles.
  • Experience with CAC authentication, PIV tokens, and client-side PKI certificate handling.
  • Experience with AWS cloud services, including EKS, IAM, VPC, EC2, S3, Route 53, CloudWatch, load balancers, and security services.
  • Proficiency in Python, Bash, PowerShell, Go, or similar languages for automation, tooling, and operational support.
  • Relevant certifications such as CKA, CKAD, CKS, HashiCorp Terraform Associate, AWS certifications, Security+, CISSP, or CCSP.
  • Experience with ATO/accreditation processes.
  • Experience with scanning and compliance tools like RMF, ACAS, Twistlock, Prisma Cloud.
  • Proven ability to work across multi-tenant identity services, supporting thousands of users and integrating with microservices.
What You Can Expect

A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.

An environment of trust. CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth. Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.

Pay Range

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

CACI International • United States

Remote
USD 99,000 - 207,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

CACI International Inc. • United States

Remote
USD 99,000 - 207,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

CACI International Inc • Chantilly (VA)

On-site
USD 113,000 - 238,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

CACI International • King of Prussia (PA)

On-site
USD 82,000 - 172,000
DevSecOps Engineer
DevSecOps Engineer

CACI International Inc • King of Prussia (PA)

On-site
USD 69,000 - 142,000
Systems Engineer - DevOps Kubernetes Support
Systems Engineer - DevOps Kubernetes Support

CACI International Inc • Hanover (MD)

On-site
USD 94,000 - 198,000
Software Engineer
Software Engineer

CACI International • King of Prussia (PA)

On-site
USD 110,000 - 170,000
DevSecOps Lead Engineer
DevSecOps Lead Engineer

CACI International • United States

Remote
USD 82,000 - 172,000
DevSecOps Engineer
DevSecOps Engineer

CACI International Inc. • Denver (CO)

On-site
USD 82,000 - 172,000
DevSecOps Engineer
DevSecOps Engineer

CACI International • Chantilly (VA)

On-site
USD 69,000 - 142,000