Contract Performance Period: March 30, 2026 - December 31, 2026
Job Location: Washington, DC – Washington, DC Office (Metro Access). On‑Site presence daily (5 days per week), unless otherwise specified.
Direct Hire: Term: through 31/12/2026, with the possibility of extension.
Pay Range: Depending on Experience
Travel Requirements / Working Remotely: Washington, DC Office (Metro Access). On‑Site presence daily (5 days per week), unless otherwise specified.
Project Description
Seeking Sr. IT DevSecOps Engineer to build GitLab‑based DevSecOps automated pipelines into AWS GovCloud; support and enable application delivery times on CI/CD platform; manage and operate GitLab CI/CD. Period of Performance: 03/30/2026 to December 31, 2026, with possibility for extension. Place of Performance: Washington, DC Office (Metro Access). On‑Site presence daily (5 days per week), unless otherwise specified.
Qualification Requirements
- Certification(s): GitLab certification desired but not required. AWS certification desired but not required.
- Version Control Systems: Proficiency with Git; advanced knowledge of GitLab, including CI/CD pipelines, merge requests, and issue tracking.
- Cloud Platforms
- Containerization
- Security Testing
- Infrastructure as Code (IaC)
- Scripting and Programming
- Automation
- U.S. citizenship is a requirement for this position.
Skills Requirements
- Version Control Systems: Proficiency with Git; advanced knowledge of GitLab, including CI/CD pipelines, merge requests, and issue tracking; familiarity with branching, promotion, and release strategies (such as SemRel); familiarity using internal registries and repositories (Nexus dependency management, internal container registries, etc.).
- CI/CD: GitLab CI/CD; GitLab runners (configuration and management); GitLab components (or generally developing and utilizing templates for CI/CD jobs in any platform, such as GitHub Actions).
- Cloud Platforms: Demonstrated proficiency with AWS (Lambda, EC2, S3, EBS/EFS, ECS, EKS, SNS, CloudWatch).
- Containerization: Docker (building, deploying, and managing containers); Kubernetes (orchestration, deployment strategies, security, troubleshooting); container security best practices; container hardening strategies, maintaining a secure “golden” image; deploying and managing container‑based runners hosted on EKS; GitOps tools and deployment principles (such as ArgoCD/Flux).
- Security Testing: Static Application Security Testing (SAST); Dynamic Application Security Testing (DAST); Interactive Application Security Testing (IAST); Software Composition Analysis (SCA); container scanning tooling (Trivy, Prisma/Twistlock, Neuvector, etc.).
- Infrastructure as Code (IaC): Terraform (writing, managing, and optimizing Terraform configurations); other IaC tools (e.g., CloudFormation, Ansible).
- Scripting and Programming: Proficiency in scripting languages (e.g., Python, Bash); basic to intermediate programming skills; experience working with a Linux‑based shell, navigating a Linux‑based system; ability to work well in a paired programming environment at times.
Responsibilities
- Build GitLab‑based DevSecOps automated pipelines into AWS GovCloud; support and enable application delivery times on CI/CD platform; manage and operate GitLab CI/CD.
- Automation: create and maintain automated security checks and remediations; integrate security into automated deployment processes; incorporate linting tooling into development processes; incorporate unit & performance testing into deployment processes.