- Build and operate CI/CD pipelines producing versioned, signed release packages with SBOM manifests, hardened container images, deployment runbooks, and validation procedures
- Execute recurring low-to-high promotion through Government-approved transfer mechanisms, including cross-domain solution submission packages
- Verify environment parity after each promotion
- Integrate vulnerability management, image signing, dependency scanning, and continuous monitoring into the pipeline
- Generate and reuse accreditation evidence across promotions
- Align pipeline outputs with the RMF body of evidence in collaboration with security engineers
- Define and track service level objectives
- Build monitoring, logging, and alerting using tools such as Prometheus, Grafana, and OpenTelemetry
- Lead incident response and run postmortems to closure
- Operate sanitized defect and telemetry feedback paths
- Enforce platform dependency constraints for target environments
- Maintain deployment runbooks, validation procedures, and operational documentation suitable for Government review and cleared personnel
Requirements
- - U.S. citizenship and eligibility to obtain and maintain a U.S. security clearance
- - 6+ years of experience in DevSecOps, site reliability engineering, platform engineering, or production operations
- - 3+ years of experience supporting Department of Defense, Intelligence Community, or similarly regulated programs
- - Hands-on experience packaging or promoting software into classified, air-gapped, or limited-connectivity environments
- - Strong Kubernetes and cloud operations experience, including operating containerized production workloads in AWS
- - Working knowledge of DevSecOps practices for regulated environments, including hardened containers, image signing, software bill of materials generation, vulnerability management, and continuous monitoring
- - Experience working within the Risk Management Framework or a comparable security and compliance framework
- - Proficiency in scripting and automation using Python, Bash, Go, or a comparable language
- - Experience with infrastructure-as-code and deployment tools such as Terraform, Helm, or equivalent technologies
- - Experience implementing or operating production observability stacks and participating in incident response
- - Current DoD 8140/8570 qualifying certification, such as CISSP or CASP+, or ability to obtain an appropriate certification within 90 days of hire
- - Bachelor's degree in computer science, engineering, or a related field, or equivalent practical experience
Core Competencies
Demonstrates expertise in building and operating CI/CD pipelines, integrating security practices, and managing deployment in regulated environments. Proficient in incident response, observability, and maintaining compliance with security frameworks.
Highest-signal resume keywords
- DevSecOps Experience
- Kubernetes Operations
- AWS Cloud Operations
- Infrastructure-as-Code
- DoD 8140/8570 Certification
Hard Skills
- CI/CD Pipeline Development
- Vulnerability Management
- Scripting with Python
- Containerization
- Image Signing
- Dependency Scanning
- Risk Management Framework
- Observability Stack Implementation
- Automation with Bash
- Software Bill of Materials Generation
Soft Skills
- Incident Response Leadership
- Collaboration with Security Engineers
Certifications & Qualifications
Industry Keywords
- Department of Defense
- Intelligence Community
- Regulated Programs
- Classified Environments
- Security Clearance
Tools & Technologies
- Prometheus
- Grafana
- OpenTelemetry
- Terraform
- Helm