Staff DevSecOps Engineer

Arete Associates

Falls Church (VA)

On-site

USD 140,000 - 180,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Generous PTO
401(k) matching
Continuing Education Assistance
Medical Insurance
Life Insurance and LTD

Job summary

Arete Associates seeks a DevSecOps Engineer to keep our GitLab environment healthy, fast, and secure. You will own pipelines, implement security scans, and unblock developers while documenting best practices. This onsite role in Falls Church collaborates with Cyber Security and IT, with occasional travel and after-hours support.

You’ll automate, optimize, and scale CI/CD, manage runners and registries, and administer Linux systems in a security‑minded DevSecOps team.

Qualifications

  • Hands-on DevSecOps experience with modern CI/CD pipelines.
  • Experience building, debugging, and optimizing GitLab CI pipelines.
  • Proficiency in Linux system administration and container lifecycles.
  • Ability to integrate security tooling into pipelines and write documentation.

Responsibilities

  • Own day-to-day health of self-hosted GitLab and CI/CD pipelines.
  • Build reusable pipeline templates and project scaffolding.
  • Integrate SAST/DAST and SBOM scanning into pipelines.
  • Provide developer enablement, documentation, and runbooks.

Skills

DevSecOps
GitLab CI/CD
Linux administration
Bash/Python/PowerShell
CI/CD pipelines
Security tooling integration
Documentation writing
Communication

Education

Bachelor's Degree in CS or related

Tools

GitLab
Docker
Artifactory
Terraform

Job description

Arete is seeking a DevSecOps Engineer who is here for one purpose: to make our software development teams fast and successful on GitLab and our CI/CD tooling.

You will own the day-to-day health of our self-hosted GitLab environment, build and troubleshoot the pipelines our developers depend on, and integrate security scanning into those pipelines so compliance is something the pipeline handles rather than something developers fight. You are the person a developer goes to when a build, runner, or merge request workflow is broken. This is a hands‑on engineering role with a heavy support and enablement component - a substantial part of the job is unblocking other engineers, writing the documentation that prevents the next ticket, and steadily raising the team's practices.

This position is onsite at our Falls Church, VA facility. The candidate will collaborate with Cyber Security and IT staff members, travel occasionally, and provide some afterhours support. This is an exempt non-supervisory full-time position.

Primary Responsibilities
Developer Enablement & Support
  • Serve as the primary point of contact for development teams on pipeline failures, GitLab access and permissions, runner issues, package and container registry usage, merge request workflows, and environment troubleshooting.
  • Build reusable pipeline templates, CI/CD components, and project scaffolding so teams start from a working, secure baseline instead of copying a pipeline from another repo.
  • Create onboarding guides, runbooks, and internal documentation; run training sessions on Git workflow, pipeline authoring, and secure development practices.
  • Advise developers on branching strategy, code review practice, versioning, and release management.
CI/CD Pipeline Engineering
  • Build, maintain, optimize, and troubleshoot CI/CD pipelines in GitLab CI, automating builds, tests, deployments, and security scans.
  • Improve build reliability and speed - caching, artifact management, parallelization, runner sizing and scaling.
  • Manage GitLab Runners across environments, including containerized and self-hosted runner fleets.
Platform & Server Administration
  • Administer self-hosted GitLab: upgrades, migrations, backups and restore testing, runners, integrations, monitoring, permissions, and security configuration.
  • Administer Arete's artifact repository (JFrog Artifactory) - repository structure, retention policy, remote/proxy repositories for external packages, and access control.
  • Administer supporting DevSecOps services such as SonarQube, a secrets manager, and container registries; perform Linux system administration (RHEL, Rocky, or Ubuntu) for the platform, including system services, logging, and SSL/TLS certificate management.
Security Integration
  • Implement and maintain SAST, DAST, software composition analysis, container image scanning, secret scanning, and SBOM generation within pipelines.
  • Configure quality and security gates, and work with development teams to triage and resolve findings rather than simply reporting them.
  • Manage build-time secrets, signing, and artifact provenance in line with Arete's security requirements.
Automation, Process & Documentation
  • Automate platform, build, and remediation tasks using Bash, Python, or PowerShell; manage infrastructure and configuration with IaC and deployment tooling.
  • Maintain DevSecOps procedures, system documentation, and standard operating procedures; support change management, audit readiness, and compliance-aligned workflows.
  • Track and report metrics on build times, pipeline reliability, and security posture, and drive measurable improvement.
  • Other duties, as assigned.
Experiences and Background We Look For
  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an additional 2 years of relevant work experience in lieu of a degree.
  • Minimum of 3 years of hands‑on DevOps or DevSecOps experience with modern CI/CD pipelines
  • Demonstrated ability to build, debug, and optimize GitLab CI pipelines - .gitlab-ci.yml authoring, CI/CD components and templates, and diagnosing failures across build, test, packaging, and deployment stages. Experience with self-hosted GitLab, as an administrator or advanced user, is strongly preferred.
  • Proficiency in Linux system administration (RHEL, Rocky, or Ubuntu), including networking fundamentals, system services, logging, and certificate management.
  • Hands‑on experience with Docker and container lifecycle management - image creation, registries, and image tagging/promotion.
  • Experience automating tasks with Bash, Python, or PowerShell.
  • Experience integrating at least one class of security tooling into pipelines - SAST, DAST, software composition analysis, secret scanning, or container image scanning.
  • Demonstrated ability to support developers directly - resolving CI/CD and Git workflow issues, teaching Git fundamentals (branching, rebasing, merge conflict resolution, repository hygiene), writing clear documentation and runbooks, and explaining technical issues to engineers and non-technical stakeholders alike.
  • Must hold an active Top Secret security clearance, or be eligible to obtain and maintain one.
  • Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS 252.239-7001.
Nice to Have
  • Active Top Secret security clearance; TS/SCI with polygraph is a plus.
  • Experience administering self-hosted GitLab - Runner configuration and scaling, project and group permissions, integrations, and registries.
  • Experience with an enterprise artifact repository - JFrog Artifactory preferred; Sonatype Nexus or the GitLab Package/Container Registry comparable; administration experience a plus.
  • Working experience with Infrastructure-as-Code (Terraform or Azure Bicep) and configuration management or deployment packaging tools such as Ansible or Helm.
  • Experience with Kubernetes or OpenShift.
  • Experience with container security practices - image signing, SBOM generation, and policy enforcement.
  • Familiarity with secure SDLC practices, OWASP Top 10, and compliance frameworks such as NIST 800-53, NIST 800-171, FedRAMP, JSIG, or ITAR.
  • Experience supporting development in classified, airgapped, or otherwise disconnected environments, including offline dependency and artifact management.
  • Experience with GitOps deployment patterns, Azure DevOps, or cloud-native CI/CD services.
  • Certifications such as GitLab Certified CI/CD Associate or Specialist, Docker or Kubernetes certifications (CKA/CKAD), or cloud associate certifications.
Benefits We Offer
  • Generous PTO and Leave Times
  • Flextime Scheduling
  • Bereavement
  • Paid Time Off (PTO)
  • Paid Parental Leave
  • Company-funded 5% contribution to your 401(k) retirement plan
  • Company-funded 5% contribution to your Employee Stock Ownership Plan
  • Continuing Education Assistance
  • Medical Insurance
  • Dental & Vision Insurance
  • Life Insurance and Long-Term Disability (LTD)
  • Vision Reimbursement
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff DevSecOps Engineer
Staff DevSecOps Engineer

Areté • Falls Church (VA), Northern (KY)

On-site
USD 120,000 - 150,000
401(k) plan
Employee Stock Ownership Plan
Medical Insurance
+2
Staff DevSecOps Engineer
Staff DevSecOps Engineer

Socket.dev • Falls Church (VA)

On-site
USD 120,000 - 180,000
Flextime Scheduling
Bereavement
Paid Time Off (PTO)
+6
Staff DevSecOps Engineer: CI/CD & Security Pipelines
Staff DevSecOps Engineer: CI/CD & Security Pipelines

Arete Associates • Falls Church (VA)

On-site
USD 140,000 - 180,000
Generous PTO
401(k) matching
Continuing Education Assistance
+2
Staff Business Apps Developer
Staff Business Apps Developer

Arete Associates • Falls Church (VA)

Hybrid
USD 120,000 - 150,000
Flextime Scheduling
Bereavement
Paid Time Off (PTO)
+5
Staff Business Apps Developer
Staff Business Apps Developer

Arete Associates • Niwot (CO)

Hybrid
USD 110,000 - 150,000
Flextime Scheduling
Bereavement
PTO
+9
Staff Business Apps Developer
Staff Business Apps Developer

Arete Associates • Los Angeles (CA)

Hybrid
USD 120,000 - 160,000
Flextime scheduling
Bereavement
PTO
+2
VULNERABILITY MGMT ANALYST
VULNERABILITY MGMT ANALYST

Arete Associates • Falls Church (VA)

On-site
USD 110,000 - 150,000
Flextime Scheduling
Bereavement
PTO
+8
Devops Engineer
Devops Engineer

Arete Technologies, Inc. • Dallas (TX)

On-site
USD 100,000 - 130,000
Dynamic work culture
Opportunities for career growth
Sr. DevSecOps Engineer 5
Sr. DevSecOps Engineer 5

Base-2 Solutions • Reston (VA)

On-site
USD 140,000 - 175,000
100% medical premiums for employees &
PPO/HMO options
401(k) with company match
+2
SeniorDevSecOpsEngineer
SeniorDevSecOpsEngineer

Pantheon-Data • Reston (VA)

Hybrid
USD 140,000 - 200,000
SmartBenefits via SmarTrip
Tuition assistance
Pre-tax SmarTrip payments