Staff DevSecOps Engineer

Socket.dev

Falls Church (VA)

On-site

USD 120,000 - 180,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flextime Scheduling
Bereavement
Paid Time Off (PTO)
Paid Parental Leave
Medical Insurance
Dental & Vision Insurance
Life Insurance
Long-Term Disability (LTD)
Vision Reimbursement

Job summary

Areté in Falls Church, VA is seeking a DevSecOps Engineer to stabilize and secure GitLab pipelines and CI/CD tooling. You will own the self-hosted GitLab environment, assist developers, and write documentation to prevent future tickets.

The role includes after-hours support and collaboration with Cyber Security and IT teams. You will drive pipeline reliability, implement security scans, manage runners, and build templates for a secure, scalable baseline.

Qualifications

  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or equivalent; or 2 years of relevant work experience in lieu of a degree.
  • Minimum of 3 years of hands-on DevOps/DevSecOps with modern CI/CD pipelines.
  • Experience building, debugging, and optimizing GitLab CI pipelines; strong preference for self-hosted GitLab administration.

Responsibilities

  • Serve as primary point of contact for pipeline failures, GitLab access, runner issues, and environment troubleshooting.
  • Build reusable pipeline templates, CI/CD components, and project scaffolding for secure baselines.
  • Create onboarding guides, runbooks, and training on Git workflow, pipeline authoring, and secure development practices.
  • Advise developers on branching strategy, code review, versioning, and release management.
  • Administer self-hosted GitLab, backups, migrations, and runner fleets; manage artifact repositories and security configurations.

Skills

GitLab CI
Linux admin
Docker
Bash
Python
PowerShell
Security tooling
CI/CD pipelines
Documentation
Runbooks

Education

Bachelor's Degree in CS/IT

Tools

GitLab
JFrog Artifactory
SonarQube
Kubernetes
Terraform
Ansible
Helm
GitOps tooling

Job description

Areté is seeking a DevSecOps Engineer who is here for one purpose: to make our software development teams fast and successful on GitLab and our CI/CD tooling.


You will own the day‑to‑day health of our self‑hosted GitLab environment, build and troubleshoot the pipelines our developers depend on, and integrate security scanning into those pipelines so compliance is something the pipeline handles rather than something developers fight. You are the person a developer goes to when a build, runner, or merge request workflow is broken. This is a hands‑on engineering role with a heavy support and enablement component — a substantial part of the job is unblocking other engineers, writing the documentation that prevents the next ticket, and steadily raising the team's practices.


This position is onsite at our Falls Church, VA facility. The candidate will collaborate with Cyber Security and IT staff members, travel occasionally, and provide some afterhours support. This is an exempt non‑supervisory full‑time position.


Primary Responsibilities

Developer Enablement & Support


  • Serve as the primary point of contact for development teams on pipeline failures, GitLab access and permissions, runner issues, package and container registry usage, merge request workflows, and environment troubleshooting.

  • Build reusable pipeline templates, CI/CD components, and project scaffolding so teams start from a working, secure baseline instead of copying a pipeline from another repo.

  • Create onboarding guides, runbooks, and internal documentation; run training sessions on Git workflow, pipeline authoring, and secure development practices.

  • Advise developers on branching strategy, code review practice, versioning, and release management.


CI/CD Pipeline Engineering


  • Build, maintain, optimize, and troubleshoot CI/CD pipelines in GitLab CI, automating builds, tests, deployments, and security scans.

  • Improve build reliability and speed — caching, artifact management, parallelization, runner sizing and scaling.

  • Manage GitLab Runners across environments, including containerized and self-hosted runner fleets.


Platform & Server Administration


  • Administer self-hosted GitLab: upgrades, migrations, backups and restore testing, runners, integrations, monitoring, permissions, and security configuration.

  • Administer Areté's artifact repository (JFrog Artifactory) — repository structure, retention policy, remote/proxy repositories for external packages, and access control.

  • Administer supporting DevSecOps services such as SonarQube, a secrets manager, and container registries; perform Linux system administration (RHEL, Rocky, or Ubuntu) for the platform, including system services, logging, and SSL/TLS certificate management.


Security Integration


  • Implement and maintain SAST, DAST, software composition analysis, container image scanning, secret scanning, and SBOM generation within pipelines.

  • Configure quality and security gates, and work with development teams to triage and resolve findings rather than simply reporting them.

  • Manage build‑time secrets, signing, and artifact provenance in line with Areté's security requirements.


Automation, Process & Documentation


  • Automate platform, build, and remediation tasks using Bash, Python, or PowerShell; manage infrastructure and configuration with IaC and deployment tooling.

  • Maintain DevSecOps procedures, system documentation, and standard operating procedures; support change management, audit readiness, and compliance‑aligned workflows.

  • Track and report metrics on build times, pipeline reliability, and security posture, and drive measurable improvement.

  • Other duties, as assigned.


Experiences and Background We Look For


  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an additional 2 years of relevant work experience in lieu of a degree.

  • Minimum of 3 years of hands‑on DevOps or DevSecOps experience with modern CI/CD pipelines

  • Demonstrated ability to build, debug, and optimize GitLab CI pipelines — .gitlab-ci.yml authoring, CI/CD components and templates, and diagnosing failures across build, test, packaging, and deployment stages. Experience with self‑hosted GitLab, as an administrator or advanced user, is strongly preferred.

  • Proficiency in Linux system administration (RHEL, Rocky, or Ubuntu), including networking fundamentals, system services, logging, and certificate management.

  • Hands‑on experience with Docker and container lifecycle management — image creation, registries, and image tagging/promotion.

  • Experience automating tasks with Bash, Python, or PowerShell.

  • Experience integrating at least one class of security tooling into pipelines — SAST, DAST, software composition analysis, secret scanning, or container image scanning.

  • Demonstrated ability to support developers directly — resolving CI/CD and Git workflow issues, teaching Git fundamentals (branching, rebasing, merge conflict resolution, repository hygiene), writing clear documentation and runbooks, and explaining technical issues to engineers and non‑technical stakeholders alike.

  • Must hold an active Top Secret security clearance, or be eligible to obtain and maintain one.

  • Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS 252.239-7001.


Nice to Have


  • Active Top Secret security clearance; TS/SCI with polygraph is a plus.

  • Experience administering self‑hosted GitLab — Runner configuration and scaling, project and group permissions, integrations, and registries.

  • Experience with an enterprise artifact repository — JFrog Artifactory preferred; Sonatype Nexus or the GitLab Package/Container Registry comparable; administration experience a plus.

  • Working experience with Infrastructure‑as‑Code (Terraform or Azure Bicep) and configuration management or deployment packaging tools such as Ansible or Helm.

  • Experience with Kubernetes or OpenShift.

  • Experience with container security practices — image signing, SBOM generation, and policy enforcement.

  • Familiarity with secure SDLC practices, OWASP Top 10, and compliance frameworks such as NIST 800‑53, NIST 800‑171, FedRAMP, JSIG, or ITAR.

  • Experience supporting development in classified, airgapped, or otherwise disconnected environments, including offline dependency and artifact management.

  • Experience with GitOps deployment patterns, Azure DevOps, or cloud‑native CI/CD services.

  • Certifications such as GitLab Certified CI/CD Associate or Specialist, Docker or Kubernetes certifications (CKA/CKAD), or cloud associate certifications.


Benefits We Offer

Generous PTO and Leave Times


  • Flextime Scheduling

  • Bereavement

  • Paid Time Off (PTO)

  • Paid Parental Leave


Financial Benefits


  • Company-funded 5% contribution to your 401(k) retirement plan

  • Company-funded 5% contribution to your Employee Stock Ownership Plan

  • Continuing Education Assistance


Health, Medical, and Wellness Benefits


  • Medical Insurance

  • Dental & Vision Insurance

  • Life Insurance and Long-Term Disability (LTD)

  • Vision Reimbursement

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff DevSecOps Engineer
Staff DevSecOps Engineer

Areté • Falls Church (VA), Northern (KY)

On-site
USD 120,000 - 150,000
401(k) plan
Employee Stock Ownership Plan
Medical Insurance
+2
Staff DevSecOps Engineer
Staff DevSecOps Engineer

Arete Associates • Falls Church (VA)

On-site
USD 140,000 - 180,000
Generous PTO
401(k) matching
Continuing Education Assistance
+2
Staff Business Apps Developer
Staff Business Apps Developer

Socket.dev • Arizona

Hybrid
USD 100,000 - 160,000
Flextime Scheduling
Bereavement
Paid Time Off (PTO)
+2
Staff Business Apps Developer
Staff Business Apps Developer

Areté • Falls Church (VA)

Hybrid
USD 90,000 - 125,000
Generous PTO
401(k) plan
Employee Stock Ownership Plan
+3
Staff Business Apps Developer
Staff Business Apps Developer

Areté • Tucson (AZ), Northern (KY)

Hybrid
USD 90,000 - 125,000
401(k) retirement plan
Employee Stock Ownership Plan
Medical insurance
+2
VULNERABILITY MGMT ANALYST
VULNERABILITY MGMT ANALYST

Areté • Falls Church (VA)

On-site
USD 110,000 - 145,000
Flextime
Paid Time Off
Parental Leave
+3
Software Engineer/Developer - Contingent
Software Engineer/Developer - Contingent

Aretum • McLean (VA)

On-site
USD 115,000 - 136,000
Health plan
401k
Life insurance
+4
Lead Software Engineer/Developer - Contingent
Lead Software Engineer/Developer - Contingent

Worky • McLean (VA)

Remote
USD 120,000 - 160,000
Health Insurance
401k Match
Life Insurance
+4
Software Engineer/Developer - Contingent
Software Engineer/Developer - Contingent

Aretum, Llc • McLean (VA), Northern (KY)

Hybrid
USD 115,000 - 136,000
Health Care Plan (Medical, Dental &amp
401k Retirement Plan
Paid Time Off
+3
Software Engineer/Developer - Contingent
Software Engineer/Developer - Contingent

Worky • McLean (VA)

On-site
USD 110,000 - 140,000