Staff DevSecOps Engineer

Areté

Falls Church, Northern (VA, KY)

On-site

USD 120,000 - 150,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) plan
Employee Stock Ownership Plan
Medical Insurance
Dental & Vision Insurance
Life Insurance & LTD

Job summary

Areté in Falls Church, VA seeks a DevSecOps Engineer to own day-to-day health of our self-hosted GitLab and CI/CD pipelines, integrating security scanning and accelerat ing developer workflows.

You will build pipelines, write onboarding guides, and help teams with branching, code review, and release management while providing afterhours support and occasional travel.

Qualifications

  • Bachelor's degree in CS/IT/cybersecurity or 2 years of related work experience.
  • Minimum of 3 years hands-on DevOps/DevSecOps experience with modern CI/CD pipelines.
  • Proficiency in building and debugging GitLab CI pipelines and self-hosted GitLab administration.
  • Proficiency in Linux system administration (RHEL, Rocky, or Ubuntu) including networking basics.
  • Hands-on experience with Docker and container lifecycle management.
  • Experience automating tasks with Bash, Python, or PowerShell.
  • Experience integrating security tooling into pipelines—SAST, DAST, software composition analysis, secret scanning, or container image scanning.
  • Ability to support developers, write clear documentation and runbooks, and explain technical issues to engineers and non-technical stakeholders.

Responsibilities

  • Serve as the primary contact for pipeline failures, GitLab access, runner issues, and environment troubleshooting.
  • Build reusable pipeline templates, CI/CD components, and project scaffolding for a secure baseline.
  • Create onboarding guides, runbooks, and internal docs; run training on Git workflow, pipeline authoring, and secure development practices.
  • Advise developers on branching strategy, code review, versioning, and release management.
  • Build, maintain, optimize, and troubleshoot CI/CD pipelines in GitLab CI, automating builds, tests, deployments, and security scans.
  • Improve build reliability and speed through caching, artifact management, parallelization, and runner sizing/scaling.
  • Manage GitLab Runners across environments, including containerized and self-hosted fleets.
  • Administer self-hosted GitLab: upgrades, migrations, backups, runners, integrations, monitoring, and security configuration.
  • Administer Artifactory; manage repository structure, retention, proxies, and access control.
  • Administer security tools (SonarQube, secrets manager, registries) and Linux services; manage SSL/TLS certificates.

Skills

GitLab CI pipelines
GitLab administration
Linux administration
Docker
Bash scripting
Python scripting
PowerShell scripting
Security tooling in pipelines
Scripting collaboration and docs
CI/CD optimization

Education

Bachelor's Degree in Computer Science / IT / Cybersecurity or related discipline
CompTIA Security+ CE certification

Tools

GitLab
JFrog Artifactory
SonarQube

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Full Time Falls Church, VA, US

Salary Range: $120,000.00 To $150,000.00 Annually

Areté is seeking a DevSecOps Engineer who is here for one purpose: to make our software development teams fast and successful on GitLab and our CI/CD tooling.

You will own the day-to-day health of our self-hosted GitLab environment, build and troubleshoot the pipelines our developers depend on, and integrate security scanning into those pipelines so compliance is something the pipeline handles rather than something developers fight. You are the person a developer goes to when a build, runner, or merge request workflow is broken. This is a hands-on engineering role with a heavy support and enablement component - a substantial part of the job is unblocking other engineers, writing the documentation that prevents the next ticket, and steadily raising the team's practices.

This position is onsite at our Falls Church, VA facility. The candidate will collaborate with Cyber Security and IT staff members, travel occasionally, and provide some afterhours support. This is an exempt non-supervisory full-time position.

Primary Responsibilities
  • Serve as the primary point of contact for development teams on pipeline failures, GitLab access and permissions, runner issues, package and container registry usage, merge request workflows, and environment troubleshooting.
  • Build reusable pipeline templates, CI/CD components, and project scaffolding so teams start from a working, secure baseline instead of copying a pipeline from another repo.
  • Create onboarding guides, runbooks, and internal documentation; run training sessions on Git workflow, pipeline authoring, and secure development practices.
  • Advise developers on branching strategy, code review practice, versioning, and release management.
  • Build, maintain, optimize, and troubleshoot CI/CD pipelines in GitLab CI, automating builds, tests, deployments, and security scans.
  • Improve build reliability and speed - caching, artifact management, parallelization, runner sizing and scaling.
  • Manage GitLab Runners across environments, including containerized and self-hosted runner fleets.
Platform & Server Administration
  • Administer self-hosted GitLab: upgrades, migrations, backups and restore testing, runners, integrations, monitoring, permissions, and security configuration.
  • Administer Areté's artifact repository (JFrog Artifactory) — repository structure, retention policy, remote/proxy repositories for external packages, and access control.
  • Administer supporting DevSecOps services such as SonarQube, a secrets manager, and container registries; perform Linux system administration (RHEL, Rocky, or Ubuntu) for the platform, including system services, logging, and SSL/TLS certificate management.
Security Integration
  • Implement and maintain SAST, DAST, software composition analysis, container image scanning, secret scanning, and SBOM generation within pipelines.
  • Configure quality and security gates, and work with development teams to triage and resolve findings rather than simply reporting them.
  • Manage build-time secrets, signing, and artifact provenance in line with Areté's security requirements.
Automation, Process & Documentation
  • Automate platform, build, and remediation tasks using Bash, Python, or PowerShell; manage infrastructure and configuration with IaC and deployment tooling.
  • Maintain DevSecOps procedures, system documentation, and standard operating procedures; support change management, audit readiness, and compliance-aligned workflows.
  • Track and report metrics on build times, pipeline reliability, and security posture, and drive measurable improvement.
  • Other duties, as assigned.
Experiences and Background We Look For:
  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an additional 2 years of relevant work experience in lieu of a degree.
  • Minimum of 3 years of hands-on DevOps or DevSecOps experience with modern CI/CD pipelines
  • Demonstrated ability to build, debug, and optimize GitLab CI pipelines — .gitlab-ci.yml authoring, CI/CD components and templates, and diagnosing failures across build, test, packaging, and deployment stages. Experience with self-hosted GitLab, as an administrator or advanced user, is strongly preferred.
  • Proficiency in Linux system administration (RHEL, Rocky, or Ubuntu), including networking fundamentals, system services, logging, and certificate management.
  • Hands-on experience with Docker and container lifecycle management — image creation, registries, and image tagging/promotion.
  • Experience automating tasks with Bash, Python, or PowerShell.
  • Experience integrating at least one class of security tooling into pipelines — SAST, DAST, software composition analysis, secret scanning, or container image scanning.
  • Demonstrated ability to support developers directly — resolving CI/CD and Git workflow issues, teaching Git fundamentals (branching, rebasing, merge conflict resolution, repository hygiene), writing clear documentation and runbooks, and explaining technical issues to engineers and non-technical stakeholders alike.
  • Must hold an active Top Secret security clearance, or be eligible to obtain and maintain one.
  • Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS 252.239-7001.
Nice to Have:
  • Active Top Secret security clearance; TS/SCI with polygraph is a plus.
  • Experience administering self-hosted GitLab — Runner configuration and scaling, project and group permissions, integrations, and registries.
  • Experience with an enterprise artifact repository — JFrog Artifactory preferred; Sonatype Nexus or the GitLab Package/Container Registry comparable; administration experience a plus.
  • Working experience with Infrastructure-as-Code (Terraform or Azure Bicep) and configuration management or deployment packaging tools such as Ansible or Helm.
  • Experience with Kubernetes or OpenShift.
  • Experience with container security practices — image signing, SBOM generation, and policy enforcement.
  • Familiarity with secure SDLC practices, OWASP Top 10, and compliance frameworks such as NIST 800-53, NIST 800-171, FedRAMP, JSIG, or ITAR.
  • Experience supporting development in classified, airgapped, or otherwise disconnected environments, including offline dependency and artifact management.
  • Experience with GitOps deployment patterns, Azure DevOps, or cloud-native CI/CD services.
  • Certifications such as GitLab Certified CI/CD Associate or Specialist, Docker or Kubernetes certifications (CKA/CKAD), or cloud associate certifications.
Benefits We Offer:

Generous PTO and Leave Times

  • Company-funded 5% contribution to your 401(k) retirement plan
  • Company-funded 5% contribution to your Employee Stock Ownership Plan
Health, Medical, and Wellness Benefits
  • Medical Insurance
  • Dental & Vision Insurance
  • Life Insurance and Long-Term Disability (LTD)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff DevSecOps Engineer
Staff DevSecOps Engineer

Socket.dev • Falls Church (VA)

On-site
USD 120,000 - 180,000
Flextime Scheduling
Bereavement
Paid Time Off (PTO)
+6
Staff DevSecOps Engineer
Staff DevSecOps Engineer

Arete Associates • Falls Church (VA)

On-site
USD 140,000 - 180,000
Generous PTO
401(k) matching
Continuing Education Assistance
+2
Staff Business Apps Developer
Staff Business Apps Developer

Areté • Tucson (AZ), Northern (KY)

Hybrid
USD 90,000 - 125,000
401(k) retirement plan
Employee Stock Ownership Plan
Medical insurance
+2
Staff Business Apps Developer
Staff Business Apps Developer

Areté • Falls Church (VA)

Hybrid
USD 90,000 - 125,000
Generous PTO
401(k) plan
Employee Stock Ownership Plan
+3
Staff Business Apps Developer
Staff Business Apps Developer

Socket.dev • Arizona

Hybrid
USD 100,000 - 160,000
Flextime Scheduling
Bereavement
Paid Time Off (PTO)
+2
Software Engineer/Developer - Contingent
Software Engineer/Developer - Contingent

Aretum, Llc • McLean (VA), Northern (KY)

Hybrid
USD 115,000 - 136,000
Health Care Plan (Medical, Dental &amp
401k Retirement Plan
Paid Time Off
+3
Software Engineer/Developer - Contingent
Software Engineer/Developer - Contingent

Worky • McLean (VA)

On-site
USD 110,000 - 140,000
Lead Software Engineer/Developer - Contingent
Lead Software Engineer/Developer - Contingent

Worky • McLean (VA)

Remote
USD 120,000 - 160,000
Health Insurance
401k Match
Life Insurance
+4
Staff DevSecOps Engineer: CI/CD & Security Pipelines
Staff DevSecOps Engineer: CI/CD & Security Pipelines

Arete Associates • Falls Church (VA)

On-site
USD 140,000 - 180,000
Generous PTO
401(k) matching
Continuing Education Assistance
+2
Software Engineer/Developer - Contingent
Software Engineer/Developer - Contingent

Aretum • McLean (VA)

On-site
USD 115,000 - 136,000
Health plan
401k
Life insurance
+4