DevSecOps Engineer

Posted yesterday

nakupuna companiesArlington (TX)

SENIORITY

Lead

SALARY

$160,000 per year

Apply

About the role

Overview: Na Ali‘i is seeking a DevSecOps Engineer to support the secure delivery and operation of a software solution for a Department of the Navy organization and serve as a team member of Nakupuna Labs, the in-house innovation team. The ideal candidate has advanced experience in designing, implementing, administering, and continuously improving CI/CD pipelines, deployment environments, and integrated security controls.
Responsibilities: The following reflects management's definition of essential functions for this job but does not restrict the tasks that may be assigned. Designing, implementing, and administering CI/CD pipelines that automate build, test, security scanning, approval, release, rollback, and deployment activities across development, test, and production environments. Integrating and maintaining automated security controls, including static and dynamic application security testing, software composition analysis, secrets scanning, container and infrastructure-as-code scanning, and policy-based quality gates. Administering source code and artifact repositories, pipeline runners or agents, deployment credentials, certificates, secrets, and role-based access in accordance with least-privilege principles. Automating infrastructure provisioning and configuration to create repeatable, hardened, and Security Technical Implementation Guide (STIG)-aligned environments and configuration baselines. Managing containerized application build and deployment processes and, where applicable, orchestration platforms, registries, software bills of materials, and signed artifacts. Monitoring pipeline and platform availability, performance, and security events; troubleshooting build and deployment failures; and coordinating patching, incident response, and vulnerability remediation. Maintaining release records, system diagrams, operating procedures, security evidence, and Risk Management Framework (RMF) authorization artifacts; supporting control assessments, remediation activities, and continuous monitoring. Collaborating with developers, testers, cybersecurity personnel, infrastructure teams, and customer stakeholders to translate delivery and security requirements into automated controls and improve reliability, delivery speed, and auditability.
Qualifications: The ideal candidate has experience with the following technical knowledge, skills, and abilities: Hands-on experience designing and administering production CI/CD pipelines using tools such as GitLab CI/CD, GitHub Actions, Azure DevOps, or Jenkins, including Git workflows, release management, and artifact repositories. Experience with containers and orchestration technologies, such as Docker and Kubernetes, and with infrastructure-as-code or configuration-management tools, such as Terraform, Bicep, Cloud Formation, or Ansible. Experience administering Azure, AWS, or on-premises environments, including Linux or Windows systems, networking, identity and access management, certificates, and secrets. Ability to automate operational tasks using PowerShell, Bash, Python, or a comparable scripting language. Working knowledge of secure software delivery practices, vulnerability management, STIGs, DoD RMF, NIST SP 800-53 controls, security evidence collection, and authorization support. Strong troubleshooting, documentation, communication, and collaboration skills, including the ability to work effectively with technical teams and customer stakeholders.
Desired Certifications: One or more relevant certifications, such as Security+ CE, CySA+, CISSP, CSSLP, GSEC, or a cloud, DevOps, or Kubernetes security credential.
Education and Experience: This position requires a Bachelor's degree in computer science, information technology, cybersecurity, engineering, or a related field and at least 5 years of relevant professional experience.
Clearance: This position requires an active Secret security clearance. Must be a U.S. citizen.
Physical Requirements: The ideal candidate must at a minimum be able to meet the following physical requirements of the job with or without a reasonable accommodation: Ability to perform repetitive motions with the hands, wrists, and fingers. Ability to engage in and follow audible communications in emergency situations. Ability to sit for prolonged periods at a desk and working on a computer. The Nakupuna Companies use a market-based compensation strategy to ensure that our employees are compensated within applicable market ranges commensurate with multiple factors, including but not limited to the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, organizational requirements, and position location. The projected compensation range for this position is $130,00 to $160,000 (annualized USD). The salary range displayed represents the typical salary range for this position and is just one component of Nakupuna Companies' total compensation package for employees.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this