xelys jobs xelys jobs

DevSecOps Engineer

DMI

full-remotemidpermanentdevops United States 49 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsTerraformOpenTofuAnsibleGitHub ActionsKubernetesDockerOPA/RegoNIST SP 800-53AWS

About the role

Role Overview

DMI is seeking a mid-level DevSecOps Engineer to augment an existing engineering team supporting a federal agency client with a hybrid cloud infrastructure. The role focuses on extending mature infrastructure automation and security-hardened CI/CD practices in an active production environment.

Responsibilities

  • Terraform/OpenTofu: Maintain, extend, and improve Terraform and OpenTofu codebases for hybrid cloud provisioning; manage state and remote backends under approved change control.
  • Ansible Automation: Develop and maintain Ansible playbooks/roles for configuration automation, compliance enforcement, patch management, and application deployment.
  • CI/CD Security: Build and improve GitHub Actions workflows with security gates, including SAST, dependency scanning, secrets detection, and policy-as-code validation.
  • Container Delivery & Orchestration: Use Docker and Kubernetes for containerized delivery; manage Dockerfiles, Kubernetes manifests, Helm charts, and RBAC.
  • Security & Compliance: Integrate security through the SDLC, enforcing CIS benchmarks and supporting NIST SP 800-53 and FISMA compliance.
  • Team Collaboration: Participate in stand-ups, sprint planning, peer code reviews, and maintain change records for shared codebases and pipelines.

Requirements

  • Mid-level hands-on experience with Terraform and/or OpenTofu (modules, remote state management, workspaces).
  • Proficiency with Ansible (playbooks/roles, dynamic inventories, Ansible Vault).
  • Experience designing and maintaining GitHub Actions workflows (reusable workflows and security gate integration).
  • Working knowledge of Docker hardening/image authoring and Kubernetes/Helm (manifests, charts), plus container security scanning.
  • Familiarity with:
    • SAST tools: Semgrep, Checkov, tfsec
    • Secrets scanning: Gitleaks, Detect-Secrets
    • Policy-as-code: OPA/Rego
  • Strong Git-based workflows (branching strategies, PR reviews, protected branches).

Background / Eligibility

  • Federal or highly regulated environment experience.
  • Familiarity with NIST SP 800-53, FISMA, and FedRAMP.
  • AWS cloud experience.
  • Experience with HashiCorp Vault (secrets management).
  • Scripting proficiency in Python and Bash.
  • Must be a U.S. citizen and must possess or be eligible to obtain and complete a Public Trust background investigation.
  • Public Trust Tier 2 clearance required.

Nice-to-Haves

  • Bachelor’s degree in IT or related field (may be waived with 4+ years relevant professional experience).

About DMI

DMI is a provider of digital services and technology solutions, offering end-to-end managed IT services such as managed mobility, cloud, cybersecurity, network operations, and application development. The company supports public sector agencies and commercial enterprises, delivering secure, efficient, and cost-effective outcomes. DMI is headquartered in Tysons Corner, Virginia.

Scraped 6/12/2026