DevSecOps Engineer
DMI
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
DMI is seeking a mid-level DevSecOps Engineer to augment an existing engineering team supporting a federal agency client with a hybrid cloud infrastructure. The role focuses on extending mature infrastructure automation and security-hardened CI/CD practices in an active production environment.
Responsibilities
- Terraform/OpenTofu: Maintain, extend, and improve Terraform and OpenTofu codebases for hybrid cloud provisioning; manage state and remote backends under approved change control.
- Ansible Automation: Develop and maintain Ansible playbooks/roles for configuration automation, compliance enforcement, patch management, and application deployment.
- CI/CD Security: Build and improve GitHub Actions workflows with security gates, including SAST, dependency scanning, secrets detection, and policy-as-code validation.
- Container Delivery & Orchestration: Use Docker and Kubernetes for containerized delivery; manage Dockerfiles, Kubernetes manifests, Helm charts, and RBAC.
- Security & Compliance: Integrate security through the SDLC, enforcing CIS benchmarks and supporting NIST SP 800-53 and FISMA compliance.
- Team Collaboration: Participate in stand-ups, sprint planning, peer code reviews, and maintain change records for shared codebases and pipelines.
Requirements
- Mid-level hands-on experience with Terraform and/or OpenTofu (modules, remote state management, workspaces).
- Proficiency with Ansible (playbooks/roles, dynamic inventories, Ansible Vault).
- Experience designing and maintaining GitHub Actions workflows (reusable workflows and security gate integration).
- Working knowledge of Docker hardening/image authoring and Kubernetes/Helm (manifests, charts), plus container security scanning.
- Familiarity with:
- SAST tools: Semgrep, Checkov, tfsec
- Secrets scanning: Gitleaks, Detect-Secrets
- Policy-as-code: OPA/Rego
- Strong Git-based workflows (branching strategies, PR reviews, protected branches).
Background / Eligibility
- Federal or highly regulated environment experience.
- Familiarity with NIST SP 800-53, FISMA, and FedRAMP.
- AWS cloud experience.
- Experience with HashiCorp Vault (secrets management).
- Scripting proficiency in Python and Bash.
- Must be a U.S. citizen and must possess or be eligible to obtain and complete a Public Trust background investigation.
- Public Trust Tier 2 clearance required.
Nice-to-Haves
- Bachelor’s degree in IT or related field (may be waived with 4+ years relevant professional experience).
About DMI
DMI is a provider of digital services and technology solutions, offering end-to-end managed IT services such as managed mobility, cloud, cybersecurity, network operations, and application development. The company supports public sector agencies and commercial enterprises, delivering secure, efficient, and cost-effective outcomes. DMI is headquartered in Tysons Corner, Virginia.
Scraped 6/12/2026