xelys jobs xelys jobs

DevSecOps Engineer

Spry Methods, Inc.

midpermanentdevopssecurity Washington, DC 47 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsTerraformOpenTofuAnsibleGitHub ActionsDockerKubernetesHelmCI/CDSAST

About the role

Role Overview

DevSecOps Engineer supporting infrastructure automation, configuration management, CI/CD pipelines, containerized delivery, and secure software delivery practices in a hybrid cloud environment. The role focuses on extending and maturing existing engineering capabilities.

Responsibilities

  • Maintain, extend, and improve infrastructure-as-code repositories using Terraform and OpenTofu
  • Develop and maintain configuration-as-code assets using Ansible
  • Build, maintain, and improve GitHub Actions workflows for:
    • build and test automation
    • scanning
    • deployment automation
  • Support containerized delivery using Docker and Kubernetes, including:
    • manifests and Helm charts
    • RBAC
    • image hardening and scanning
  • Integrate security into delivery pipelines, including:
    • SAST
    • secrets scanning
    • policy-as-code
    • compliance hardening
  • Participate in Agile ceremonies and contribute to documentation and peer reviews

Requirements

  • 5+ years of experience in DevSecOps, infrastructure automation, or CI/CD pipeline engineering
  • Hands-on with Terraform and OpenTofu (modules, remote state, workspace management)
  • Proficiency with Ansible (playbooks, roles, inventories, secrets handling)
  • Demonstrated experience designing and maintaining GitHub Actions workflows
  • Working knowledge of Docker, Kubernetes, Helm, and container security scanning tools
  • Familiarity with SAST, secrets scanning, policy-as-code frameworks, and Git-based workflows
  • Active Top Secret clearance

Preferred Qualifications

  • Experience in regulated/federal environments
  • Knowledge of NIST SP 800-53, FISMA, and FedRAMP compliance
  • AWS experience
  • Secrets management tools such as HashiCorp Vault
  • Python and Bash scripting experience

Scraped 6/18/2026