xelys jobs xelys jobs

DevSecOps Engineer

StratasCorp Technologies

full-remotemidpermanentdevopssecurity Virginia, United States 62 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsCI/CDGitLab CIKubernetesDISA STIGTerraformGitOpsSBOMCVE ScanningInfrastructure as Code

About the role

Role Overview

DevSecOps Engineer (remote) Hands-on role building, automating, and sustaining secure delivery infrastructure so mission-critical software can move fast without compromising compliance. You will own CI/CD pipelines, harden and manage Kubernetes environments, automate security compliance (including evidence for ATO), and use AI tooling to accelerate delivery lifecycle tasks. When needed, you’ll also contribute to feature development with a security-first mindset.

Primary Responsibilities

  • Design and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment into Navy and DoD environments.
  • Build and harden Kubernetes environments aligned to DISA STIG requirements across cloud and restricted network contexts.
  • Automate security artifacts and compliance:
    • SBOM generation
    • CVE scanning and vulnerability triage/remediation
    • Continuous compliance validation
  • Drive adoption of Infrastructure as Code, GitOps, and controls-as-code across the team.
  • Use AI tooling for pipeline development, vulnerability triage, compliance remediation, and operational documentation.
  • Partner with software and systems engineers and ISSEs to embed security/compliance requirements early.
  • Maintain deployment infrastructure across multiple secure environments, including air-gapped or intermittently connected contexts.
  • Support ATO processes via automated evidence generation, documentation-as-code, and collaboration with the security team.
  • Establish standards for pipeline design, container security, secrets management, and deployment consistency.
  • Contribute to feature development when capacity demands it, applying security-first practices to application code.
  • Maintain operational documentation (runbooks, deployment guides, architecture diagrams) as version-controlled artifacts.

Required Skills & Experience

  • Active Secret security clearance
  • 4+ years of DevSecOps/DevOps engineering experience
  • Hands-on CI/CD pipeline design and maintenance using GitLab CI (additional pipeline tooling is a plus)
  • Kubernetes administration and hardening in DoD/compliance environments (RKE2 or K3S strongly preferred)
  • Experience implementing DISA STIG compliance in containerized and Linux environments (RHEL/Rocky Linux)
  • Infrastructure as Code, especially Terraform
  • Helm chart authoring and Kubernetes deployment management
  • Automated security scanning, SBOM generation, and CVE triage/remediation
  • Scripting proficiency in Python or Bash for automation
  • Demonstrated use of AI tooling to accelerate workflows
  • Experience contributing to application feature development alongside infrastructure work
  • Ability to operate independently and manage competing priorities in a small team

Preferred Qualifications

  • Experience with air-gapped/disconnected network environments
  • Supporting ATO through automation, documentation, and technical leadership
  • Secrets management tooling: Vault, Sealed Secrets, SOPS
  • Observability/monitoring: Prometheus, Grafana
  • CKA certification (or willingness to obtain on onboarding)
  • “As code” approaches beyond infrastructure (configuration/policy/workflows/documentation)

Education & Certifications

  • BS in Computer Science or related field
  • Active Security+ (or equivalent)
  • IAT Level II certification

About StratasCorp Technologies

StratasCorp Technologies provides technology and engineering services for mission-critical software and secure delivery environments. The company focuses on enabling organizations to move quickly while maintaining compliance, particularly in defense-oriented contexts involving Navy and DoD systems.

Scraped 7/23/2026