xelys jobs xelys jobs

DevSecOps Engineer

StratasCorp Technologies

full-remotemidpermanentdevopssecurity Virginia, United States Yesterday via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsCI/CDGitLab CIKubernetesDISA STIGInfrastructure as CodeTerraformGitOpsSBOMCVE Scanning

About the role

Role Overview

Hands-on DevSecOps Engineer responsible for building, automating, and sustaining the delivery infrastructure that enables mission-critical software delivery without compromising compliance. This role focuses on CI/CD automation, secure Kubernetes operations, and continuous security/compliance across Navy/DoD environments. When needed, you also contribute to feature development with a security-first approach.

Primary Responsibilities

  • Design, implement, and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment.
  • Build and maintain hardened Kubernetes environments aligned to DISA STIG across cloud and restricted/deployment contexts.
  • Automate security artifact generation including:
    • SBOM production
    • CVE scanning
    • Continuous compliance validation
  • Drive adoption of Infrastructure as Code, GitOps, and controls-as-code.
  • Use AI tooling to accelerate:
    • pipeline development
    • vulnerability triage
    • compliance remediation
    • operational documentation
  • Partner with software engineers, systems engineers, and ISSEs to embed security and compliance requirements early.
  • Maintain and evolve deployment infrastructure across multiple secure environments, including air-gapped or intermittently connected contexts.
  • Support ATO via automated evidence generation, documentation-as-code, and collaboration with the security team.
  • Establish standards for pipeline design, container security, secrets management, and deployment consistency.
  • Maintain operational documentation (runbooks, deployment guides, architecture diagrams) as version-controlled artifacts.

Required Skills & Experience

  • Active Secret security clearance
  • 4+ years professional DevSecOps/DevOps experience
  • Hands-on CI/CD pipeline experience using GitLab CI (other pipeline tools a plus)
  • Kubernetes administration/hardening in compliance-driven or DoD environments; RKE2 or K3S strongly preferred
  • Experience implementing DISA STIG in containerized and Linux environments (e.g., RHEL/Rocky Linux)
  • Infrastructure as Code, especially Terraform
  • Helm chart authoring and Kubernetes deployment management
  • Security automation: scanning, SBOM generation, CVE triage/remediation
  • Scripting proficiency in Python or Bash
  • Demonstrated use of AI tooling to accelerate engineering workflows
  • Ability to operate independently and manage competing priorities in a small team
  • Ability to contribute to application feature development alongside infrastructure work

Preferred Qualifications

  • Experience with air-gapped/disconnected network environments
  • Supporting ATO through automation, documentation, and technical leadership
  • Secrets management tooling experience: Vault, Sealed Secrets, SOPS
  • Observability/monitoring: Prometheus, Grafana
  • CKA (or willingness to obtain)
  • Broader “as code” approaches beyond infrastructure (configuration/policy/workflows/documentation)

Education & Certifications

  • BS in Computer Science or related field
  • Active Security+ (or equivalent)
  • IAT Level II certification

About StratasCorp Technologies

StratasCorp Technologies is a technology services provider supporting mission-focused software and delivery infrastructure. The company works in highly regulated environments where security and compliance are essential to deploying software reliably and quickly.

Scraped 7/29/2026