DevSecOps Engineer
StratasCorp Technologies
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
Hands-on DevSecOps Engineer responsible for building, automating, and sustaining the delivery infrastructure that enables mission-critical software delivery without compromising compliance. This role focuses on CI/CD automation, secure Kubernetes operations, and continuous security/compliance across Navy/DoD environments. When needed, you also contribute to feature development with a security-first approach.
Primary Responsibilities
- Design, implement, and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment.
- Build and maintain hardened Kubernetes environments aligned to DISA STIG across cloud and restricted/deployment contexts.
- Automate security artifact generation including:
- SBOM production
- CVE scanning
- Continuous compliance validation
- Drive adoption of Infrastructure as Code, GitOps, and controls-as-code.
- Use AI tooling to accelerate:
- pipeline development
- vulnerability triage
- compliance remediation
- operational documentation
- Partner with software engineers, systems engineers, and ISSEs to embed security and compliance requirements early.
- Maintain and evolve deployment infrastructure across multiple secure environments, including air-gapped or intermittently connected contexts.
- Support ATO via automated evidence generation, documentation-as-code, and collaboration with the security team.
- Establish standards for pipeline design, container security, secrets management, and deployment consistency.
- Maintain operational documentation (runbooks, deployment guides, architecture diagrams) as version-controlled artifacts.
Required Skills & Experience
- Active Secret security clearance
- 4+ years professional DevSecOps/DevOps experience
- Hands-on CI/CD pipeline experience using GitLab CI (other pipeline tools a plus)
- Kubernetes administration/hardening in compliance-driven or DoD environments; RKE2 or K3S strongly preferred
- Experience implementing DISA STIG in containerized and Linux environments (e.g., RHEL/Rocky Linux)
- Infrastructure as Code, especially Terraform
- Helm chart authoring and Kubernetes deployment management
- Security automation: scanning, SBOM generation, CVE triage/remediation
- Scripting proficiency in Python or Bash
- Demonstrated use of AI tooling to accelerate engineering workflows
- Ability to operate independently and manage competing priorities in a small team
- Ability to contribute to application feature development alongside infrastructure work
Preferred Qualifications
- Experience with air-gapped/disconnected network environments
- Supporting ATO through automation, documentation, and technical leadership
- Secrets management tooling experience: Vault, Sealed Secrets, SOPS
- Observability/monitoring: Prometheus, Grafana
- CKA (or willingness to obtain)
- Broader “as code” approaches beyond infrastructure (configuration/policy/workflows/documentation)
Education & Certifications
- BS in Computer Science or related field
- Active Security+ (or equivalent)
- IAT Level II certification
About StratasCorp Technologies
StratasCorp Technologies is a technology services provider supporting mission-focused software and delivery infrastructure. The company works in highly regulated environments where security and compliance are essential to deploying software reliably and quickly.
Scraped 7/29/2026