xelys jobs xelys jobs

DevSecOps Engineer

StratasCorp Technologies

full-remoteseniorpermanentdevopssecurity Virginia, United States Yesterday via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsCI/CDGitLab CIKubernetesDISA STIGTerraformInfrastructure as CodeGitOpsSBOMVulnerability Management

About the role

Role Overview

Hands-on DevSecOps Engineer responsible for building, automating, and sustaining delivery infrastructure that accelerates development without compromising compliance. The position is remote and includes CI/CD, Kubernetes hardening, security compliance automation, and occasional feature development with a security-first approach.

Primary Responsibilities

  • Design, implement, and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment into Navy and DoD environments.
  • Build and maintain hardened Kubernetes environments aligned to DISA STIG requirements across cloud and restricted deployment contexts.
  • Automate security compliance and artifacts, including:
    • SBOM production
    • CVE scanning
    • Continuous compliance validation
  • Drive adoption of Infrastructure as Code (IaC), GitOps, and controls-as-code.
  • Use AI tooling to accelerate:
    • pipeline development
    • vulnerability triage and remediation
    • operational documentation
  • Partner with software engineers, systems engineers, and ISSEs to embed security and compliance requirements early in development.
  • Maintain and evolve deployment infrastructure across secure environments, including air-gapped or intermittently connected contexts.
  • Support ATO processes via automated evidence generation, documentation-as-code, and collaboration with the security team.
  • Establish standards for:
    • pipeline design
    • container security
    • secrets management
    • deployment consistency
  • Maintain operational documentation as version-controlled artifacts (runbooks, deployment guides, architecture diagrams).

Required Skills & Experience

  • Active Secret security clearance.
  • 4+ years professional DevSecOps/DevOps experience.
  • Hands-on CI/CD pipeline design/maintenance using GitLab CI (additional pipeline tooling a plus).
  • Kubernetes administration and hardening in DoD/compliance-driven environments; RKE2 or K3S strongly preferred.
  • Implementing DISA STIG compliance for containerized and Linux environments (RHEL/Rocky Linux).
  • Infrastructure as Code, specifically Terraform.
  • Helm chart authoring and Kubernetes deployment management.
  • Automated security scanning including SBOM generation and CVE triage/remediation.
  • Scripting proficiency in Python or Bash.
  • Demonstrated ability using AI tooling to accelerate engineering workflows.
  • Ability to contribute to application feature development alongside infrastructure work.
  • Ability to operate independently and manage competing priorities in a small, fast-moving team.

Preferred Qualifications

  • Experience operating in air-gapped/disconnected network environments.
  • Supporting ATO through automation, documentation, and technical leadership.
  • Secrets management tooling: Vault, Sealed Secrets, SOPS.
  • Observability tools: Prometheus, Grafana.
  • CKA (Certified Kubernetes Administrator) or willingness to obtain.
  • Applying broader “as code” approaches (configuration-as-code, policy-as-code, workflows-as-code, documentation-as-code).

Education & Certifications

  • BS in Computer Science (or related field).
  • Active Security+ (or equivalent).
  • IAT Level II certification.

About StratasCorp Technologies

StratasCorp Technologies is a technology services company providing engineering and security-focused support for mission-critical environments. The role described centers on building compliant delivery infrastructure for defense-oriented (Navy/DoD) software systems using DevSecOps practices.

Scraped 7/30/2026