DevSecOps Engineer
StratasCorp Technologies
full-remoteseniorpermanentdevopssecurity Virginia, United States Today via LinkedIn
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
DevSecOpsCI/CDGitLab CIKubernetesDISA STIGInfrastructure as CodeTerraformGitOpsSBOMCVE Scanning
About the role
Role Overview
DevSecOps Engineer responsible for building, automating, and sustaining delivery infrastructure that enables fast movement without compromising compliance. You will lead CI/CD and security automation, harden Kubernetes environments for restricted DoD contexts, and support ATO through automated evidence generation.
Responsibilities
- Design, implement, and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment into Navy/DoD environments
- Build and maintain hardened Kubernetes environments aligned to DISA STIG requirements across cloud and restricted network contexts
- Automate security artifacts and compliance validation, including SBOM production, CVE scanning, and continuous compliance evidence
- Drive adoption of Infrastructure as Code, GitOps, and controls-as-code
- Use AI tooling to accelerate pipeline development, vulnerability triage, compliance remediation, and operational documentation
- Partner with software engineers, systems engineers, and ISSEs to embed security and compliance requirements early
- Maintain deployment infrastructure across multiple secure environments, including air-gapped / intermittently connected contexts
- Support ATO processes via automated evidence generation and documentation as code
- Establish standards for pipeline design, container security, secrets management, and deployment consistency
- Contribute to feature development when needed, applying security-first practices to application code
- Maintain operational documentation (runbooks, deployment guides, architecture diagrams) as version-controlled artifacts
Required Skills & Experience
- Active Secret security clearance
- 4+ years of professional DevSecOps/DevOps experience
- Hands-on CI/CD pipeline experience with GitLab CI (additional pipeline tools a plus)
- Kubernetes administration and hardening in DoD/compliance-driven environments (RKE2 or K3S strongly preferred)
- Implementation of DISA STIG compliance for containerized and Linux environments (RHEL/Rocky Linux)
- Terraform (Infrastructure as Code)
- Helm chart authoring and Kubernetes deployment management
- Automated security scanning, SBOM generation, and CVE triage/remediation
- Scripting proficiency in Python or Bash
- Demonstrated use of AI tools to accelerate engineering workflows
- Ability to contribute to application feature development alongside infrastructure work
- Ability to operate independently and manage competing priorities in a small, fast-moving team
Preferred Qualifications
- Experience in air-gapped/disconnected networks
- Experience supporting ATO through automation, documentation, and technical leadership
- Secrets management tooling experience: Vault, Sealed Secrets, or SOPS
- Observability/monitoring experience: Prometheus or Grafana
- CKA or willingness to obtain upon onboarding
- Experience applying “as code” beyond infrastructure (configuration/policy/workflows/documentation)
Education & Certifications
- BS in Computer Science or related field
- Active Security+ (or equivalent) and IAT Level II certification
About StratasCorp Technologies
StratasCorp Technologies is a technology company focused on building secure, mission-critical software delivery and infrastructure for highly regulated defense environments. The role emphasizes compliance-first DevSecOps practices supporting Navy and DoD contexts.
Scraped 7/31/2026