DevSecOps Engineer
StratasCorp Technologies
full-remotemidpermanentdevopssecurity Virginia, United States Yesterday via LinkedIn
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
DevSecOpsCI/CDGitLab CIKubernetesDISA STIGTerraformInfrastructure as CodeGitOpsSBOMCVE Scanning
About the role
Role Overview
Hands-on DevSecOps Engineer responsible for building, automating, and sustaining delivery infrastructure so mission-critical software can move quickly without compromising compliance.
Primary Responsibilities
- Design, implement, and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment into Navy and DoD environments.
- Build and maintain hardened Kubernetes environments aligned to DISA STIG requirements across cloud and restricted network contexts.
- Automate security artifact generation and validation, including:
- SBOM production
- CVE scanning
- Continuous compliance validation
- Drive adoption of Infrastructure as Code (IaC), GitOps, and controls-as-code.
- Use AI tooling to accelerate:
- pipeline development
- vulnerability triage and remediation
- operational documentation
- Partner with software engineers, systems engineers, and ISSEs to embed security and compliance requirements early.
- Maintain and evolve deployment infrastructure across multiple secure environments, including air-gapped or intermittently connected contexts.
- Support ATO via automated evidence generation, documentation as code, and collaboration with security teams.
- Establish standards for pipeline design, container security, secrets management, and deployment consistency.
- When needed, contribute directly to feature development with a security-first approach.
- Maintain operational documentation (runbooks, deployment guides, architecture diagrams) as version-controlled artifacts.
Required Skills & Experience
- Active Secret security clearance
- 4+ years DevSecOps/DevOps engineering experience
- Hands-on CI/CD pipeline design and maintenance using GitLab CI (additional pipeline tools a plus)
- Kubernetes administration and hardening in DoD/compliance-driven environments; RKE2 or K3S strongly preferred
- Implementing DISA STIG compliance in containerized and Linux environments (e.g., RHEL/Rocky Linux)
- Infrastructure as Code, particularly Terraform
- Helm chart authoring and Kubernetes deployment management
- Automated security scanning: SBOM, CVE triage, and remediation
- Scripting proficiency in Python or Bash for pipeline/operational automation
- Demonstrated use of AI tooling to accelerate engineering workflows
- Ability to contribute to application feature development alongside infrastructure work
Preferred Qualifications
- Experience in air-gapped/disconnected network environments
- Supporting ATO through automation, documentation, and technical leadership
- Secrets management tools: Vault, Sealed Secrets, SOPS
- Observability/monitoring: Prometheus or Grafana
- CKA certification (or willingness to obtain upon onboarding)
- Experience with broader “as code” approaches beyond infrastructure (configuration/policy/workflows/documentation)
Education & Certification Requirements
- BS in Computer Science or related field
- Active Security+ (or equivalent)
- IAT Level II certification
About StratasCorp Technologies
StratasCorp Technologies appears to be an engineering-focused technology company supporting mission-critical software delivery, with an emphasis on security and compliance. The role description indicates the company operates in environments tied to Navy and DoD requirements, where delivery infrastructure must support compliance processes like ATO.
Scraped 8/2/2026