xelys jobs xelys jobs

DevSecOps Engineer

StratasCorp Technologies

full-remotemidpermanentdevopssecurity Virginia, United States Yesterday via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsCI/CDGitLab CIKubernetesDISA STIGTerraformInfrastructure as CodeGitOpsSBOMCVE Scanning

About the role

Role Overview

Hands-on DevSecOps Engineer responsible for building, automating, and sustaining delivery infrastructure so mission-critical software can move quickly without compromising compliance.

Primary Responsibilities

  • Design, implement, and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment into Navy and DoD environments.
  • Build and maintain hardened Kubernetes environments aligned to DISA STIG requirements across cloud and restricted network contexts.
  • Automate security artifact generation and validation, including:
    • SBOM production
    • CVE scanning
    • Continuous compliance validation
  • Drive adoption of Infrastructure as Code (IaC), GitOps, and controls-as-code.
  • Use AI tooling to accelerate:
    • pipeline development
    • vulnerability triage and remediation
    • operational documentation
  • Partner with software engineers, systems engineers, and ISSEs to embed security and compliance requirements early.
  • Maintain and evolve deployment infrastructure across multiple secure environments, including air-gapped or intermittently connected contexts.
  • Support ATO via automated evidence generation, documentation as code, and collaboration with security teams.
  • Establish standards for pipeline design, container security, secrets management, and deployment consistency.
  • When needed, contribute directly to feature development with a security-first approach.
  • Maintain operational documentation (runbooks, deployment guides, architecture diagrams) as version-controlled artifacts.

Required Skills & Experience

  • Active Secret security clearance
  • 4+ years DevSecOps/DevOps engineering experience
  • Hands-on CI/CD pipeline design and maintenance using GitLab CI (additional pipeline tools a plus)
  • Kubernetes administration and hardening in DoD/compliance-driven environments; RKE2 or K3S strongly preferred
  • Implementing DISA STIG compliance in containerized and Linux environments (e.g., RHEL/Rocky Linux)
  • Infrastructure as Code, particularly Terraform
  • Helm chart authoring and Kubernetes deployment management
  • Automated security scanning: SBOM, CVE triage, and remediation
  • Scripting proficiency in Python or Bash for pipeline/operational automation
  • Demonstrated use of AI tooling to accelerate engineering workflows
  • Ability to contribute to application feature development alongside infrastructure work

Preferred Qualifications

  • Experience in air-gapped/disconnected network environments
  • Supporting ATO through automation, documentation, and technical leadership
  • Secrets management tools: Vault, Sealed Secrets, SOPS
  • Observability/monitoring: Prometheus or Grafana
  • CKA certification (or willingness to obtain upon onboarding)
  • Experience with broader “as code” approaches beyond infrastructure (configuration/policy/workflows/documentation)

Education & Certification Requirements

  • BS in Computer Science or related field
  • Active Security+ (or equivalent)
  • IAT Level II certification

About StratasCorp Technologies

StratasCorp Technologies appears to be an engineering-focused technology company supporting mission-critical software delivery, with an emphasis on security and compliance. The role description indicates the company operates in environments tied to Navy and DoD requirements, where delivery infrastructure must support compliance processes like ATO.

Scraped 8/2/2026