DevSecOps Engineer
StratasCorp Technologies
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
Hands-on DevSecOps Engineer responsible for building, automating, and sustaining the delivery infrastructure for mission-critical software. You will enable fast delivery while maintaining compliance through CI/CD, Kubernetes hardening, automated security evidence, and collaboration with engineering teams.
Responsibilities
- Design, implement, and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment into Navy and DoD environments
- Build and maintain hardened Kubernetes environments aligned with DISA STIG across cloud and restricted deployment contexts
- Automate security artifact generation, including SBOM production, CVE scanning, and continuous compliance validation
- Drive adoption of Infrastructure as Code, GitOps, and controls-as-code across the team
- Use AI tooling to accelerate pipeline development, vulnerability triage, compliance remediation, and operational documentation
- Partner with software engineers, systems engineers, and ISSEs to embed security/compliance requirements early
- Maintain and evolve deployment infrastructure across secure environments, including air-gapped or intermittently connected contexts
- Support ATO via automated evidence generation, documentation-as-code, and collaboration with the security team
- Establish standards for pipeline design, container security, secrets management, and deployment consistency
- Contribute to feature development when needed, applying a security-first perspective to application code
- Maintain operational documentation (runbooks, deployment guides, architecture diagrams) as version-controlled artifacts
Required Skills & Experience
- Active Secret security clearance
- 4+ years of DevSecOps/DevOps engineering experience
- Hands-on GitLab CI experience designing and maintaining CI/CD pipelines (additional pipeline tools a plus)
- Kubernetes administration and hardening in DoD/compliance-driven environments; RKE2 or K3S strongly preferred
- Ability to implement DISA STIG compliance in containerized and Linux environments (e.g., RHEL/Rocky Linux)
- Terraform for Infrastructure as Code
- Helm and Kubernetes deployment management
- Automated security scanning, SBOM generation, CVE triage, and remediation
- Scripting proficiency in Python or Bash for automation
- Demonstrated use of AI tooling to accelerate workflows
- Background contributing to application feature development alongside infrastructure work
- Ability to operate independently and manage competing priorities in a small team
Preferred Qualifications
- Experience in air-gapped/disconnected networks
- Experience supporting ATO through automation, documentation, and technical leadership
- Secrets management tooling: Vault, Sealed Secrets, or SOPS
- Observability tools: Prometheus or Grafana
- CKA certification (or willingness to obtain)
- Experience applying “as code” approaches beyond infrastructure (configuration/policy/workflows/documentation)
Education & Certifications
- BS in Computer Science or related field
- Active Security+ (or equivalent)
- IAT Level II certification
About StratasCorp Technologies
StratasCorp Technologies provides technology and engineering services focused on building secure, mission-critical software delivery capabilities for defense and government environments. The company emphasizes compliance, automation, and secure infrastructure to help teams move quickly without sacrificing security requirements.
Scraped 8/3/2026