xelys jobs xelys jobs

DevSecOps Engineer

StratasCorp Technologies

full-remotemidpermanentdevopssecurity Virginia, United States Today via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsCI/CDGitLab CIKubernetesDISA STIGTerraformGitOpsSBOMCVE ScanningATO Automation

About the role

Role Overview

Hands-on DevSecOps Engineer responsible for building, automating, and sustaining the delivery infrastructure for mission-critical software. You will enable fast delivery while maintaining compliance through CI/CD, Kubernetes hardening, automated security evidence, and collaboration with engineering teams.

Responsibilities

  • Design, implement, and maintain automated CI/CD pipelines from development through security scanning, compliance validation, and deployment into Navy and DoD environments
  • Build and maintain hardened Kubernetes environments aligned with DISA STIG across cloud and restricted deployment contexts
  • Automate security artifact generation, including SBOM production, CVE scanning, and continuous compliance validation
  • Drive adoption of Infrastructure as Code, GitOps, and controls-as-code across the team
  • Use AI tooling to accelerate pipeline development, vulnerability triage, compliance remediation, and operational documentation
  • Partner with software engineers, systems engineers, and ISSEs to embed security/compliance requirements early
  • Maintain and evolve deployment infrastructure across secure environments, including air-gapped or intermittently connected contexts
  • Support ATO via automated evidence generation, documentation-as-code, and collaboration with the security team
  • Establish standards for pipeline design, container security, secrets management, and deployment consistency
  • Contribute to feature development when needed, applying a security-first perspective to application code
  • Maintain operational documentation (runbooks, deployment guides, architecture diagrams) as version-controlled artifacts

Required Skills & Experience

  • Active Secret security clearance
  • 4+ years of DevSecOps/DevOps engineering experience
  • Hands-on GitLab CI experience designing and maintaining CI/CD pipelines (additional pipeline tools a plus)
  • Kubernetes administration and hardening in DoD/compliance-driven environments; RKE2 or K3S strongly preferred
  • Ability to implement DISA STIG compliance in containerized and Linux environments (e.g., RHEL/Rocky Linux)
  • Terraform for Infrastructure as Code
  • Helm and Kubernetes deployment management
  • Automated security scanning, SBOM generation, CVE triage, and remediation
  • Scripting proficiency in Python or Bash for automation
  • Demonstrated use of AI tooling to accelerate workflows
  • Background contributing to application feature development alongside infrastructure work
  • Ability to operate independently and manage competing priorities in a small team

Preferred Qualifications

  • Experience in air-gapped/disconnected networks
  • Experience supporting ATO through automation, documentation, and technical leadership
  • Secrets management tooling: Vault, Sealed Secrets, or SOPS
  • Observability tools: Prometheus or Grafana
  • CKA certification (or willingness to obtain)
  • Experience applying “as code” approaches beyond infrastructure (configuration/policy/workflows/documentation)

Education & Certifications

  • BS in Computer Science or related field
  • Active Security+ (or equivalent)
  • IAT Level II certification

About StratasCorp Technologies

StratasCorp Technologies provides technology and engineering services focused on building secure, mission-critical software delivery capabilities for defense and government environments. The company emphasizes compliance, automation, and secure infrastructure to help teams move quickly without sacrificing security requirements.

Scraped 8/3/2026