xelys jobs xelys jobs

DevSecOps Engineer

TCG

hybridseniorfixed-termdevopssecurity Washington, DC 98 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsAWSCI/CDGitLabKubernetesDockerTerraformSonarQubeSAST/DASTZero Trust

About the role

Role Overview

TCG is seeking a DevSecOps Engineer to support a Federal government customer. The role involves designing, developing, and implementing DevSecOps solutions, including CI/CD automation, container security, cloud security hardening, and monitoring.

Citizenship/background: U.S. citizenship is required and the selected applicant must pass a government background investigation and be favorably adjudicated before starting.

Position type & timing: Full-time, short-term position through September 2026, with a remote possibility of extension. Primarily remote; occasional on-site attendance may be required within commuting distance of Washington, D.C.

Responsibilities

  • Design, develop, and maintain CI/CD pipelines in AWS, leveraging tools such as GitLab
  • Deploy and manage containerized applications using Kubernetes and Docker in AWS
  • Configure and maintain AWS environments, including baselines and security policies (aligned to Zero Trust)
  • Apply security best practices across the DevSecOps lifecycle, emphasizing vulnerability management and secure configuration
  • Integrate SAST/DAST into CI/CD (e.g., SonarQube, Invicti) for code and container image analysis
  • Ensure container application security within Kubernetes on AWS
  • Collaborate with development teams to resolve vulnerabilities reported by tools such as Tenable and track remediation progress
  • Automate deployment/configuration across dev/test/prod using Ansible
  • Implement and maintain monitoring and logging solutions (e.g., Splunk or ELK Stack)
  • Support platform operations for AWS infrastructure (updates, patching, maintenance)
  • Review and recommend improvements to cloud architecture to support scaling

Required Skills

  • 5+ years DevSecOps experience; 3+ years managing and maintaining AWS ecosystems
  • Strong experience with Kubernetes and Docker for containerized application management
  • Proficiency in AWS security: configuring baselines/security policies to support Zero Trust (e.g., encrypted S3, IAM roles, logging)
  • CI/CD pipeline experience using GitLab; Infrastructure as Code using Terraform or CloudFormation
  • Hands-on security scanning/vulnerability management: SAST/DAST (SonarQube, Invicti) and Tenable
  • Ability to work in an agile/iterative environment
  • Dockerfile authoring/debugging for web applications (preferably Java or Angular)
  • Experience standing up/managing AWS + GitLab architecture, preferably in non-DOD federal contexts

Preferred Skills

  • DevSecOps certifications for cloud platforms (AWS preferred)
  • Experience securing Java Spring Boot API containers
  • Experience working with regulatory/legal/government data

Education

  • Bachelor’s degree in Information Systems, Computer Engineering, Computer Science, or related field

About TCG

TCG is an award-winning IT solutions provider serving the Federal government. The company is a B Corp focused on profitability while supporting responsible practices for employees and the community.

Scraped 4/22/2026