DevSecOps Engineer
TCG
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
TCG is seeking a DevSecOps Engineer to support a Federal government customer. The role involves designing, developing, and implementing DevSecOps solutions, including CI/CD automation, container security, cloud security hardening, and monitoring.
Citizenship/background: U.S. citizenship is required and the selected applicant must pass a government background investigation and be favorably adjudicated before starting.
Position type & timing: Full-time, short-term position through September 2026, with a remote possibility of extension. Primarily remote; occasional on-site attendance may be required within commuting distance of Washington, D.C.
Responsibilities
- Design, develop, and maintain CI/CD pipelines in AWS, leveraging tools such as GitLab
- Deploy and manage containerized applications using Kubernetes and Docker in AWS
- Configure and maintain AWS environments, including baselines and security policies (aligned to Zero Trust)
- Apply security best practices across the DevSecOps lifecycle, emphasizing vulnerability management and secure configuration
- Integrate SAST/DAST into CI/CD (e.g., SonarQube, Invicti) for code and container image analysis
- Ensure container application security within Kubernetes on AWS
- Collaborate with development teams to resolve vulnerabilities reported by tools such as Tenable and track remediation progress
- Automate deployment/configuration across dev/test/prod using Ansible
- Implement and maintain monitoring and logging solutions (e.g., Splunk or ELK Stack)
- Support platform operations for AWS infrastructure (updates, patching, maintenance)
- Review and recommend improvements to cloud architecture to support scaling
Required Skills
- 5+ years DevSecOps experience; 3+ years managing and maintaining AWS ecosystems
- Strong experience with Kubernetes and Docker for containerized application management
- Proficiency in AWS security: configuring baselines/security policies to support Zero Trust (e.g., encrypted S3, IAM roles, logging)
- CI/CD pipeline experience using GitLab; Infrastructure as Code using Terraform or CloudFormation
- Hands-on security scanning/vulnerability management: SAST/DAST (SonarQube, Invicti) and Tenable
- Ability to work in an agile/iterative environment
- Dockerfile authoring/debugging for web applications (preferably Java or Angular)
- Experience standing up/managing AWS + GitLab architecture, preferably in non-DOD federal contexts
Preferred Skills
- DevSecOps certifications for cloud platforms (AWS preferred)
- Experience securing Java Spring Boot API containers
- Experience working with regulatory/legal/government data
Education
- Bachelor’s degree in Information Systems, Computer Engineering, Computer Science, or related field
About TCG
TCG is an award-winning IT solutions provider serving the Federal government. The company is a B Corp focused on profitability while supporting responsible practices for employees and the community.
Scraped 4/22/2026