DevSecOps Engineer
Whitespace
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
Senior DevSecOps Engineer (100% remote) to strengthen cybersecurity posture and support federal compliance requirements, with a primary focus on achieving and maintaining a DoD/DoW Authorization to Operate (ATO). You will integrate security practices into development and operations workflows, guided by DoD DevSecOps reference architectures and RMF requirements.
Responsibilities
- Design, implement, and maintain secure CI/CD pipelines aligned with DoD DSOP/enterprise DevSecOps standards.
- Automate provisioning and secure environment deployment using Terraform, Ansible, or CloudFormation for DoD/FedRAMP systems.
- Embed security testing and scanning into pipelines, including:
- SAST, DAST, container scanning, and other security toolsets for continuous compliance.
- Implement and operationalize DoD STIGs, DISA baselines, and RMF controls using Infrastructure as Code (IaC).
- Translate DoD security controls into automated enforcement/validation in CI/CD.
- Build compliance validation tooling and scripts (e.g., OpenSCAP, Chef InSpec, PowerSTIG).
- Co-develop technical documentation supporting RMF authorization and continuous monitoring.
- Manage and integrate DevSecOps toolchains such as:
- GitLab, Jenkins, ArgoCD, Harbor, Nexus, SonarQube, Anchore.
- Automate container security and orchestrate deployments using Kubernetes.
- Manage secrets, credential rotation, and logging using Vault, DoD-approved KMS, or AWS Secrets Manager.
- Collaborate with security, engineering, and operations teams to align with DoD RMF, NIST SP 800-53, and/or FedRAMP.
- Partner with ISSOs/ISSMs and security control assessors to support ATO package development.
- Act as an internal subject matter expert on federal compliance and cybersecurity practices.
Requirements
- U.S. citizenship; must reside in the contiguous United States.
- Active security clearance preferred: US Gov Secret or above (not a hard requirement).
- Bachelor’s degree in CS (or related) or equivalent experience.
- 7+ years hands-on DevSecOps experience in AI/ML or data-intensive systems.
- Proven success managing/driving ATO processes.
- Strong understanding of federal security compliance standards (NIST 800-53, RMF, FedRAMP).
- Hands-on cloud experience (AWS, Azure, or GCP) and containerization (Docker, Kubernetes).
- Familiarity with OpenShift or Kubernetes security hardening.
- Knowledge of Zero Trust Architecture (ZTA) concepts.
- Strong scripting/automation skills (Python, Bash, or similar).
- Excellent leadership, communication, and documentation skills.
Nice-to-Haves / Focus Areas
- DoD cloud environment experience (AWS GovCloud, Azure Government, DoD Cloud, air-gapped environments).
- Expertise integrating DoD DevSecOps reference architecture and secure CI/CD practices.
Logistics
- Remote: 100% remote.
- Travel: less than 20%.
About Whitespace
Whitespace delivers innovative technological solutions with a strong emphasis on security and compliance. The company supports federal cybersecurity and compliance requirements, including DoD authorization processes and continuous monitoring.
Scraped 7/2/2026