DevSecOps Engineer

Posted An Hour Ago
Be an Early Applicant
Arlington, VA, USA
In-Office
130K-160K Annually
Senior level
Information Technology • Logistics • Consulting • Defense
The Role
Designs, administers, and improves secure CI/CD pipelines and deployment environments. Integrates automated security testing, vulnerability scanning, secrets management, containers, infrastructure as code, and policy gates. Supports cloud and on-premises systems, RMF authorization, STIG-aligned configurations, security evidence, monitoring, troubleshooting, patching, and incident response. Collaborates with development, infrastructure, cybersecurity, testing, and customer teams to improve secure software delivery and auditability.
Summary Generated by Built In
Overview

Na Ali‘i is seeking a DevSecOps Engineer to support the secure delivery and operation of a software solution for a Department of the Navy organization and serve as a team member of Nakupuna Labs, the in-house innovation team. The ideal candidate has advanced experience in designing, implementing, administering, and continuously improving CI/CD pipelines, deployment environments, and integrated security controls.

Responsibilities

The following reflects management's definition of essential functions for this job but does not restrict the tasks that may be assigned.

  • Designing, implementing, and administering CI/CD pipelines that automate build, test, security scanning, approval, release, rollback, and deployment activities across development, test, and production environments.
  • Integrating and maintaining automated security controls, including static and dynamic application security testing, software composition analysis, secrets scanning, container and infrastructure-as-code scanning, and policy-based quality gates.
  • Administering source code and artifact repositories, pipeline runners or agents, deployment credentials, certificates, secrets, and role-based access in accordance with least-privilege principles.
  • Automating infrastructure provisioning and configuration to create repeatable, hardened, and Security Technical Implementation Guide (STIG)-aligned environments and configuration baselines.
  • Managing containerized application build and deployment processes and, where applicable, orchestration platforms, registries, software bills of materials, and signed artifacts.
  • Monitoring pipeline and platform availability, performance, and security events; troubleshooting build and deployment failures; and coordinating patching, incident response, and vulnerability remediation.
  • Maintaining release records, system diagrams, operating procedures, security evidence, and Risk Management Framework (RMF) authorization artifacts; supporting control assessments, remediation activities, and continuous monitoring.
  • Collaborating with developers, testers, cybersecurity personnel, infrastructure teams, and customer stakeholders to translate delivery and security requirements into automated controls and improve reliability, delivery speed, and auditability.
Qualifications

The ideal candidate has experience with the following technical knowledge, skills, and abilities:

  • Hands-on experience designing and administering production CI/CD pipelines using tools such as GitLab CI/CD, GitHub Actions, Azure DevOps, or Jenkins, including Git workflows, release management, and artifact repositories.
  • Experience with containers and orchestration technologies, such as Docker and Kubernetes, and with infrastructure-as-code or configuration-management tools, such as Terraform, Bicep, CloudFormation, or Ansible.
  • Experience administering Azure, AWS, or on-premises environments, including Linux or Windows systems, networking, identity and access management, certificates, and secrets.
  • Ability to automate operational tasks using PowerShell, Bash, Python, or a comparable scripting language.
  • Working knowledge of secure software delivery practices, vulnerability management, STIGs, DoD RMF, NIST SP 800-53 controls, security evidence collection, and authorization support.
  • Strong troubleshooting, documentation, communication, and collaboration skills, including the ability to work effectively with technical teams and customer stakeholders.
  • Desired Certifications:
    • One or more relevant certifications, such as Security+ CE, CySA+, CISSP, CSSLP, GSEC, or a cloud, DevOps, or Kubernetes security credential.

Education and Experience:

This position requires a Bachelor's degree in computer science, information technology, cybersecurity, engineering, or a related field and at least 5 years of relevant professional experience.


Clearance:

This position requires an active Secret security clearance. Must be a U.S. citizen.


Physical Requirements: The ideal candidate must at a minimum be able to meet the following physical requirements of the job with or without a reasonable accommodation:

  • Ability to perform repetitive motions with the hands, wrists, and fingers.
  • Ability to engage in and follow audible communications in emergency situations.
  • Ability to sit for prolonged periods at a desk and working on a computer.

The Nakupuna Companies use a market-based compensation strategy to ensure that our employees are compensated within applicable market ranges commensurate with multiple factors, including but not limited to the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, organizational requirements, and position location. The projected compensation range for this position is $130,00 to $160,000 (annualized USD). The salary range displayed represents the typical salary range for this position and is just one component of Nakupuna Companies' total compensation package for employees.

Skills Required

  • Bachelor's degree in computer science, information technology, cybersecurity, engineering, or a related field
  • At least 5 years of relevant professional experience
  • Hands-on experience designing and administering production CI/CD pipelines
  • Experience with Git workflows, release management, and artifact repositories
  • Experience with Docker and Kubernetes
  • Experience with infrastructure-as-code or configuration-management tools such as Terraform, Bicep, CloudFormation, or Ansible
  • Experience administering Azure, AWS, or on-premises environments
  • Experience with Linux or Windows systems, networking, identity and access management, certificates, and secrets
  • Ability to automate operational tasks using PowerShell, Bash, Python, or a comparable scripting language
  • Working knowledge of secure software delivery, vulnerability management, STIGs, DoD RMF, NIST SP 800-53 controls, security evidence collection, and authorization support
  • Strong troubleshooting, documentation, communication, and collaboration skills
  • Active Secret security clearance
  • U.S. citizenship
  • Relevant certification such as Security+ CE, CySA+, CISSP, CSSLP, GSEC, or a cloud, DevOps, or Kubernetes security credential
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,040 Employees
Year Founded: 2003

What We Do

Nakupuna Companies is a Native Hawaiian Organization–owned family of businesses serving federal, defense, and civilian government clients. Its capabilities span management consulting, information technology, facilities and infrastructure, environmental consulting, and logistics, including strategic planning, network operations, application development, infrastructure support, environmental construction, and warehouse or inventory services. The company’s mission combines solving difficult government problems with creating economic opportunities for the Native Hawaiian community.

Similar Jobs

Vantor Logo Vantor

Devsecops Engineer

Aerospace • Artificial Intelligence • Computer Vision • Software • Analytics • Defense • Big Data Analytics
In-Office
Herndon, VA, USA
2500 Employees
140K-206K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Devsecops Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Sterling, VA, USA
40000 Employees
150K-254K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Devsecops Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Sterling, VA, USA
40000 Employees
147K-249K Annually
Remote or Hybrid
United States
150 Employees
100K-135K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account