DevSecOps Lead

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
Senior level
Information Technology
The Role
Lead design and implementation of secure CI/CD pipelines, IaC (Terraform/Ansible/YAML), and Kubernetes-based deployments on OCI. Integrate SAST/DAST/SCA, enforce DoD RMF/ATO compliance, build automated test frameworks, manage container/runtime security, and drive DevSecOps tooling, onboarding, and continuous improvement in a federal security-controlled environment.
Summary Generated by Built In

About Concept Plus
Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.


Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.


We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.


For more information, visit www.conceptplus.com.


About the role

Concept Plus LLC is seeking an experienced DevSecOps Lead to drive the design, implementation, and continuous improvement of secure CI/CD pipelines, automated testing frameworks, and Infrastructure as Code (IaC) practices to provide common services for Oracle eBusiness applications hosted on Oracle Cloud Infrastructure (OCI) platforms. The DevSecOps Lead will embed security, quality, and automation throughout the entire service lifecycle — from development through operations — ensuring that all common services on the Cloud One Oracle Cloud Infrastructure (OCI) platform are delivered with speed, rigor, and compliance. This is a key leadership role requiring a minimum of 5 years of hands-on DevSecOps experience, including demonstrated proficiency with YAML, Ansible, Git, Jenkins or equivalent pipeline tooling (e.g., GitLab CI/CD), Terraform-based IaC, and Kubernetes (K8s) container orchestration, along with experience operating in a DoD or Federal security-controlled environment. An active Secret clearance and DoD 8140/8570 IAT-II or higher certification are required to start.

What you'll do

  • Design, implement, and maintain secure CI/CD pipelines using Jenkins, GitLab CI/CD, or comparable enterprise tooling to automate build, test, and deployment workflows for all common services on OCI
  • Develop and maintain Infrastructure as Code (IaC) using Ansible, YAML, and Terraform to automate environment provisioning, configuration management, and compliance enforcement across OCI environments
  • Architect, deploy, and manage containerized workloads using Kubernetes (K8s) or OCI Container Engine (OKE), including cluster configuration, workload scheduling, secrets management, and runtime security controls
  • Integrate SAST, DAST, software composition analysis (SCA), and container image scanning tools into all CI/CD pipelines to enforce security-left practices throughout the development lifecycle
  • Establish and maintain a comprehensive automated test framework — including unit, integration, regression, and performance testing — in support of the Government's Test Automation objectives
  • Enforce code quality, branching strategies, and version control governance across all development teams using Git (GitHub, GitLab, or equivalent)
  • Embed DoD RMF controls and security compliance checks into CI/CD workflows to support continuous ATO and audit readiness
  • Collaborate with the Cybersecurity Lead/ISSO to ensure all pipeline artifacts, container images, and deployed services meet required security scanning thresholds and DoD 8140/8570 compliance baselines
  • Lead DevSecOps toolchain onboarding, training, and standards adoption across all integrated team members
  • Monitor pipeline performance, test coverage metrics, and deployment frequency; report results to the Program Manager and Government stakeholders as part of recurring performance reporting
  • Support the Technical Lead in aligning DevSecOps practices with the OCI platform architecture, including OCI DevOps services, OCI Artifact Registry, and OCI Vault
  • Develop and maintain automated patching, configuration compliance, and vulnerability remediation workflows to support 24/7/365 operational sustainment requirements
  • Contribute to AI/ML integration efforts by implementing automated pipelines for model training, validation, and deployment within the authorized OCI environment
  • Support transition-in activities by assessing the incumbent's existing pipeline tooling, identifying gaps, and migrating to the team's DevSecOps toolchain with no disruption to operations

Required Qualifications

  • US Citizen
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related technical field
  • 5+ years of hands-on DevSecOps, platform engineering, or software delivery engineering experience
  • Proficiency with YAML for configuration, pipeline, and IaC definition
  • Hands-on experience with Ansible for configuration management and automated provisioning
  • Proficiency with Git-based version control (GitHub, GitLab, Bitbucket, or equivalent) and branching/merge strategies
  • Hands-on experience designing and maintaining CI/CD pipelines using Jenkins, GitLab CI/CD, or comparable enterprise pipeline tooling
  • Demonstrated experience implementing Infrastructure as Code (IaC) using Terraform, including state management, module design, and automated compliance enforcement
  • Demonstrated experience deploying and managing containerized applications using Kubernetes (K8s), including cluster administration, Helm charts, namespace management, and workload security
  • Experience integrating SAST, DAST, and security scanning tools into automated pipelines (e.g., SonarQube, Fortify, Checkmarx, Twistlock/Prisma Cloud, or equivalent)
  • Experience building and maintaining automated test frameworks for web services, APIs, or enterprise applications
  • Familiarity with DoD RMF, ATO processes, and embedding security compliance into development and deployment pipelines
  • Active DoD Secret clearance required to start; must be maintainable for the duration of the program
  • Active DoD 8140/8570 IAT-II or higher certification required at time of hire (qualifying certifications include CompTIA Security+ CE, CompTIA CySA+, GSEC, SSCP, GICSP, CND, or any IAT-III equivalent such as CASP+ CE, CISSP, CISA, CCNP Security, GCED, or GCIH)

Preferred Qualifications

  • Active Top Secret (TS) security clearance; candidates holding an active TS clearance will be given strong preference as the program's operational scope and data sensitivity may require TS access
  • Experience with FlexDeploy (Flexagon) as a DevOps orchestration and release automation platform, particularly for Oracle-technology deployments including Oracle eBS, Oracle Fusion Middleware, SOA Suite, or WebLogic
  • Experience operating within a DISA-managed or Cloud One cloud environment, including familiarity with IL4/IL5 authorization boundaries and FedRAMP controls
  • Hands-on experience with OCI DevOps services, OCI Container Engine for Kubernetes (OKE), OCI Artifact Registry, or OCI Vault
  • Familiarity with Oracle eBusiness Suite (eBS), Oracle Fusion Middleware, or Oracle database environments and associated patch/deploy automation
  • Experience with automated testing tools such as Selenium, Robot Framework, Postman/Newman, JMeter, JUnit, TestNG, or Cucumber
  • Experience with security scanning tools specific to Oracle or Java-based environments (e.g., Fortify for Java, OWASP ZAP, or Oracle-specific vulnerability scanning)
  • Additional certifications such as Certified Kubernetes Administrator (CKA), HashiCorp Terraform Associate, OCI DevOps certifications, or DoD 8140 CSSP Analyst/Developer designations
  • Prior experience supporting AFLCMC, BES Directorate, or a DoD ERP program of record
  • Familiarity with Agile/SAFe delivery frameworks and sprint-based DevSecOps execution within Integrated Team Structures

Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.


Skills Required

  • US Citizen
  • Bachelor's degree in Computer Science, IT, Cybersecurity, or related field
  • 5+ years hands-on DevSecOps, platform engineering, or software delivery engineering experience
  • Proficiency with YAML for configuration, pipeline, and IaC definition
  • Hands-on experience with Ansible for configuration management and automated provisioning
  • Proficiency with Git-based version control (GitHub, GitLab, Bitbucket, or equivalent)
  • Hands-on experience designing and maintaining CI/CD pipelines using Jenkins, GitLab CI/CD, or comparable tooling
  • Demonstrated experience implementing Infrastructure as Code (IaC) using Terraform
  • Demonstrated experience deploying and managing containerized applications using Kubernetes (K8s), including Helm
  • Experience integrating SAST, DAST, and software composition analysis (SCA) and container image scanning into CI/CD pipelines
  • Experience building and maintaining automated test frameworks for web services, APIs, or enterprise applications
  • Familiarity with DoD RMF, ATO processes, and embedding security compliance into pipelines
  • Active DoD Secret clearance required to start; must be maintainable for the duration of the program
  • Active DoD 8140/8570 IAT-II or higher certification at time of hire (e.g., Security+ CE, CySA+, GSEC, SSCP, or equivalent)
  • Experience operating in a DoD or Federal security-controlled environment
  • Active Top Secret (TS) security clearance
  • Experience with FlexDeploy (Flexagon) for DevOps orchestration and Oracle deployments
  • Experience with DISA-managed or Cloud One environments, IL4/IL5, and FedRAMP controls
  • Hands-on experience with OCI DevOps services, OKE, OCI Artifact Registry, or OCI Vault
  • Familiarity with Oracle eBusiness Suite, Oracle Fusion Middleware, WebLogic, or Oracle DB deployment automation
  • Experience with automated testing tools such as Selenium, Robot Framework, Postman/Newman, JMeter, JUnit, TestNG, or Cucumber
  • Experience with security scanning tools for Java/Oracle (Fortify, OWASP ZAP) or container security (Twistlock/Prisma Cloud)
  • Certifications such as CKA, HashiCorp Terraform Associate, OCI DevOps certs, or DoD 8140 CSSP Analyst/Developer
  • Familiarity with Agile/SAFe delivery frameworks
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fairfax, VA
102 Employees
Year Founded: 2008

What We Do

Concept Plus is a technology services company offering deep technical expertise, an experienced team, and a dedication to maximizing business productivity. A process driven organization, Concept Plus provides solutions for clients that align technology with strategic goals and business drivers. Oracle, Cloud Computing, Healthcare IT and Mobile technologies are our strength; client service and partner focus our mission. Headquartered outside of Washington, D.C., we are SDB and SBA 8(a) certified, an Oracle Platinum Partner, ISO 9001, 20000-1, and 27001 certified, and CMMI Maturity Level 3 Appraised.

Similar Jobs

In-Office or Remote
Dayton, OH, USA
285 Employees

DEFCON AI Logo DEFCON AI

Devsecops Engineer

Logistics • Transportation
Remote
USA
31 Employees
175K-215K Annually

Red Cell Partners Logo Red Cell Partners

Devsecops Engineer

Fintech • Payments • Financial Services
Remote
USA
64 Employees
175K-215K Annually

General Dynamics Information Technology Logo General Dynamics Information Technology

Systems Engineer

Aerospace • Information Technology • Professional Services • Security • Software
Remote
United States
21625 Employees
213K-288K Annually

Similar Companies Hiring

Scrunch  Thumbnail
Artificial Intelligence • Information Technology • Marketing Tech • Software • SEO
Salt Lake City, Utah
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account