POSITION OVERVIEW
SteerBridge is seeking a DevSecOps Engineer to own the security infrastructure and automation behind a mission-critical VA Disability Claims platform that supports Veterans and federal customers in AWS GovCloud. This role builds and runs the systems that security depends on: the log pipelines that feed our SIEM, the CI/CD and infrastructure-as-code pipelines that deploy every environment, and the scanning, patching, and security services deployed across our accounts.
The engineer partners closely with our security team, which monitors the environment, triages alerts, and leads incident response. This role makes sure that team has complete, reliable data and working tools, and turns their requirements into code, guardrails, and pipelines that run automatically. The engineer will also work with cloud engineers, solutions and security architects, application developers, and program leadership.
This is a hands-on role. The ideal candidate writes Terraform and pipeline code, onboards new log sources end to end, keeps security tooling deployed and healthy, and fixes the root cause when a pipeline, agent, or integration breaks. They are comfortable reviewing a merge request, debugging a broken data connector, and documenting how a control is implemented.
This is a hybrid position based in Vienna, VA.
Key Responsibilities
Own end-to-end security log pipelines from AWS and SaaS sources into Microsoft Sentinel, including CloudTrail, VPC Flow Logs, DNS query logs, GuardDuty, WAF, identity provider, and zero-trust platform logs.
Onboard and validate new log sources using native delivery paths, including data collection endpoints and rules, S3/SQS connectors, and vendor streaming; monitor pipeline health, ingestion gaps, data completeness, and parsing accuracy.
Manage security log retention, centralization, and immutability in accordance with federal logging and compliance requirements.
Own GitLab CI/CD pipelines used to plan and deploy Terraform and Terragrunt across multiple AWS GovCloud accounts and organizations.
Implement and maintain CI/CD security controls, including IaC scanning, secrets detection, container image scanning, dependency and SBOM checks, least-privilege deployment roles, protected branches, approval rules, and secure state and secrets handling.
Standardize secure container build and release practices for ECS and Fargate workloads, including immutable image tags, signed and scanned images, and ECR lifecycle policies.
Maintain security baselines across cloud environments, including IAM Identity Center permission sets, least-privilege roles, encryption, network segmentation, zero-trust access through Zscaler ZPA/ZIA, and inline inspection using Palo Alto VM-Series.
Document infrastructure security controls and maintain operational runbooks supporting NIST SP 800-53, RMF, and ATO activities.
Required Qualifications
Eligibility requirements: U.S. citizenship is required for this position under applicable federal contract requirements. Candidate must also be able to obtain and maintain the security clearance required for the role.
5+ years of hands-on experience in DevOps, cloud security, security engineering, or a related field, preferably within AWS environments.
Strong experience with infrastructure as code, including Terraform, and familiarity with Terragrunt, policy-as-code, and IaC security scanning tools such as Checkov or tfsec.
Experience building and securing CI/CD pipelines using GitLab CI, GitHub Actions, or similar platforms, including SAST, DAST, SCA, secrets detection, container image scanning, and secrets management using tools such as SonarQube, Snyk, Trivy, Checkmarx, AWS Secrets Manager, or KMS.
Experience building and troubleshooting security log pipelines into SIEM platforms such as Microsoft Sentinel, Splunk, or Elastic, including log-source onboarding and ingestion monitoring.
Experience implementing AWS security services across multi-account environments, including CloudTrail, GuardDuty, Security Hub, Config, and IAM, with a strong understanding of cloud networking, identity, least-privilege access, and zero-trust principles.
Experience securing containerized workloads using Docker with ECS, Fargate, or Kubernetes, along with scripting and automation skills in Python, Bash, or PowerShell and strong troubleshooting, documentation, and cross-functional communication skills.
Experience with AWS GovCloud or other regulated or federal cloud environments, including familiarity with NIST SP 800-53, RMF, FedRAMP, or federal ATO processes.
Experience with multi-account AWS Organizations, service control policies (SCPs), and AWS landing zone patterns such as Trusted Secure Enclaves or Landing Zone Accelerator.
Familiarity with Terragrunt and log transformation tools such as Vector.
Experience with Azure Monitor data collection, including data collection endpoints and rules, and working knowledge of KQL for validating ingested data.
Experience with security and infrastructure platforms such as Zscaler ZPA/ZIA, Palo Alto or comparable next-generation firewalls, Tenable vulnerability scanning, and AWS Systems Manager patching at scale.
Relevant certifications such as AWS Certified Security – Specialty or AWS Certified DevOps Engineer – Professional.
Benefits
- Health insurance
- Dental insurance
- Vision insurance
- Life Insurance
- 401(k) Retirement Plan with matching
- Paid Time Off
- Paid Federal Holidays
Skills Required
- U.S. citizenship
- 5+ years of hands-on experience across DevOps, cloud security, or security engineering, preferably with AWS
- Strong experience with Terraform infrastructure as code; Terragrunt is a plus
- Experience with policy-as-code and IaC security scanning, such as Checkov or tfsec
- Experience building and securing CI/CD pipelines, preferably GitLab CI
- Experience integrating SAST, DAST, SCA, secrets, and container image scanning
- Experience with secrets management, such as AWS Secrets Manager and KMS
- Experience building log pipelines into a SIEM and troubleshooting ingestion
- Experience deploying AWS security services including CloudTrail, GuardDuty, Security Hub, Config, and IAM across multiple accounts
- Experience deploying and securing containerized workloads using Docker with ECS, Fargate, or Kubernetes
- Solid understanding of cloud networking, identity, least-privilege access, and zero-trust principles
- Scripting and automation skills in Python, Bash, or PowerShell
- Strong troubleshooting, communication, documentation, diagramming, and runbook skills
- Experience in AWS GovCloud or other regulated or federal cloud environments
- Familiarity with Vector or other log transformation tools
- Experience with AWS Organizations, service control policies, or AWS landing zone patterns
- Experience with Azure Monitor data collection and KQL
- Experience with Zscaler or comparable ZTNA/SASE platforms and Palo Alto or similar next-generation firewalls
- Experience deploying vulnerability scanning tools such as Tenable and AWS Systems Manager patching at scale
- Familiarity with NIST 800-53, RMF, FedRAMP, or federal ATO processes
- AWS Security Specialty or AWS DevOps Engineer Professional certification
What We Do
SteerBridge is a technology company that provides professional services and solutions to the U.S. Government and Corporate counterparts through a wide array of capabilities and myopic focus on innovative solutions. We leverage decades of federal acquisition and private sector experience to deliver best in class commercial solutions while maximizing Veteran talent to enhance efficiency and surpass expectations. Current & Past Services include: Veteran Relations | Strategic Communications | General Technology Services | Software Engineering | Program Management | Business Process Management | Cybersecurity Professional Services | AI/ML capabilities | Data Management & Analytics.







