- Salary
- $185k – $240k
- Location
- Chantilly/Herndon, VA · Chantilly, Virginia, United States
- Department
- Data & AI
- Experience
- 15+ years
- Education
- Bachelor
- Visa
- Not sponsored
- Clearance
- Required
- Source
- Greenhouse
Description
Dark Wolf constructs and deploys data management and analytics solutions for the defense and intelligence communities. We’re proud to boast a world-class engineering team that thrives on rolling up their sleeves to solve your mission’s biggest challenges.
Dark Wolf is seeking a DevSecOps Subject Matter Expert (SME) to architect, lead, and optimize Continuous Integration/Continuous Deployment (CI/CD) tooling, security paradigms, and operational observability across the entire software development lifecycle. In this role, you will serve as the principal authority on modern DevSecOps strategies, driving shift-left security practices, zero-trust architectures, and high-reliability platform engineering.
We are seeking a technical leader and strategic problem solver capable of delivering superior, high-impact results across high-performing teams in fast-paced environments.
Key Responsibilities
- Enterprise CI/CD Strategy & Operations: Architect, maintain, and optimize mission-critical CI/CD pipelines and infrastructure, leveraging tools such as Jenkins, GitLab CI/CD, and enterprise automation engines.
- Automated Security Integration & Continuous ATO: Spearhead the seamless integration of dynamic security tools and automated governance into pipelines—including SAST, DAST, dependency scanning, and container analysis—to support Continuous Authority to Operate (cATO).
- Testing & Quality Framework Design: Establish and maintain comprehensive automated testing architectures covering unit testing, integration testing, and User Acceptance Testing (UAT).
- Vulnerability & Threat Remediation: Lead cross-functional collaboration with software development and security teams to proactively identify, prioritize, and remediate application and infrastructure vulnerabilities.
- Governance & Standards Compliance: Define and enforce compliance strategies aligned with federal security regulations, DoD guidelines, and strict agency security standards.
- Technical Leadership & Innovation: Drive DevSecOps roadmaps, evaluate cutting-edge tools, define infrastructure-as-code (IaC) governance, and mentor multi-disciplinary engineering teams.
Qualifications:
- Clearance: Must be a US Citizen holding an active TS/SCI security clearance with an active Full-Scope Polygraph.
- Education: Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical field.
- Experience: Minimum 15+ years of total technical experience, with at least 7+ years specializing in building, securing, and maintaining automated CI/CD pipelines.
- Infrastructure Automation: Minimum 7+ years of hands-on experience using automation tools for infrastructure provisioning and configuration management (e.g., Terraform, Ansible).
- Source Control & Developer Tooling: Expert-level proficiency with version control systems and ecosystem platforms (e.g., Git, GitLab, Jira).
- Systems & Networking Mastery: Strong understanding of Containerization, Linux systems administration, kernel-level operations, and fundamental networking protocols.
- Communication & Leadership: Superior problem-solving skills and excellent communication abilities to articulate complex technical architectures, risks, and strategies to executive leadership, technical teams, and government stakeholders.
- Security Discipline: Deep commitment to adhering to strict security protocols, defensive systems design, and DoD/IC best practices.
Core SME Technical Competencies:
- Continuous ATO (cATO) & Compliance-as-Code: Proven expertise translating NIST SP 800-53, DISA STIGs, and CNSSI 1253 controls into automated pipeline validation checks (e.g., using OSCAL, Open Policy Agent).
- Air-Gapped & High-Security Environment Engineering: Hands-on experience designing, deploying, and maintaining CI/CD pipelines and mirror repositories within disconnected, air-gapped, or Cross Domain Solution (CDS) networks.
- Advanced Container Orchestration Security: Expert-level knowledge of Kubernetes security architectures, Service Mesh traffic policies (Istio), Admission Controllers (OPA/Gatekeeper, Kyverno), and runtime security tooling (Falco).
- Zero Trust & Secrets Lifecycle Management: Architecture experience implementing identity-aware security models and enterprise secrets management solutions (HashiCorp Vault, AWS Secrets Manager) for automated dynamic dynamic secret rotation.
Desired Qualifications:
- Programming & Scripting: Strong proficiency in programming/scripting languages such as Python, Go, Bash, or C/C++.
- Containerization: Deep practical experience with containerized software practices and container runtimes (Docker, Podman, Kubernetes).
- Agile Frameworks: Experience driving outcomes within Agile, Scrum, or SAFe software engineering methodologies.
- Multi-Cloud Architecture: Direct experience architecting secure cloud platforms across AWS, Azure, GCP, or specialized IC cloud environments (C2S/GovCloud).
- Security Scanning Tooling: Deep familiarity with modern vulnerability management and static/dynamic scanning tools (e.g., SonarQube, Snyk, Trivy, OWASP ZAP, Fortify).
Advanced Certifications:
- Certified Kubernetes Security Specialist (CKS) or Certified Kubernetes Administrator (CKA)
- Certified Information Systems Security Professional (CISSP)
- AWS Certified DevOps Engineer – Professional
- CompTIA Security+ or GIAC DevSecOps Automation (GCSA)
Position Clearance Requirement:
US Citizenship with an active TS/SCI security clearance with Full-Scope Polygraph
Location: Chantilly/Herndon, VA.
Target Salary Range: $185,000.00 – $240,000.00+ (Commensurate with specialized expertise and technical skillset).
Equal Opportunity Employer:
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.