- Salary
- $100k – $110k
- Location
- Springfield, VA
- Workplace
- Remote, Onsite
- Department
- Engineering
- Experience
- 2+ years
- Education
- Bachelor
- Source
- Paylocity
Description
Description
Contingent Upon Contract Award
Remote with occasional on-site support
Connected Logistics is seeking a DevSecOps Engineer to support the Cybersecurity Architecture and Engineering Services supporting the Department of Veterans Affairs (VA) Office of Information Security (OIS) Cybersecurity Operations Systems Engineering (COSE) program.
The DevSecOps Engineer provides specialized cybersecurity and DevSecOps expertise supporting the design, development, integration, deployment, and operation of secure applications and information systems. The DevSecOps Engineer integrates security throughout the software development lifecycle (SDLC), evaluates security requirements and technology capabilities, identifies and mitigates cybersecurity risks, and develops solutions that enable secure and reliable delivery of mission-critical capabilities. The DevSecOps Engineer works with development, security, operations, and engineering teams to incorporate automated security controls, continuous monitoring, vulnerability management, and compliance activities into development and deployment processes. The position also supports technical risk analysis, including risk assessments, and provides technical direction and daily supervision to assigned staff.
Key Responsibilities
- Analyze and define cybersecurity and system security requirements for applications, platforms, infrastructure, and development environments.
- Design, develop, engineer, and implement secure solutions that address application, infrastructure, cloud, container, and DevSecOps security requirements.
- Integrate security controls and testing throughout the SDLC and CI/CD pipeline.
- Implement and support automated security testing, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), dependency scanning, container scanning, and infrastructure-as-code security scanning, as applicable.
- Evaluate security products, platforms, and tools to determine suitability for technical and mission requirements.
- Identify vulnerabilities, security deficiencies, and technical risks and coordinate remediation activities with development and operations teams.
- Perform cybersecurity risk analysis, including risk identification, assessment, prioritization, mitigation, and tracking.
- Support secure configuration, vulnerability management, continuous monitoring, and security compliance activities across development, test, staging, and production environments.
- Gather and organize technical information regarding organizational mission objectives, system requirements, existing security capabilities, architectures, products, and ongoing cybersecurity initiatives.
- Collaborate with developers, system engineers, security engineers, architects, and operations personnel to embed security into application and infrastructure engineering processes.
- Develop and maintain security-related technical documentation, engineering artifacts, procedures, implementation guidance, and risk assessment information.
- Support investigation / resolution of security findings identified through automated testing, vulnerability assessments, security reviews, or compliance activities.
- Promote consistent application of secure coding, secure configuration, least privilege, secrets management, identity and access management, and other cybersecurity engineering practices.
- Provide technical guidance, daily supervision, direction to assigned technical staff.
- Communicate cybersecurity risks, technical recommendations, remediation priorities, and implementation considerations to technical and program stakeholders.
Requirements
- Public Trust: T4 or T5 (TS)
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Information Systems, Risk Management or a related technical discipline or an Associate's degree in the above discipline with an additional 2 years of experience.
- Minimum of five (5) years of relevant professional experience in cybersecurity, information security, DevSecOps, systems security engineering, application security, or a related technical field.
- Demonstrated experience analyzing cybersecurity requirements and implementing technical security solutions.
- Experience supporting DevSecOps processes and integrating cybersecurity activities into application development and deployment workflows.
- Experience performing cybersecurity risk assessments and identifying appropriate technical risk mitigation approaches.
- Knowledge of security principles, vulnerability management, security testing, access control, secure configuration, and continuous monitoring.
- Ability to collaborate effectively with software development, security, engineering, and IT operations teams.
- Ability to develop clear technical documentation and communicate security requirements and risks to technical and non-technical stakeholders.
- Experience providing technical direction, supervision, or leadership to technical personnel.
Preferred Qualifications:
- Experience implementing DevSecOps practices within federal government environments.
- Experience designing or operating secure CI/CD pipelines.
- Experience with automated application and infrastructure security testing technologies.
- Experience securing cloud-native applications, containers, Kubernetes environments, microservices, APIs, and infrastructure-as-code deployments.
- Experience with source-code management, build automation, artifact repositories, container registries, and automated deployment technologies.
- Familiarity with federal cybersecurity requirements, security controls, risk management, and continuous monitoring practices.
- Experience supporting security authorization, assessment, remediation, and compliance activities.
- Experience implementing security gates and automated compliance checks within CI/CD pipelines.
- Knowledge of secure software development practices, supply-chain security, secrets management, identity and access management, and zero-trust security principles.
- Relevant cybersecurity, cloud, DevSecOps, or technical certifications are desirable.
Total Rewards Statement
We believe in fairness and clarity throughout our hiring process. The anticipated salary range for this position is $100,000.00-$110,000.00 USD. This is a good-faith range based on factors such as your experience, geographic location, and any applicable contractual requirements, and may vary slightly.
Beyond salary, we provide a robust benefits package and encourage ongoing professional development, because your growth and well-being matter to us. We’re excited to support you in building a rewarding career with us!
Connected Logistics respects the need for confidentiality for all applicants.
Connected Logistics has been named a 2026 WTOP Top Workplace in the medium sized business category. Our mission is clear: we deliver mission-focused IT, cybersecurity, logistics, and enterprise modernization support to federal agencies. When we invest in our people and create an environment where they feel valued and empowered, we deliver stronger outcomes for our clients and the missions we support.
Connected Logistics offers an excellent benefits package that includes health, dental, vision, life, and disability insurance, a great 401(k) package, and generous Paid Time Off.
EOE/Disability/Veterans