DevSecOps Engineer

7 days ago


Arlington, United States RIT Solutions, Inc. Full time
Local candidates only- must send documentation with name/address
Candidate MUST be open to onsite interview as final interview

Vendor Call Notes:
  • DevSecOps Engineer, involved in integration apps to CI pipelines that build and deploy apps, they do security
  • Set of security testing tools and integrate to pipeline, integrate whole process, fixing issues, automated whole process, work with dev team
  • Experience with DevOps processes, Jenkins, plugins that can be used, Groovy for writing scripts to help with automation
  • Jenkins used for CI/CD processes, will know Groovy if worked with Jenkins (a plus in basic knowledge) - will not write 100s lines of Groovy code, updating existing ones
  • Use Python for automation of process - need python development (6-7 years of exp) - write scripts to automate processes
  • Internal scripts are what they use, not customer facing script
  • OWASP good to have
  • Maintenance of existing process and implementing new process
  • Need security piece
  • 6 members including team lead (onshore/offshore)
  • Proactive mindset, work with other teams, meet with any issues in environment and able to reach out to other teams to fix issue, large org experience, preferably financial (exposure to complex and diverse development)

What You'll Do:
- Collaborate with a team of engineers to implement Brokerage specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications.
- Work with Development, DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevOps processes.
- Define the security rules that needs to be adhered to at a code level in web and mobile applications written in Java, React, Objective C, SWIFT, Kotlin etc. - DO NOT NEED TO KNOW, nice to have
- With your development background and security knowledge, provide security guidance to developers in the form secure coding standards and guidelines.
- Support security standards, create templates and patterns to increase the efficiency and adoption of security program. - Good if familiar but they can train them on that

These skills will help you succeed in this role:
- Bachelor's degree with minimum 8 years of work experience in the IT field
- 3+ years software development experience using Java, JavaScript
- 3+ years of experience in the following:
- OWASP Secure Coding Practices - GOOD TO HAVE
- Common software and web application security vulnerabilities
- Application security scanning tools
- Continuous Integration/Continuous Deployment (CI/CD) processes and concepts using relevant technologies and tools (e.g., Jenkins) - Required
- Experience in Python scripting - Required

Even Better If You Have
- A degree in Cybersecurity or CISSP/CSSLP certification or keen desire to move to security field
- Business acumen to support the implementation of SAST or DAST or IAST across the enterprise
- Ability to perform code reviews with minimal assistance
- A self-starter, with a strong desire for learning new technologies and applying them to solve problems
- Experience with two or more of the application build environments like Jenkins, Gradle, Maven.
- Familiarity with public cloud services a plus
- Experience with two or more of the Secure SDLC tools like Burp Suite, Fortify, Checkmarx, AppSec SE, Veracode, WhiteSource, Sonatype
- Experience with Threat Analysis.
- Experience with DevSecOps, Secure SDLC.
- DevOps container/orchestration tools (Kubernetes, Docker, Puppet, etc) is a plus
- Experience with evaluation, integration and onboard of security tools such as RASP, WAF, vulnerability scanner results, container analyzers, open source scanning etc is a plus
  • DevSecOps Engineer

    1 day ago


    Arlington, United States Innovative Defense Technologies Full time

    Background Information: Innovative Defense Technologies (IDT), provider of automated software testing, data analysis, and cybersecurity solutions for complex, mission-critical systems for the US Department of Defense (DOD) and commercial customers, is seeking a DevSecOps Engineer to be based in our Arlington, VA office. This individual will work with senior...


  • Arlington, United States SAIC Full time

    Description SAIC is seeking a proven Senior DevSecOps Cloud Engineer to join the Enterprise Cloud Management Agency (ECMA) Cloud Enterprise Technology Services (CETS) program and the opportunity to evaluate and potentially re-invent how the Army delivers IT services and make use of data and analytics to meet mission requirements. The CETS program provides...

  • DevSecOps engineer

    1 week ago


    Arlington, United States Zealogics Full time

    What You'll Do: - Collaborate with a team of engineers to implement  client specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications. - Work with Development, DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevOps processes. - Define the...


  • Arlington, United States Unavailable Full time

    Overview Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and...


  • Arlington, United States Systems Planning and Analysis Full time

    Overview Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in...


  • Arlington, Virginia, United States Systems Planning and Analysis Full time

    At Systems Planning and Analysis, we deliver high-impact technical solutions to complex national security challenges. Our team of experts is highly collaborative and produces results that matter.The Joint Office of the Secretary of Defense, Interagency Division provides expert support services to various customers across the Department of Defense, Federal...


  • Arlington, United States ArdentMC Full time

    Why do you need to choose between doing important work and having a fulfilling life? At Ardent, we have both. Ardent employees are committed to solving our customer's most difficult problems and we are committed to the well-being, personal goals, and professional development of our employee. We are All In. We put forth our strongest effort possible to get...


  • Arlington, Virginia, United States Bloomberg Industry Group Full time

    Bloomberg Industry Group is a leading provider of innovative solutions for the financial industry.About UsWe are committed to delivering high-quality products and services that meet the evolving needs of our clients.Job DescriptionThe estimated salary for this position is $120,000 - $180,000 per year, based on industry standards and location. This figure may...


  • Arlington, United States Glocomms Full time

    Please note that this role is Hybrid and will require 3 days per week onsiteGlocomms is partnered with a leading consumer-focused data analytics and online marketplace company that’s reshaping how millions of users engage with real estate. Security is paramount to this mission, and the organization is seeking innovative professionals to integrate security...

  • AL/ML Engineer

    4 weeks ago


    Arlington, United States Core4ce Full time

    Job Description Core4ce is looking for AI/ML Engineers to join our team supporting the CDAO effort which is responsible for the acceleration of the DoD's adoption of data, analytics, and AI to generate decision advantage from the boardroom to the battlefield. The CDAO is the lead for all AI work within the DoD. Responsibilities • Designs and develops...

  • AL/ML Engineer

    3 weeks ago


    Arlington, United States Core4ce Full time

    Job Description Core4ce is looking for AI/ML Engineers to join our team supporting the CDAO effort which is responsible for the acceleration of the DoD's adoption of data, analytics, and AI to generate decision advantage from the boardroom to the battlefield. The CDAO is the lead for all AI work within the DoD. Responsibilities • Designs and develops...


  • Arlington, Virginia, United States Three Saints Bay Full time

    Job Title: Technical Systems EngineerEstimated Salary: $145,000 - $180,000 per yearAt Three Saints Bay, LLC, we are seeking a highly skilled Technical Systems Engineer to join our team in Crystal City, VA.About the Position:As a Technical Systems Engineer, you will provide systems engineering support for design, development, production, and in-service...

  • Senior AI/ML Engineer

    4 weeks ago


    Arlington, United States Core4ce Full time

    Job Description Core4ce is looking for Senior AI/ML Engineers to join our team supporting the CDAO effort which is responsible for the acceleration of the DoD's adoption of data, analytics, and AI to generate decision advantage from the boardroom to the battlefield. The CDAO is the lead for all AI work within the DoD. Responsibilities • Designs and...

  • Senior AI/ML Engineer

    3 weeks ago


    Arlington, United States Core4ce Full time

    Job Description Core4ce is looking for Senior AI/ML Engineers to join our team supporting the CDAO effort which is responsible for the acceleration of the DoD's adoption of data, analytics, and AI to generate decision advantage from the boardroom to the battlefield. The CDAO is the lead for all AI work within the DoD. Responsibilities • Designs and...


  • Arlington, United States RMAS Full time

    Job DescriptionSr. DevOps/Cloud Solutions Engineer (Kubernetes & Helm)Location: Arlington, VA - Hybrid (2-3 Days/Week)Clearance Requirement: Active Secret We are seeking a DevOps Engineer with 10+ years of experience in Kubernetes and Helm. Familiarity in Big Bang and Crossplane is preferred. Candidates should possess a developer-first mindset, and have the...


  • Arlington, United States RMAS Full time

    Job DescriptionSr. DevOps/Cloud Solutions Engineer (Kubernetes & Helm)Location: Arlington, VA - Hybrid (2-3 Days/Week)Clearance Requirement: Active Secret We are seeking a DevOps Engineer with 10+ years of experience in Kubernetes and Helm. Familiarity in Big Bang and Crossplane is preferred. Candidates should possess a developer-first mindset, and have the...


  • Arlington, United States RMAS Full time

    Job DescriptionSr. DevOps/Cloud Solutions Engineer (Kubernetes & Helm)Location: Arlington, VA - Hybrid (2-3 Days/Week)Clearance Requirement: Active Secret We are seeking a DevOps Engineer with 10+ years of experience in Kubernetes and Helm. Familiarity in Big Bang and Crossplane is preferred. Candidates should possess a developer-first mindset, and have the...


  • Arlington, Virginia, United States IMAGINEEER LLC Full time

    Job DescriptionWe are seeking a highly skilled Software Migration Engineer to lead our team in migrating a custom-built application to a commercial off-the-shelf solution. As an IT Lead, you will be responsible for directing Agile teams, structuring migration plans, and ensuring a seamless transition to the new platform.About This Role:An active Secret...

  • Full Stack Engineer

    5 days ago


    Arlington, United States Donatech Full time

    Position would require the candidate to be a W2 employee of Donatech. US Citizenship Required. Basic Qualifications: - Minimum 3 to 5 years of Software Development experience including proficiency in full-stack web development (frontend, backend, database, APIs and other service types). - US Citizenship is required for this role - Experience in...

  • AWS cloud Engineer

    4 weeks ago


    Arlington, United States TechnoGen Full time

    Job Title: Cloud Security Engineer Location: Maryland/Arlington, VA Duration: Contract Overview- As a Cloud Security Engineer, you will work within our growing DevSecOps practice delivering features to support developing, testing, and monitoring secure cloud architectures for cloud migration, cloud optimization and cloud deployment. We are looking for...