Seniour DevSecOps Engineer
2 weeks ago
Senior DevSecOps Engineer
PSDC - TAS1 A4 SC3
Commonwealth of PA/OA (PSDC) requires the services of a TAS1 A4 SC3 to act as a Senior DevSecOps Engineer.
Work Location: Hybrid with two days onsite (1920 Technology Parkway, Mechanicsburg, PA Schedule can be discussed during interview.
Work hours: 8AM to 5PM (hourlong lunch)
Start date can be ID'd upon after compliant PATCH and PSDC-related clearance has been processed and approved.
This req is available to candidates nationwide, but candidate must be ready to relocate for this hybrid position (60% remote vs. 40% onsite). Candidate must go onsite on their first day to pick up commonwealth-issued equipment, badging, etc.. Role contingent on compliant PATCH and passing PSDC/CJIS background checks.
PSDC (Public Safety Delivery Center) requires the services of a Senior DevSecOps Engineer to act as consultant with the PSDC Solutions Management group.
Role summary
Hands-on security automation for AWS delivery. Build secure-by-default CDK constructs and CloudFormation templates, wire them into CI/CD, and enforce compliance checks that map to CJIS and NIST. Azure support is a future consideration, not a core day-one duty.
Scope boundaries
Does not own enterprise AWS Organizations or SCP operations.
Designs and builds reference guardrails and enforcement patterns that can be deployed by enterprise teams.
Focuses on preventive controls and compliance automation, not incident response.
What you will deliver
First 90 days
Pipeline security templates in GitHub Actions and Azure DevOps with SAST, SCA, IaC, container, and secret scanning gates.
Compliance as code in reference accounts: AWS Config rules and Security Hub standards aligned to CJIS and NIST 800-53, with exceptions workflow documented.
IaC reference modules using AWS CDK and CloudFormation for IAM least privilege, KMS, Secrets Manager, logging, and network baselines; Terraform equivalents provided where teams require them.
Evidence exports tying checks to control IDs and producing auditor-ready artifacts.
Ongoing
Harden CDK/CFT modules and pipeline templates as compliance needs evolve.
Coach pilot teams to adopt templates.
Raise gaps to enterprise teams for org-level enforcement.
Day-to-day responsibilities
Author and maintain AWS CDK constructs and CloudFormation templates; provide Terraform versions as secondary.
Implement AWS Config conformance, Security Hub standards, and GuardDuty routing in reference accounts.
Wire scanning in CI/CD for app code, containers, and IaC.
Create reusable GitHub/Azure DevOps templates with enforcement gates and exception handling.
Generate posture and evidence reports mapped to CJIS and NIST controls.
Required skills
5+ years AWS security automation and DevOps.
Strong with AWS CDK and CloudFormation; working proficiency in Terraform.
CI/CD authoring in GitHub Actions and Azure DevOps.
Proficient in Python and Bash, with PowerShell for Windows automation.
Able to read Java and C# to integrate and tune SAST/SCA.
Practical knowledge of CJIS and NIST control families and how to automate checks and evidence.
Nice to have
EKS/ECS/Lambda hardening patterns.
OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent.
Basic Azure security automation for future phases.
Decision rights
Independent on design and build within standards; proposes guardrails and reference patterns; escalates enterprise-wide changes.
Skills Table:
Skill
Required / Desired Amount of Experience
5+ years AWS security automation and DevOps
Required
5 Years
Strong with AWS CDK and CloudFormation; working proficiency in Terraform
Required
CI/CD authoring in GitHub Actions and Azure DevOps
Required
Proficient in Python and Bash, with PowerShell for Windows automation
Required
Able to read Java and C# to integrate and tune SAST/SCA
Required
Practical knowledge of CJIS and NIST control families and how to automate checks and evidence
Required
EKS/ECS/Lambda hardening patterns
Nice to have
OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent
Nice to have
Basic Azure security automation for future phases
Nice to have
Background Check: This position requires an in-depth background check, including fingerprinting, and requires successful results. Do you accept this requirement?
Where does your candidate currently reside?
Resume wise, please do not include filler material (e.g. describing a company's core capabilities/description). Please only include relevant info (e.g. what was done at the job/project). Is this reflected in the resume?
The skills (and applicable experience) must also be explicitly referenced in the candidate resume. Have you confirmed that the responses to the skills above are accurate and reflect the actual experience the candidate possesses?
-
Director of Engineering
2 days ago
Atlanta, Georgia, United States Tropical Smoothie Cafe Full time $175,000 - $250,000 per yearSUMMARYWe're seeking a curious, future‑focused Director of Engineering to mature and scale our engineering practices and platforms spanning mobile, web, kiosks, POS, KDS, loyalty, marketing tech, data, and analytics. This leader will set a bold engineering vision, lead high‑performing teams (including strategic partners), and deliver reliable, secure,...
-
vp - om (0972)
19 minutes ago
Atlanta, Georgia, United States Corpay Full time $120,000 - $250,000 per yearJob SummaryWe are seeking an experienced and visionary Vice President (VP) of Engineering to lead and oversee the company's innovation of delivering to the markets quicker. This executive will be responsible for driving innovation, enhancing engineering excellence, and ensuring the integration of robust security practices within the software development...
-
Senior Software Engineer
4 days ago
Atlanta, Georgia, United States Mastercard Full time $115,000 - $184,000 per yearOur PurposeMastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships...
-
Principal Software Engineer
15 hours ago
Atlanta, Georgia, United States TriNet Full time $140,600 - $309,200TriNet is a leading provider of comprehensive human resources solutions for small to midsize businesses (SMBs). We enhance business productivity by enabling our clients to outsource their HR function to one strategic partner and allowing them to focus on operating and growing their core businesses. Our full-service HR solutions include features such as...
-
Senior Software Development Engineer, Crew
3 hours ago
Atlanta, Georgia, United States Delta Air Lines Full time $120,000 - $200,000 per yearHow You'll Help Us Keep Climbing (Overview & Key Responsibilities)Sr. Software Development Engineer will be joining the Crew IT team and contributing to the software design, software development, and overall product lifecycle. The Software Development Engineer is responsible for development, operations and support, and enhancements of Delta's Crew Operations...
-
Lead Application Security Engineer
5 days ago
Atlanta, Georgia, United States Cox Enterprises Full time $100,000 - $200,000 per yearCompanyCox Automotive - USA Job Family GroupInformation Technology Job ProfileCybersecurity Lead Engineer Management LevelManager - Non People Leader Flexible Work Option Hybrid - Ability to work remotely part of the week Travel %Yes, 5% of the time Work ShiftDayCompensationCompensation includes a base salary of $119, $199, The...
-
Staff Cloud Security Engineer
5 days ago
Atlanta, Georgia, United States Warner Bros. Discovery Full time $115,000 - $215,020 per yearWelcome to Warner Bros. Discovery… the stuff dreams are made of.Who We Are…When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are thestorytellersbringing our characters to life,...
-
Secure Computing Engineer
2 days ago
Atlanta, Georgia, United States Georgia Tech Research Institute Full time $80,000 - $140,000 per yearOverviewThe Georgia Tech Research Institute (GTRI) is the nonprofit, applied research division of the Georgia Institute of Technology (Georgia Tech). Founded in 1934 as the Engineering Experiment Station, GTRI has grown to more than 2,900 employees, supporting eight laboratories in over 20 locations around the country and performing more than $940 million...
-
Azure Architect
5 days ago
Atlanta, Georgia, United States Capgemini Full time $104,000 - $160,000 per yearAbout Capgemini A global leader in consulting, technology services and digital transformation, Capgemini is at the forefront of innovation address the entire breadth of clients' opportunities in the evolving world of cloud, digital and platforms. Building on its strong 50-year heritage and deep industry-specific expertise, Capgemini enables organizations...
-
Cortex Cloud Sales Specialist
4 days ago
Atlanta, Georgia, United States Palo Alto Networks Full time $264,000 - $363,000Company Description Our MissionAt Palo Alto Networks everything starts and ends with our mission:Being the cybersecurity partner of choice, protecting our digital way of life.Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and...