Haystack
← Back to Jobs
Engineering

DevSecOps Engineer

Satsyil CorporationTysons, VA🇺🇸United StatesPosted 7 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

2. DevSecOps Engineer — Key Personnel

Labor Category:  DevSecOps Engineer

Clearance:  U.S. Citizen with active SECRET clearance (required).

Position Summary

Design, automate, and secure the CI/CD pipelines, cloud infrastructure, and RMF compliance for a FedRAMP High / DoD Impact Level 5 (IL5) data and analytics platform. Embeds security automation across the DevOps lifecycle under an ''Automation-First'' mandate.

A. Minimum Qualifications (resume must demonstrate)

       Five (5) years in DevSecOps: designing, implementing, and maintaining CI/CD pipelines and automating deployment (Jenkins, GitLab CI/CD, Ansible).

       Five (5) years supporting the RMF process for DoD/federal systems: applying DISA STIGs, vulnerability assessments, and patching/remediation.

       Five (5) years automating cloud infrastructure/platform provisioning (AWS, Azure) using Infrastructure as Code (Terraform, CloudFormation).

       Experience integrating security automation, vulnerability scanning (Nessus, OpenSCAP), and monitoring/logging (Splunk, ELK) into the DevOps lifecycle.

       Verifiable experience with containerization/orchestration (Docker, Kubernetes) in a microservices architecture.

       Verifiable experience integrating automated security testing (SAST and DAST) directly into the CI/CD pipeline.

B. On-Contract Responsibilities (from PWS Task Areas)

       Automate infrastructure and workflows using IaC (Terraform, Ansible); build and manage CI/CD pipelines for secure deployment; develop streaming data pipelines (Apache Kafka, AWS Kinesis) for real-time processing.

       Deliver all activities and evidence to achieve and maintain a full Authority to Operate (ATO) under RMF — System Security Plan, Security Assessment Report, POA&M — and support control assessments and continuous monitoring.

       Implement Compliance-as-Code: automate DISA STIG application/verification across all infrastructure layers; auto-generate RMF artifacts (PPSM, topology diagrams) from IaC repos so eMASS reflects the true environment; integrate zero-touch automated vulnerability scanning into CI/CD.

       Operate within a FedRAMP High / DoD IL5 cloud (AWS GovCloud, Azure Government), ensuring all AI/ML processing stays inside the accredited boundary (no CUI to public commercial AI endpoints).

       Use IaC to dynamically provision/de-provision GPU-accelerated compute clusters to control costs, supporting the MLOps lifecycle.

       Perform continuous security compliance for baseline components — software patching and STIG/vulnerability remediation — with zero degradation to legacy capabilities during modernization.

 

 

Similar jobs