Haystack
← Back to Jobs
Employee
Administrative

Cloud DevSecOps Engineer with Security Clearance

Stratias LLCScott AFB, IL🇺🇸United StatesPosted 23 Jul 2026

Quick Overview

Work Type
Hybrid
Schedule
Employee
Level
Mid Senior

Job Description

About Stratias
Stratias is a mission-focused digital transformation firm that helps the Department of Defense modernize critical systems at speed and scale. We specialize in program modernization through application rationalization, code refactoring, cloud migration, data pipelining, and SaaS integration. Our teams combine Agile delivery, DevSecOps practices, and deep mission expertise to drive results for the Air Force and across the defense enterprise. Why Join Us
At Stratias, you won’t be a small cog in a massive machine—you’ll be a core part of a fast-growing team that’s helping shape the future of defense IT. We hire subject-matter experts who understand both the technology and the mission. You’ll get the freedom to innovate, the support of a collaborative team, and benefits designed for real work-life balance. About this Role
The Cloud DevSecOps Engineer will support the U.S. Transportation Command's Joint Transportation Management System (JTMS) Program Management Office, a major DoD ERP modernization effort fielding and sustaining commercial logistics and transportation software across the Joint Deployment and Distribution Enterprise. The ideal candidate brings 5+ years of experience building and securing CI/CD pipelines with hands-on AWS and Kubernetes expertise. This role embeds security scanning, container orchestration, and DevSecOps best practices directly into JTMS's development and deployment lifecycle. Candidates must possess an active Secret Clearance. Responsibilities: CI/CD Pipeline Development & Management:
Design, build, and maintain automated CI/CD pipelines using GitLab CI/CD
Implement automated build, test, deployment, and rollback processes with quality gates and approval workflows
Optimize pipeline performance and reliability Security Integration & Automation:
Embed security scanning tools into CI/CD pipelines (SAST, DAST, SCA, container scanning)
Implement and maintain security tools (SonarQube, Fortify, OWASP)
Monitor and remediate vulnerabilities in code, dependencies, and infrastructure Container & Orchestration Management:
Build and secure container images following best practices
Develop and maintain Kubernetes manifests, operators, and security policies (network policies, RBAC)
Implement security monitoring, logging, and alerting solutions (Splunk, ELK Stack, Prometheus/Grafana)
Develop automated incident response workflows and security/pipeline dashboards Collaboration & Enablement:
Partner with development teams on secure coding practices and vulnerability remediation
Provide DevSecOps training and guidance on tools, practices, and security requirements
Collaborate with Security, Operations, and Architecture teams on security initiatives
Participate in security-focused code reviews Qualifications Required: Education and Clearance requirements:
5 years of experience in related field
Bachelor’s Degree or equivalent experience
Secret Clearance
Security+ Certification Experience & Core Skills:
3-5 years in software development, DevOps, or security engineering
2+ years implementing and managing production CI/CD pipelines
Understanding of SDLC and agile methodologies
Proficiency in programming/scripting languages (Python, Go, Java, JavaScript, Bash)
Experience with Git version control and branching strategies Technical Skills – DevOps:
Hands-on experience with GitLab CI/CD
Proficiency with Infrastructure as Code tools (Terraform, Ansible, CloudFormation)
Experience with container technologies (Docker, Kubernetes, OpenShift)
Familiarity with artifact repositories (Artifactory, Nexus, Docker Registry) Technical Skills – Security:
Experience with application security testing tools (SAST, DAST, SCA, IAST)
Knowledge of container/Kubernetes security best practices and frameworks (OWASP, NIST) Technical Skills - Cloud & Infrastructure:
Expert knowledge of AWS platforms and security services (EC2, CloudWatch, CloudTrail, S3, IAM, EKS, WAF & Shield, ECS)
Understanding of cloud-native services, serverless architecture, and networking (VPC, subnets, firewalls, load balancers, service mesh)
Knowledge of identity and access management (IAM, RBAC, SSO, SAML) Soft Skills:
Strong problem-solving and communication abilities
Collaborative across development, security, and operations teams
Self-motivated with ability to manage multiple priorities
Security-first mindset with pragmatic risk management approach Desired: Security certifications (CISSP, CEH, GIAC, CSSLP)
AWS Cloud certifications
DevOps/Container certifications (CKA, CKAD, CKS, Docker Certified Associate)

Skills

Agile

Similar jobs