Role Description
NetImpact Strategies is seeking a DevSecOps Engineer to support secure cloud infrastructure and applications within a Department of Defense environment. This hands-on role combines DevSecOps engineering with cybersecurity and Risk Management Framework support.
The ideal candidate will have experience with cloud platforms, Kubernetes, CI/CD pipelines, Linux administration, infrastructure automation, vulnerability remediation, and RMF/ATO documentation. This individual will partner with engineering and cybersecurity teams to implement secure solutions and produce the technical evidence required to obtain and maintain an Authorization to Operate.
-
Design, deploy, maintain, and troubleshoot secure cloud infrastructure and applications across development, testing, and production environments.
-
Administer Docker and Kubernetes environments, including deployments, networking, configuration, storage, scaling, and upgrades.
-
Develop and maintain CI/CD pipelines that automate application builds, testing, security scanning, and deployment.
-
Implement Infrastructure as Code using Terraform, CloudFormation, Ansible, or comparable technologies.
-
Administer Linux systems and troubleshoot issues across applications, containers, networks, operating systems, and cloud services.
-
Implement monitoring, logging, alerting, backup, recovery, and operational automation capabilities.
-
Apply security baselines, DISA STIGs, patching requirements, least-privilege access, and secure configuration practices.
-
Identify, prioritize, remediate, and document vulnerabilities and security findings.
-
Support DoD RMF and ATO activities by developing and maintaining SSPs, POA&Ms, architecture diagrams, inventories, data flows, PPSM documentation, and remediation evidence.
-
Work with ISSOs, ISSMs, engineers, developers, and assessors to document NIST SP 800-53 control implementations and maintain accurate authorization packages.
Qualifications
-
Bachelorβs degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.
-
Four or more years of experience in DevOps, DevSecOps, cloud engineering, systems engineering, or a related discipline.
-
Hands-on experience with Linux, Docker, Kubernetes, Git, and AWS, Microsoft Azure, or another major cloud platform.
-
Experience developing CI/CD pipelines and implementing Infrastructure as Code using Terraform, CloudFormation, or comparable tools.
-
Knowledge of cloud networking, identity and access management, secrets management, encryption, monitoring, vulnerability management, patching, and system hardening.
-
Familiarity with DoD RMF, the ATO lifecycle, NIST SP 800-53, DISA STIGs, security-control documentation, and POA&Ms.
-
Strong troubleshooting, technical-writing, communication, and collaboration skills.
Requirements
-
Must be a U.S. citizen.
-
Must be eligible to obtain and maintain the required U.S. Government security clearance and/or suitability determination.
-
Must meet applicable DoD 8140 cybersecurity workforce qualification requirements.
Benefits
-
Your health comes first β we offer comprehensive medical, dental, & vision insurance that starts the first of the month after you join the team.
-
Invest in your future β 401(k) Plan β Immediately vested employer contributions; no matching required.
-
Work hard, play hard β we offer a generous Paid Time Off (PTO) policy, one (1) additional day of paid wellness leave per calendar year, and observe ten (10) federal holidays.
-
Pawsitively pawesome β Pet Insurance (because our little critters are part of our families, too!).
-
Invest in your education β Tuition reimbursement, internal training programs, & company-sponsored industry certifications!
-
Be part of a dynamic and collaborative work environment recently ranked by The Washington Post as a Top Work Place in 2019, 2021, 2022, 2023, & 2024!
-
Have fun and celebrate and give back β Team building activities, community volunteering, quarterly HQ days, wellness events, happy hours, family fun events, and more!