DevSecOps Engineer

United States - Remote

9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions.  Our specialties include cybersecurity, cloud modernization, software development, data analytics, enterprise architecture, enterprise IT, analytics, process automation, and artificial intelligence.  Learn more about 9th Way Insignia at https://9thwayinsignia.com/.

Application password: Niner

Team (Project) Introduction
The Department of Veterans Affairs (VA) Cybersecurity Operations Systems Engineering (COSE) project serves as an overarching technical engine that unifies Architecture and Engineering Services throughout the VA Enterprise. This program implements cohesive organizational security architecture and underlying engineering components that utilize national security standards, guidelines, and frameworks. COSE bridges the gap between high-level business requirements and technical structures, enabling the consistent deployment of secure technologies through implementation guidance and the establishment of an analytic library. Systems security engineering within COSE contributes a holistic perspective to the systems engineering effort, ensuring that stakeholder protection needs are addressed throughout the entire system life cycle from concept and development to production, support, and decommissioning. By drawing upon well-established systems engineering and security principles, COSE adapts and supplements practices to protect intellectual property, data, and the methods used to create VA systems. These activities improve the security posture of VA applications to prevent, deter, or detract from cyberattacks by nefarious adversaries or insider threats.

9th Way Insignia is looking for an Engineer, 3, DevSecOps Engineer to join this team.

Professional Level Information:
An Engineer, 3 typically plans and directs research or development work on complex projects, along with engaging various parties in design and development. Costs and recommendations of new components may also involve part of the job scope. Performs multiple engineering-related tasks in various assignments within the project and firm. An Engineer, 3 oversees the design, development, implementation, and analysis of technical products and systems.  An Engineer, 3 has broad knowledge of engineering procedures and assists in the resolution of complex problems.  An Engineer, 3 has strong technical skills and background, a knack for learning new technologies, and a blend of good problem-solving and innovation needed to resolve a wide variety of technical production challenges.

Functional Job (LCAT) Information:
The DevSecOps Engineer will design, implement, automate, secure, and maintain development and deployment processes supporting the VA COSE program. The engineer will integrate cybersecurity throughout the software development lifecycle and establish automated, repeatable, and secure processes for building, testing, deploying, configuring, and maintaining applications and infrastructure within enterprise and cloud environments.


Responsibilities:

  • Design, implement, maintain, and optimize DevSecOps processes and CI/CD pipelines supporting secure software development, testing, integration, deployment, and operations.
  • Integrate security controls and security gates directly into development and deployment pipelines to ensure applications and infrastructure are securely configured, tested, and deployed.
  • Automate security testing and compliance activities throughout the software development lifecycle (SDLC).
  • Develop and maintain automated deployment scripts, workflows, and configuration-management solutions that support consistent and repeatable deployment of hardened security configurations.
  • Support development and implementation of cloud-native DevSecOps solutions, including secure build, test, deployment, and operational processes within cloud environments.
  • Support secure implementation and management of containerized applications and workloads within enterprise and cloud-native environments.
  • Integrate cybersecurity tools and technologies into CI/CD pipelines and DevOps workflows to identify security issues as early as possible in the development lifecycle.
  • Implement automated mechanisms for identifying and addressing security vulnerabilities, configuration weaknesses, compliance issues, and other software security risks.
  • Perform and support security assessments and vulnerability-management activities for applications, platforms, infrastructure, and cloud environments.
  • Support cybersecurity incident-response activities involving applications, development pipelines, cloud infrastructure, software components, and related DevSecOps technologies.
  • Apply secure software-development practices throughout the development lifecycle and promote security-by-design and security-by-default principles.
  • Manage and maintain source-code repositories and version-control processes, including Git-based repositories, branching, merging, change tracking, and controlled software releases.
  • Establish processes that ensure source code, configuration scripts, deployment artifacts, and other software components are appropriately version-controlled, traceable, and reproducible.
  • Develop and maintain automation scripts supporting build, configuration, testing, deployment, security validation, compliance, and operational activities.
  • Integrate automated security checks into development workflows to support continuous security validation and continuous compliance.
  • Support development and maintenance of automated requirements traceability from foundational cybersecurity controls and architecture requirements through implementation and final Authority to Operate (ATO).
  • Collaborate with cybersecurity engineers and architects to translate security requirements into automated technical controls, pipeline checks, deployment requirements, and configuration standards.
  • Support secure engineering activities across applications, cloud platforms, networks, data environments, identity systems, and enterprise platforms.
  • Review application and platform designs to identify potential security risks, control gaps, vulnerabilities, attack paths, and configuration weaknesses before implementation.
  • Implement and maintain secure configuration baselines and automated controls supporting consistent configuration across operating systems, cloud-native platforms, applications, databases, and other enterprise technologies.
  • Automate configuration and deployment processes using approved configuration-management frameworks and infrastructure automation technologies.
  • Support continuous quality improvement by identifying opportunities to automate manual development, security, testing, deployment, and compliance processes.
  • Develop automated workflows that improve the speed, repeatability, consistency, security, and reliability of software and infrastructure delivery.
  • Support secure integration of cybersecurity tools and enterprise technologies through APIs, automation scripts, workflow orchestration, and other approved integration methods.
  • Support development and maintenance of automated cybersecurity workflows, scripts, and configurations within Government-approved repositories and platforms.
  • Assist with security tool integration and automation to reduce manual operational workload and improve enterprise cybersecurity effectiveness.
  • Support software supply-chain security by helping ensure software components, dependencies, packages, patches, and other development artifacts meet applicable security and integrity requirements.
  • Support generation, validation, or use of Software Bills of Materials (SBOMs) where required as part of software supply-chain risk management activities.
  • Ensure software and patches provided for VA environments are appropriately evaluated for malware, unauthorized modifications, and other software integrity risks.
  • Support secure software delivery practices, including applicable code signing, software integrity validation, and controlled deployment processes.
  • Develop, maintain, and deliver custom code, scripts, APIs, configuration scripts, schemas, metadata, deployment artifacts, and supporting technical documentation in accordance with applicable Government requirements.
  • Ensure custom-developed code and technical artifacts are structured and documented to support Government ownership, reuse, maintenance, testing, and future development.
  • Support cloud security engineering activities by incorporating appropriate security controls into cloud architectures, workloads, deployment pipelines, and operational processes.
  • Work closely with software developers, cybersecurity architects, cloud engineers, security engineers, system administrators, configuration-management personnel, and Government stakeholders to integrate security into development and operational processes.
  • Participate in technical design reviews, security engineering reviews, modernization initiatives, pilots, testing activities, and engineering working groups.
  • Document DevSecOps architectures, pipeline configurations, automation workflows, security controls, technical procedures, system configurations, deployment processes, and integration points.
  • Support audit and compliance activities by producing technical evidence demonstrating implementation of required security controls, configurations, testing, and automated compliance checks.
  • Assist with remediation of security and compliance findings by developing or implementing automated corrective actions and technical solutions.
  • Ensure DevSecOps activities align with applicable VA security policies, Government architecture requirements, approved development methodologies, and Federal cybersecurity requirements.
  • Support VA modernization efforts by applying DevOps, DevSecOps, automation, cloud-native, and Lean-Agile principles to continuously deliver secure and sustainable IT capabilities.
  • May require up to two onsite travel visits per year

 Requirements:

  • Minimum of 10 years of DevSecOps experience of which at least 5 years are of Cybersecurity and Cloud Security experience at a large Government agency similar in size/scope to GSA, IRS, DoD or VA. 
  • Expertise in DevSecOps or related fields, including experience with CI/CD pipelines, containerization, and cloud-native environments. 
  • Expertise in software development and familiarity with development practices, code repositories (e.g., Git), and version control. 
  • Expertise in cybersecurity roles that include performing security assessments, vulnerability management, and incident response. 
  • Expertise in integrating security tools into DevOps pipelines and automating security testing and compliance. 

Preferred/Desired:

  • Bachelor’s degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or related fields. 
  • CASP+ (SecurityX), CCISO, CISA, CISM, CISSP, CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH, GSLC, CCNP Security

Salary Range

$98,135.18 - $125,000 USD

9th Way Insignia’s range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Clearance/Background Investigation
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

Benefits
Eligible employees will have access to our comprehensive benefits package which includes Medical, Dental, Vision, Voluntary Life Insurance, 401(k), Basic Life A&D, STD, LTD, PTO, Telehealth, paid holidays, FSA, HSA. Additional resources include our Employee Assistance Program (EAP) and Traveling Assistance.

Legal
We’re an equal employment opportunity employer that empowers our people to fearlessly drive change – no matter their race, color, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, age, marital status, sexual orientation, gender identity, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, or local law.

Create a Job Alert

Interested in building your career at 9th Way Insignia? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

This is at the top of the job description.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in 9th Way Insignia’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.


We use Greenhouse’s AI-powered Talent Matching tool to compare your application against our job requirements.

Learn more