Back to jobs
New

DevSecOps Project Lead (Sr DevSecOps Engineer)

Remote, USA

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.
In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role 

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer's security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government's timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities 

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program's first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer's cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer's security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer's network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications 

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard while leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like 

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer's assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer: 

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

 

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability. 

Applicant Data Disclosure   
By submitting an application, you acknowledge that Defcon AI uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, "Hiring Platforms"). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:  
  • Managing and administering your application throughout the hiring process; 
  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases; 
  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories. 
Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact recruiting@defconai.com.  
 
Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI's data retention policies.
For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.  

 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in DEFCON AI’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.