DevSecOps Project Lead – Sr DevSecOps Engineer
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
DevSecOps Lead building and operating delivery platforms for AI-enabled programs in a government cloud environment. Leading security and operational architecture while ensuring compliance with federal requirements.
Responsibilities:
- As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization.
- This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them.
- Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit.
- As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer's security and accreditation staff.
- We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government's timeline rather than ours.
Requirements:
- 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
- 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
- Hands-on keyboard while leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
- Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
- Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
- Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
- Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
- A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
- Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
- An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
- US Citizenship Required
- Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
- Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.
Benefits:
- A fully remote, results-based environment
- Competitive salary, bonus, and equity package
- 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
- Unlimited PTO, with your manager’s approval
- Flexible work environment where you manage your work day
- 14 weeks of fully-paid parental leave


















