Summary
NetImpact Strategies Inc. is a digital transformation and technology services provider supporting the Federal Government. The company is seeking a DevSecOps Engineer to secure cloud infrastructure and applications in a Department of Defense environment. The role focuses on DevSecOps engineering, cybersecurity, vulnerability remediation, and Risk Management Framework (RMF) and Authorization to Operate (ATO) documentation.
Responsibilities
- Design, deploy, maintain, and troubleshoot secure cloud infrastructure and applications across development, testing, and production environments
- Administer Docker and Kubernetes environments, including deployments, networking, configuration, storage, scaling, and upgrades
- Develop and maintain CI/CD pipelines that automate application builds, testing, security scanning, and deployment
- Implement Infrastructure as Code using Terraform, CloudFormation, Ansible, or comparable technologies
- Administer Linux systems and troubleshoot issues across applications, containers, networks, operating systems, and cloud services
- Implement monitoring, logging, alerting, backup, recovery, and operational automation capabilities
- Apply security baselines, DISA STIGs, patching requirements, least-privilege access, and secure configuration practices
- Identify, prioritize, remediate, and document vulnerabilities and security findings
- Support DoD RMF and ATO activities by developing and maintaining SSPs, POA&Ms, architecture diagrams, inventories, data flows, PPSM documentation, and remediation evidence
- Work with ISSOs, ISSMs, engineers, developers, and assessors to document NIST SP 800-53 control implementations and maintain accurate authorization packages
Skills
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field
- Four or more years of experience in DevOps, DevSecOps, cloud engineering, systems engineering, or a related discipline
- Hands-on experience with Linux, Docker, Kubernetes, Git, and AWS, Microsoft Azure, or another major cloud platform
- Experience developing CI/CD pipelines and implementing Infrastructure as Code using Terraform, CloudFormation, or comparable tools
- Knowledge of cloud networking, identity and access management, secrets management, encryption, monitoring, vulnerability management, patching, and system hardening
- Familiarity with DoD RMF, the ATO lifecycle, NIST SP 800-53, DISA STIGs, security-control documentation, and POA&Ms
- Strong troubleshooting, technical-writing, communication, and collaboration skills
- Must be a U.S. citizen
- Must be eligible to obtain and maintain the required U.S. Government security clearance and/or suitability determination
- Must meet applicable DoD 8140 cybersecurity workforce qualification requirements
- Experience supporting DoD or other federal information systems, including eMASS and RMF/ATO documentation
- Experience with AWS GovCloud and Kubernetes platforms such as EKS, AKS, Rancher/RKE2, or Red Hat OpenShift
- Experience with security and compliance tools such as Fortify, SonarQube, Snyk, Trivy, Nessus, ACAS, AWS Inspector, or SCAP
- Security+, CISSP, SecurityX, AWS, Azure, CKA, CKS, or another relevant certification
Qualifications
Must Haves
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field
- Four or more years of experience in DevOps, DevSecOps, cloud engineering, systems engineering, or a related discipline
- Hands-on experience with Linux, Docker, Kubernetes, Git, and AWS, Microsoft Azure, or another major cloud platform
- Experience developing CI/CD pipelines and implementing Infrastructure as Code using Terraform, CloudFormation, or comparable tools
- Knowledge of cloud networking, identity and access management, secrets management, encryption, monitoring, vulnerability management, patching, and system hardening
- Familiarity with DoD RMF, the ATO lifecycle, NIST SP 800-53, DISA STIGs, security-control documentation, and POA&Ms
- Strong troubleshooting, technical-writing, communication, and collaboration skills
- Must be a U.S. citizen
- Must be eligible to obtain and maintain the required U.S. Government security clearance and/or suitability determination
- Must meet applicable DoD 8140 cybersecurity workforce qualification requirements
Nice to Haves
- Experience supporting DoD or other federal information systems, including eMASS and RMF/ATO documentation
- Experience with AWS GovCloud and Kubernetes platforms such as EKS, AKS, Rancher/RKE2, or Red Hat OpenShift
- Experience with security and compliance tools such as Fortify, SonarQube, Snyk, Trivy, Nessus, ACAS, AWS Inspector, or SCAP
- Security+, CISSP, SecurityX, AWS, Azure, CKA, CKS, or another relevant certification
Benefits
- Comprehensive medical, dental, & vision insurance that starts the first of the month after you join the team
- 401(k) Plan – Immediately vested employer contributions; no matching required
- Generous Paid Time Off (PTO) policy
- One (1) additional day of paid wellness leave per calendar year
- Ten (10) federal holidays
- Pet Insurance
- Tuition reimbursement
- Internal training programs
- Company-sponsored industry certifications
- Team building activities
- Community volunteering
- Quarterly HQ days
- Wellness events
- Happy hours
- Family fun events