DevSecOps Engineer - Government

Applied Intuition•Arlington, VA
•Onsite

About The Position

Applied Intuition, Inc. is seeking a highly skilled DevSecOps Engineer to own secure code integration across their software delivery lifecycle. The DevSecOps Engineer will require a Security Clearance and will work directly with developers to ensure software is securely built, tested, packaged, and deployed into Government and customer environments, including classified and air-gapped systems. This engineer moves our pipeline from scanning to enforcement: defining promotion gates, severity thresholds, and a documented exception path, and doing it without stalling delivery. Partners with the ISSM and Cyber Security Engineer to translate NIST, DISA, and DoD security requirements into automated engineering controls and repeatable deployment workflows.

Requirements

  • A Bachelor’s degree in Computer Science, Software Engineering, Cyber Security, or a related field, or equivalent hands-on experience
  • A minimum of 5 years of experience across software engineering, DevOps, platform engineering, or security engineering
  • DoD 8140/8570 IAT level II (Security+ Certification, condition of employment)
  • Hands-on scripting or software development experience using Python, Bash, Go, or similar languages
  • Experience with CI/CD platforms such as GitLab CI, GitHub Actions, Jenkins, or equivalent tooling
  • Production experience with containers and orchestration technologies such as Docker and Kubernetes
  • Experience with infrastructure-as-code or configuration management technologies such as Terraform or Ansible, AWS CDK, or CloudFormation
  • Hands-on AWS experience, including working knowledge of Config, Security Hub, IAM, KMS, CloudTrail, and CloudWatch/EventBridge
  • Experience writing and deploying policy-as-code (OPA Rego, cfn-guard, Cedar, or equivalent)
  • Working knowledge of NIST 800-53, NIST 800-171, DISA STIGs, and RMF, and of DFARS 252.204-7012 and CMMC Level 2 obligations
  • Experience producing audit-ready evidence and working directly with third-party assessors
  • Experience introducing blocking security gates into a delivery pipeline that did not previously have them, and sustaining them under delivery pressure
  • Demonstrated ability to integrate security tooling into developer workflows and make findings actionable
  • Proven ability to work directly with developers to troubleshoot issues, teach secure practices, and unblock delivery
  • Must be a U.S. Citizen
  • Must have or be able to obtain an active DoD security clearance (minimum Secret, prefer Top Secret)

Nice To Haves

  • CISSP, CSSLP, or CKS certification, or AWS Security Specialty
  • Experience with DoD software factories such as Platform One, Iron Bank, or Big Bang
  • Experience with hardware-isolated container runtimes such as Kata Containers or gVisor
  • Experience delivering software into classified or air-gapped environments
  • Familiarity with software supply chain frameworks such as SLSA, SSDF, CycloneDX, or SPDX, and with machine-readable compliance formats such as OSCAL
  • Experience supporting a FedRAMP or DoD Impact Level 4/5 authorization
  • Experience securing AI/ML workloads or machine-generated code and container artifacts
  • Prior software development experience on a product engineering team

Responsibilities

  • Own secure code integration from source through build, test, release, and deployment
  • Directly support developers integrating and deploying software onto Government and customer systems
  • Build and maintain secure CI/CD pipelines, reusable pipeline templates, and hardened build environments
  • Integrate and tune SAST, DAST, SCA, secrets scanning, container scanning, and infrastructure-as-code scanning, and consolidate overlapping toolchains into a single supported stack
  • Define and enforce promotion gates: which findings block, which are advisory, and the severity thresholds applied. Where a finding cannot be remediated before release, record the exception with a justification, an accountable owner, and a remediation date
  • Serve as the primary technical resource for developers by troubleshooting findings, pairing on remediation, and removing delivery blockers
  • Automate system hardening, security validation, and compliance evidence collection using infrastructure-as-code and policy-as-code (OPA/Rego, cfn-guard, Cedar, or equivalent), producing machine-readable evidence that holds up in front of a third-party assessor
  • Build preventive and detective controls in AWS GovCloud, including Service Control Policies and Resource Control Policies across multi-account Organizations, Config, Security Hub, IAM, KMS, CloudTrail, and EventBridge, with automated remediation workflows
  • Implement software supply chain protections including SBOM generation, artifact signing, and secure dependency management, and admission control that rejects unsigned or unscanned images at deploy time
  • Support software promotion into classified and air-gapped environments, including offline dependencies and controlled transfer workflows, and offline package mirrors for language and native dependency managers
  • Lead threat modeling and security design reviews for new services and pipeline changes, and propose compensating controls where direct remediation is not possible
  • Partner with the ISSM and Cyber Security Engineer to map technical controls to NIST 800-53, NIST 800-171, DISA STIGs, and CMMC Level 2, and support evidence production during assessments and ATO activity
  • Establish secure development guidance, technical documentation, and repeatable engineering patterns for product teams
  • Serve as a documented backup on build, artifact, and pipeline systems, and participate in the security on-call rotation

Benefits

  • Base salary
  • Equity
  • Comprehensive health, dental, vision, life and disability insurance coverage
  • 401k retirement benefits with employer match
  • Learning and wellness stipends
  • Paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service