DevSecOps Engineer III

NoblisReston, VA
6h

About The Position

Noblis is seeking a highly skilled and motivated Senior DevSecOps Engineer with an active Top Secret/SCI with Polygraph clearance to join our security team. You will be responsible for integrating security seamlessly into our software development life cycle (SDLC), driving the "shift-left" security approach, and ensuring our cloud-native applications are secure by design. This hands-on role involves building secure CI/CD pipelines, automating security controls, managing Kubernetes security, and mentoring junior engineers.

Requirements

  • Active Top Secret SCI (TS/SCI) with Polygraph
  • U.S. Citizenship is required.
  • Bachelor’s degree in Computer Science, Information Security, or related technical field.
  • 7+ years of experience in DevOps, SRE, or Platform Engineering, with at least 3 years focused on DevSecOps and cloud-native security.
  • Deep hands-on experience securing AWS or Azure environments (IAM, KMS, Networking, logging).
  • Proficiency in building CI/CD pipelines (GitLab) and automating tasks with Python, Bash.
  • Strong expertise in Docker and Kubernetes/EKS security.
  • Hands-on experience with security scanning tools.

Nice To Haves

  • Certified Information Systems Security Professional (CISSP), AWS Certified DevOps Engineer – Professional, Certified Kubernetes Security Specialist (CKS), or CCSP.
  • Experience with OPA/Gatekeeper or Kyverno.
  • Knowledge of SBOM generation, artifact signing (cosign), and provenance concepts.
  • Familiarity with NIST SP 800-171 or CMMC expectations.
  • Strong analytical skills to diagnose complex security issues spanning multiple technologies.
  • Ability to distill technical complexities into actionable guidance for development teams.
  • Passion for automating everything and a mindset of continuous improvement.

Responsibilities

  • Design, build, and maintain automated CI/CD pipelines (GitLab CI/CD, GitHub Actions) that incorporate security testing tools at every stage.
  • Develop and manage infrastructure using Terraform or CloudFormation, implementing security guardrails and scanning to ensure compliance and prevent misconfigurations.
  • Implement security best practices for Docker, Kubernetes, and EKS, including image hardening, admission controls, policy-as-code and runtime security.
  • Partner with teams to design and enforce AWS/Azure security guardrails, including IAM least-privilege, network controls, and encryption standards.
  • Operationalize vulnerability management by identifying, prioritizing, and remediating security threats across applications and infrastructure.
  • Translate security compliance requirements into automated security controls and audit-ready evidence.
  • Act as a security champion, mentoring junior engineers and developers on secure coding practices and DevSecOps principles.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service