Nationwide IT Services, NIS, is seeking a DevSecOps Engineer for a potential opportunity. In this position, the Engineer will: Design and manage fully automated pipelines using AWS CodeCommit, CodeBuild, and CodePipeline. Integrate automated security scanning tools (SAST/DAST) directly into the build process. If the code fails a SonarQube scan or has a high-severity CVE, the pipeline must break. Secure the supply chain by managing immutable Docker images in Amazon ECR, ensuring only signed and scanned images are deployed. Manage serverless container deployments on ECS Fargate. Provision all AWS GovCloud resources using Terraform or CloudFormation. Build and maintain hardened base images that are pre-patched and STIG-compliant. Secure Amazon Redshift clusters handling sensitive government data. You will implement Column-Level Access Control, ensure strict encryption at rest (KMS) and in transit, and manage VPI/Security Group ingress rules. Configure CloudTrail and Redshift Audit Logging to capture every query run against the data warehouse for compliance audits. Aggregate logs from CloudWatch, GuardDuty, and Security Hub to provide a real-time "single pane of glass" view of the system's security posture. Primary Objectives: Assist in the Discovery Phase activities of gathering user requirements, business analysis, legacy system analysis, Epic/Story creation, external data integration planning, and product backlog management.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Career Level
Mid Level
Number of Employees
101-250 employees