DevSecOps Engineer (TS/SCI)

Maxaar•Herndon, VA
•Onsite

About The Position

Vantor is seeking a Mid-Level DevSecOps Engineer located in Herndon, VA, to support the development, integration, and cybersecurity compliance of intelligence capabilities in Development and Production environments. This is a software engineering-focused DevSecOps role. The primary focus is designing, coding, testing, and maintaining software and automation tools that streamline Cyber Security workflows and improve the reliability of our platforms. We are looking for a candidate with a software development background who can build scalable, reliable systems and developer tools, and contribute to DevSecOps pipelines that integrate and deploy components across multiple networks into private cloud infrastructures hosted for our government customer. As a Vantor team member, you will closely support our mission partners, and your work will have direct mission impact. You will work with DevSecOps engineers, software developers, infrastructure technicians, and cybersecurity professionals to use open-source technology to create and maintain the full stack of a High-Performance Computing (HPC) system that hosts applications for thousands of users. We are a multi-faceted technical team with expertise spanning the full stack of cloud computing technologies including systems administration, DevOps, cybersecurity, software development, and systems engineering that builds and maintains software applications backed by a self-managed cloud infrastructure with a true big-data footprint (over 10 petabytes). Our diverse background of experience in mission support and technology development and operations serves as a catalyst to solve unique and challenging intelligence problems in support of special operations analysts and their on-going activities. Prototyping and frequent, iterative feedback are core to our delivery approach, anchored by a need to work quickly in support of our missions.

Requirements

  • Must have an active TS/SCI clearance and be willing and able to pass a CI polygraph.
  • Must be able and willing to work 40 hours per week in a SCIF in Herndon, Virginia.
  • At least 3 years of industry experience in software development or software engineering.
  • At least 5 years of industry experience in DevSecOps, with a bachelor’s degree in Computer Science, Information Systems, or a related field; or a master’s degree and at least 3 years of relevant experience.
  • Demonstrated professional software development experience is required.
  • Candidates must be able to design, write, test, debug, and maintain software using at least one language such as Python, Go, Java, C#, or similar.
  • Experience building automation tools, APIs, or applications is central to this role.
  • Strong expertise in cloud environments, including deployment, optimization, and troubleshooting.
  • Proven track record in building and operating Cloud Native Applications using tools like Kubernetes and Docker.
  • In-depth experience with IaC tools such as Terraform, Ansible, or equivalent.
  • Solid experience in creating and managing CI/CD build pipelines using GitLab or similar tools (e.g., Jenkins, Azure DevOps).
  • Strong software automation skills using Python, Bash, or equivalent languages; Python or comparable application development experience is required.
  • Excellent problem-solving skills with attention to detail and the ability to thrive in a fast-paced environment.
  • Experience applying security best practices in DevSecOps pipelines (e.g., Trivy, Grype, GitLab SAST, or SonarQube).
  • Familiarity with monitoring tools like Prometheus, Grafana, or ELK Stack.
  • Strong knowledge of networking and load balancing technologies.
  • Experience with source control tools such as Git, including collaborative development workflows.
  • Experience with automated deployment technologies such as Cloud Formation, Ansible, Puppet or Chef.
  • Experience deploying and maintaining open-source and custom applications.
  • Moderate Linux system administration experience (Red Hat, Rocky Linux, AlmaLinux, or similar).
  • Working knowledge of Linux and Windows operating systems, web services, and SQL databases.
  • Experience working in an Agile environment.

Nice To Haves

  • Security+ or comparable certification for privileged user access.
  • Experience with distributed processing methods and tools, such as REST APIs, microservices, IaaS/PaaS services.
  • Experience developing and deploying web services.
  • Experience in implementing Docker STIGs
  • Experience with CONMON cybersecurity remediation.
  • RHCSA/LPIC 1/2, CKA, or Docker Certified Associate certification.

Responsibilities

  • Build and maintain custom command-line tools, APIs, and dashboards that reduce manual effort and streamline Cyber Security and developer workflows.
  • Design, write, test, and maintain clean, production-quality code (e.g., Python, Go, Java, or similar) to automate Cyber Security workflows.
  • Convert manual Cyber Security, compliance, infrastructure, and developer workflows into automated, repeatable software workflows.
  • Build automation for security analysis, vulnerability correlation, compliance tracking, remediation workflows, and security exception processes.
  • Develop custom dashboards and reporting applications that aggregate data from multiple systems and provides actionable visibility into security, compliance, infrastructure, and software delivery.
  • Participate in code reviews.
  • Troubleshoot complex application and automation failures by analyzing source code, logs, APIs, infrastructure, and system behavior.
  • Deploy and manage highly available applications to ensure system reliability and scalability.
  • Implement and maintain HashiCorp Nomad and Kubernetes clusters for workload orchestration.
  • Execute DNS configuration, management, and performance tuning for enterprise-grade systems.
  • Develop and implement Infrastructure-as-Code (IaC) solutions using tools like Terraform, Ansible, or similar.
  • Build and manage multiple CI/CD pipelines with GitLab or equivalent tools to automate deployments and streamline development workflows for rapid development and integration.
  • Perform system monitoring, logging, and troubleshooting to proactively identify and resolve issues.
  • Automate security testing and monitoring within the DevOps workflows using ACAS and Trivy.
  • Analyze cybersecurity scan findings and work with the cybersecurity team to identify false positives.
  • Assist the cybersecurity team in assembling the required Body of Evidence for False Positive exceptions.
  • Assist the cybersecurity team in assembling the required Body of Evidence to submit containerized and non-containerized software packages for enterprise software approval.
  • Integrate static code analysis tools such as GitLab SAST, Fortify, or SonarQube and other security mechanisms into CI/CD pipelines.
  • Build and maintain software tools that automate cybersecurity analysis and correlation workflows as compliance requirements evolve.
  • Perform cybersecurity remediation on DevSecOps-managed virtual machines, including OS patching, OS STIG implementation, and software package updates.
  • Build, maintain, and monitor configuration management of release products.
  • Troubleshoot and resolve issues in networks, automation pipelines, and infrastructure.

Benefits

  • robust 401(k) with company match
  • mental health resources
  • student loan repayment assistance
  • adoption reimbursement
  • pet insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service