DevSecOps Engineer Role

OpenDataJobsWashington, DC

About The Position

DevSecOps Engineers make secure delivery repeatable. They design the CI/CD paths, deployment controls, and operational feedback loops that carry software from a change in source code to a running service. In federal environments, that work also includes assembling and maintaining security evidence for an Authority to Operate (ATO), the formal decision to allow a system to operate at an accepted level of risk. The role works across development, operations, and security. DevSecOps Engineers automate build, test, deployment, configuration, vulnerability management, logging, and recovery practices so teams can release with visible controls and usable evidence. They partner with Cloud Infrastructure Engineers who provide the underlying platform, while they own the delivery path and its security integration.

Requirements

  • Hands-on experience with source control, automated testing, CI/CD, and deployment automation.
  • Infrastructure-as-code experience with tools such as Terraform, Amazon Web Services CloudFormation, or comparable platforms.
  • Working knowledge of container security, software supply-chain controls, and vulnerability remediation.
  • Experience with logging, monitoring, incident response, and recovery practices.
  • Ability to translate National Institute of Standards and Technology (NIST) Special Publication 800-53 control expectations into engineering work and evidence.

Nice To Haves

  • Experience supporting an ATO.
  • Experience working with the Risk Management Framework.
  • Experience with a specific cloud, orchestration platform, programming language, or delivery toolchain.
  • Demonstrated work with on-call operations, incident response, security assessments, or regulated release controls.

Responsibilities

  • Design CI/CD paths, deployment controls, and operational feedback loops.
  • Assemble and maintain security evidence for an Authority to Operate (ATO).
  • Automate build, test, deployment, configuration, vulnerability management, logging, and recovery practices.
  • Partner with Cloud Infrastructure Engineers.
  • Own the delivery path and its security integration.
  • Build CI/CD pipelines that run tests, security checks, approvals, and deployments consistently.
  • Build Infrastructure-as-code modules and deployment patterns that are versioned and reviewable.
  • Build container build, image-scanning, and release processes for application workloads.
  • Build observability and vulnerability-management workflows that turn operating signals into action.
  • Build control evidence and traceability that support authorization, assessment, and continuous monitoring.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service