Government and Infrastructure - Cybersecurity - DevSecOps Engineer

EY•McLean, VA
•$82,500 - $154,600•Hybrid

About The Position

Our cybersecurity professionals possess diverse industry knowledge, along with unique technical expertise and specialized skills. The team works together in planning, pursuing, delivering and managing engagements to assess, improve, build, and in some cases operate integrated security operations for our clients. We will support you with career-long training and coaching to develop your skills. As EY is a global leading service provider in this space, you will be working with the best of the best in a collaborative environment. So, whenever you join, however long you stay, the exceptional EY experience lasts a lifetime. The DevSecOps Engineer assesses the delivery and security maturity of each application in the portfolio and builds the secure pipelines, controls and automated evidence that the modernization factory runs on. This role ensures that security is built into how software is delivered — not added afterwards — and that rationalization recommendations reflect each application's true security posture and delivery risk.

Requirements

  • Bachelor's degree in computer science, software engineering, information systems, computer engineering or a related field, or equivalent practical experience
  • 2+ years of experience in DevOps, software engineering or security engineering
  • Hands-on CI/CD pipeline engineering with Jenkins, GitHub Actions, GitLab CI or Azure DevOps.
  • Experience with at least one application security scanning tool (for example, Fortify, Checkmarx, SonarQube, Snyk, Trivy or OWASP ZAP).
  • Working knowledge of containers and Infrastructure-as-Code.
  • Scripting in Python, PowerShell or Bash.
  • Understanding of the NIST Risk Management Framework, NIST SP 800-53 and secure software development lifecycle practices.
  • Must be able to obtain and maintain a secret level clearance
  • Must be comfortable with working in-person as needed in the Washington, DC area

Nice To Haves

  • Convey complex technical security concepts to technical and non-technical audiences including executives.
  • Experience with Design, building and maintaining secure CI/CD pipelines for the modernization factory with integrated static and dynamic application security testing (SAST/DAST), software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection and quality gates.
  • Experience supporting continuous ATO or FedRAMP authorizations and managing POA&Ms.
  • Kubernetes security and policy engines (OPA/Gatekeeper, Azure Policy).
  • SBOM tooling and standards (CycloneDX, SPDX).
  • Certifications such as CompTIA Security+, CISSP, CCSP, Certified Kubernetes Security Specialist (CKS) or relevant GIAC certifications.

Responsibilities

  • Assess each application's delivery toolchain and practices — source control, build and release automation (for example, Jenkins and Bitbucket), artifact management (Artifactory), code quality (SonarQube), Infrastructure-as-Code and configuration management (Terraform, Ansible) and monitoring (Datadog) — and identify manual release processes and gaps.
  • Assess application security posture as an input to rationalization, including open vulnerabilities, outdated or vulnerable dependencies, software bill of materials (SBOM) availability, secrets handling, authentication patterns and open plans of action and milestones (POA&Ms).
  • Design, build and maintain secure CI/CD pipelines for the modernization factory with integrated static and dynamic application security testing (SAST/DAST), software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection and quality gates.
  • Implement policy-as-code and automated evidence collection that support continuous Authorization to Operate (cATO) and NIST SP 800-53 control traceability.
  • Harden container images and environments against applicable security configuration benchmarks (DISA STIGs or CIS Benchmarks).
  • Integrate governance gates for AI-assisted development, including provenance, human review and traceability of AI-generated code.
  • Define reference DevSecOps patterns and reusable pipeline templates for future modernization waves, and report delivery and security metrics (for example, DORA metrics and vulnerability aging).
  • Support vulnerability triage and remediation guidance and collaborate with client cybersecurity and authorization stakeholders.

Benefits

  • medical and dental coverage
  • pension and 401(k) plans
  • a wide range of paid time off options
  • flexible vacation policy
  • time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service