DevSecOps Engineer

Nakupuna Companies•Arlington, VA
•Onsite

About The Position

Na Ali‘i is seeking a DevSecOps Engineer to support the secure delivery and operation of a software solution for a Department of the Navy organization and serve as a team member of Nakupuna Labs, the in-house innovation team. The ideal candidate has advanced experience in designing, implementing, administering, and continuously improving CI/CD pipelines, deployment environments, and integrated security controls.

Requirements

  • Hands-on experience designing and administering production CI/CD pipelines using tools such as GitLab CI/CD, GitHub Actions, Azure DevOps, or Jenkins, including Git workflows, release management, and artifact repositories.
  • Experience with containers and orchestration technologies, such as Docker and Kubernetes, and with infrastructure-as-code or configuration-management tools, such as Terraform, Bicep, CloudFormation, or Ansible.
  • Experience administering Azure, AWS, or on-premises environments, including Linux or Windows systems, networking, identity and access management, certificates, and secrets.
  • Ability to automate operational tasks using PowerShell, Bash, Python, or a comparable scripting language.
  • Working knowledge of secure software delivery practices, vulnerability management, STIGs, DoD RMF, NIST SP 800-53 controls, security evidence collection, and authorization support.
  • Strong troubleshooting, documentation, communication, and collaboration skills, including the ability to work effectively with technical teams and customer stakeholders.
  • Bachelor's degree in computer science, information technology, cybersecurity, engineering, or a related field and at least 5 years of relevant professional experience.
  • Active Secret security clearance.
  • Must be a U.S. citizen.

Nice To Haves

  • One or more relevant certifications, such as Security+ CE, CySA+, CISSP, CSSLP, GSEC, or a cloud, DevOps, or Kubernetes security credential.

Responsibilities

  • Designing, implementing, and administering CI/CD pipelines that automate build, test, security scanning, approval, release, rollback, and deployment activities across development, test, and production environments.
  • Integrating and maintaining automated security controls, including static and dynamic application security testing, software composition analysis, secrets scanning, container and infrastructure-as-code scanning, and policy-based quality gates.
  • Administering source code and artifact repositories, pipeline runners or agents, deployment credentials, certificates, secrets, and role-based access in accordance with least-privilege principles.
  • Automating infrastructure provisioning and configuration to create repeatable, hardened, and Security Technical Implementation Guide (STIG)-aligned environments and configuration baselines.
  • Managing containerized application build and deployment processes and, where applicable, orchestration platforms, registries, software bills of materials, and signed artifacts.
  • Monitoring pipeline and platform availability, performance, and security events; troubleshooting build and deployment failures; and coordinating patching, incident response, and vulnerability remediation.
  • Maintaining release records, system diagrams, operating procedures, security evidence, and Risk Management Framework (RMF) authorization artifacts; supporting control assessments, remediation activities, and continuous monitoring.
  • Collaborating with developers, testers, cybersecurity personnel, infrastructure teams, and customer stakeholders to translate delivery and security requirements into automated controls and improve reliability, delivery speed, and auditability.

Benefits

  • Market-based compensation strategy
  • Total compensation package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service