DevSecOps Engineer

ICFReston, VA
Remote

About The Position

ICF’s Digital Modernization division is a rapidly growing, entrepreneurial, technology department, seeking a DevSecOps Engineer to support upcoming needs with our federal customers. Our Digital Modernization division is an information technology and management consulting department that offers integrated, strategic solutions to its public and private-sector clients. ICF has the expertise, agility, and commitment to design, build, and operate high-performance IT engines to support all aspects of our client’s business. We are seeking a DevSecOps Engineer to support a federal client by helping integrate security practices into modern cloud and application delivery workflows. You will work alongside senior DevOps, security, and application teams to support CI/CD pipelines, cloud infrastructure, automated testing, and security controls in alignment with federal standards. Work is fully remote within the United States on government-furnished equipment, with core collaboration hours in Eastern Time.

Requirements

  • U.S. citizenship, required due to federal contract requirements
  • Must reside in the United States (U.S.) and the work must be performed in the United States (U.S.), as this work is for a federal contract and laws do apply
  • Ability to obtain and maintain a favorable federal agency background investigation / suitability determination
  • 5+ years of experience in DevOps, cloud engineering, systems engineering, or cybersecurity

Nice To Haves

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related technical field
  • An active federal security clearance or a prior favorable federal background investigation (supports reciprocity and faster onboarding)
  • Basic understanding of CI/CD concepts and DevOps practices; experience with GitLab and/or Jenkins specifically
  • Familiarity with at least one cloud platform (AWS or Azure preferred, including GovCloud)
  • Working knowledge of Linux (e.g., RHEL) and Windows Server environments, and basic scripting (Bash, Python, PowerShell, or similar)
  • Exposure to DevSecOps and security tooling (e.g., SonarQube, Tenable, Snyk, Trivy, Checkov, Prisma Cloud)
  • Experience with Docker and basic Kubernetes or OpenShift concepts
  • Familiarity with SIEM/log-analysis platforms such as Splunk
  • Exposure to low-code or COTS application platforms (e.g., Appian, Salesforce, ServiceNow) and their deployment/release models
  • Basic familiarity with relational databases (e.g., SQL Server)
  • Familiarity with NIST 800-53, FedRAMP, or other federal security standards
  • Entry-level certifications such as AWS Cloud Practitioner, Azure Fundamentals, Security+, or similar
  • Experience supporting applications in a regulated or government environment

Responsibilities

  • Assist in the development, maintenance, and monitoring of CI/CD pipelines using tools such as GitLab CI or Jenkins, including artifact management (e.g., Nexus)
  • Support automated deployment and environment promotion for applications built on a COTS/low-code platform (e.g., Appian), from development through test and production
  • Help implement automated quality gates in pipelines — unit/integration test execution, automated regression suites, and code-quality/static analysis — in support of contract quality targets
  • Help integrate security scanning and compliance checks into build and deployment pipelines (SAST, DAST, dependency scanning, container scanning)
  • Support cloud infrastructure in AWS or Azure, including GovCloud regions, with an emphasis on security best practices; support infrastructure as code (IaC) using tools like Terraform, CloudFormation, or platform-native tooling
  • Support monitoring and observability — log aggregation and streaming to enterprise monitoring (e.g., Splunk), alerting, performance testing (e.g., JMeter) — and assist with troubleshooting and incident response
  • Support backup/recovery operations and availability, recovery-time, and recovery-point objectives
  • Document configurations, processes, and security controls to support audits, Assessment & Authorization (ATO) activities, and continuous-monitoring evidence
  • Collaborate with development, operations, and security teams in an Agile/Scrum environment
  • Learn and apply federal security frameworks such as NIST 800-53, FISMA, and FedRAMP

Benefits

  • ICF is an equal opportunity employer
  • Reasonable Accommodations are available
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service