DevSecOps Security Engineer

General Dynamics Information Technology
$191,250 - $258,750Remote

About The Position

Help us simplify the complex as a DevSecOps Security Engineer at GDIT, where we tailor advanced cloud security solutions to critical client missions. In this role, your priority will be engineering automated, secure compliance and vulnerability-management workflows for our program, while we focus on supporting your professional growth. Our work on the AED program depends on a senior security engineer who has managed the security portion of a DevSecOps pipeline operating under a continuous ATO (cATO). You’ll leverage a modern stack, including AWS GovCloud security services, Terraform, and CI/CD pipeline tooling, to shift our security posture from reactive to proactive across a highly secure, automated environment.

Requirements

  • Direct, hands-on experience managing the security portion of a DevSecOps pipeline in a continuous ATO (cATO) environment. Candidates must have owned automated security gates, control evidence, and compliance posture within a live continuous-authorization pipeline, not point-in-time ATO or general DevOps exposure.
  • BA/BS Degree and 8+ years of relevant experience (or an equivalent combination of education and experience).
  • Hands-on automation of compliance workflows: scan ingestion, finding triage, evidence generation, and continuous monitoring reporting.
  • Familiarity with AWS GovCloud security services (Security Hub, Inspector, GuardDuty, Config) and centralizing/correlating their findings, along with scanning and monitoring tooling such as Qualys, CrowdStrike, Nexus/Sonatype, SonarQube, and Datadog.
  • Experience building and scanning IaC (Terraform, CloudFormation) for security and compliance.
  • Background in NIST 800-53 or 800-171 control implementation and evidence mapping; familiarity with FedRAMP and IAM.
  • Strong proficiency in automation scripting (Python, Bash, or similar) for building internal security tooling; Linux/Unix administration (RHEL or CentOS preferred).
  • Active Security+ Certification (or equivalent DoD 8570/8140 baseline).
  • Demonstrated capability or strong desire to mentor junior/mid-level engineers, drive technical consensus, and serve as a technical anchor for the team.
  • Exceptional critical thinking skills with a proven track record of delivering simple, elegant solutions to highly complex security and compliance problems.
  • Highly effective communication and collaboration skills, with the ability to bridge technical concepts between development teams and program stakeholders.
  • A strong commitment to continuous learning, engineering best practices, and driving process improvements.

Nice To Haves

  • Prior experience at a company that builds security products or DevSecOps tooling for software development, with a focus on cyber automation.
  • Experience with continuous monitoring automation and proactive compliance posture management.
  • Experience supporting a security audit cadence and evidence collection at scale.
  • Exposure to security analytics platforms (e.g., Databricks) for correlating and analyzing security telemetry at scale.

Responsibilities

  • Architect and automate security workflows across our CI/CD pipeline and compliance operations, reducing manual effort in vulnerability scan analysis, security inventory auditing, and continuous monitoring reporting.
  • Partner with development and platform teams to integrate, automate, and monitor security tool components (scan ingestion, finding triage, evidence generation) within automated pipelines.
  • Build automation for compliance and ATO artifacts, including continuous monitoring reports, SPIAs, and control evidence mapping against NIST 800-53 / 800-171.
  • Perform automated inventory delta analysis and drift detection across cloud accounts to maintain an accurate, auditable security posture.
  • Champion DevSecOps culture by mentoring junior/mid-level engineers, educating teams on modern security tooling, and resolving complex configuration or performance issues.
  • Leverage Generative AI engineering tools (such as Claude, Gemini, Copilot) to accelerate the development of security automation, compliance reporting, and Infrastructure as Code (IaC) scanning workflows.
  • Define guidelines and standards for securing AWS Cloud and container environments, implementing advanced solutions for system security, logging, and audit correlation.
  • Drive engineering excellence by guiding the preparation of comprehensive technical documentation, processes, and procedures.

Benefits

  • Full-flex work week
  • Comprehensive health, dental, vision, and wellness packages
  • Robust 401(k) program with a competitive company match
  • Access to paid advanced certifications, higher education, and dedicated professional growth opportunities
  • Internal career mobility support
  • Generous paid vacation, floating holidays, and time off
  • 15 days of paid leave per calendar year
  • 10 paid holidays per year
  • Up to 160 hours of paid family leave in a rolling 12-month period
  • Short and long-term disability benefits
  • Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service