Jr DevSecOps Engineer

Koniag Government Services, LLCWashington, DC
$75,000 - $105,000Hybrid

About The Position

Koniag Data Solutions, a Koniag Government Services company, is seeking a motivated and technically driven DevSecOps Engineer (Jr) to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved. The ideal candidate is an early-career software or cybersecurity professional with foundational knowledge of secure software development principles, DevSecOps practices, and application security concepts who is eager to build deep technical expertise in a complex, mission-driven federal IT environment. This individual must be a technically curious self-starter with strong analytical skills, a foundational understanding of software development and security integration practices, and the ability to contribute effectively to cross-functional engineering and security teams under the guidance of senior cybersecurity engineers and program leadership. This role sits within the Information Security Division (ISD) and provides foundational DevSecOps engineering support, security integration assistance, and application security services in support of the agency's secure software development lifecycle (SDLC), continuous integration and continuous delivery (CI/CD) pipeline security, and enterprise cybersecurity architecture and engineering program. Position Description: The DevSecOps Engineer (Jr) provides foundational engineering support across a range of DevSecOps integration, application security testing, security tool management, and continuous monitoring activities under the direction of senior cybersecurity engineers, the cybersecurity architecture and engineering team, and program leadership. This individual assists in the integration of security requirements into the software development lifecycle, supports CI/CD pipeline security tooling, contributes to application security testing activities including static and dynamic code analysis and API security testing, and helps ensure that security is embedded throughout the development-to-delivery pipeline for agency IT systems and applications. This role offers significant professional development opportunities for an early-career DevSecOps or cybersecurity professional seeking to build expertise in secure SDLC integration, application security testing, cloud security, Zero Trust Architecture implementation, and enterprise cybersecurity engineering within a dynamic and mission-critical federal environment.

Requirements

  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
  • Minimum of 1–2 years of experience in software development, DevOps, DevSecOps, application security, or a closely related technical field, including internship, academic project, or entry-level professional experience in a federal government IT environment or federal contractor setting.
  • Demonstrated foundational knowledge of secure software development lifecycle (SDLC) principles, CI/CD pipeline concepts, and application security testing methodologies obtained through coursework, certification study, or practical work experience.
  • Basic hands-on experience with at least one scripting or programming language (e.g., Python, PowerShell, Bash, JavaScript) used for automation, security tooling, or application development purposes.
  • Ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and all required system access authorizations prior to performing work.
  • Strong technical aptitude with foundational knowledge of secure software development principles, DevSecOps concepts, CI/CD pipeline security integration, and application security testing methodologies.
  • Basic hands-on proficiency with at least one scripting or programming language (e.g., Python, PowerShell, Bash, JavaScript) for automation, security tooling, or application development purposes.
  • Foundational knowledge of common application security vulnerabilities and remediation strategies, including familiarity with the OWASP Top Ten and OWASP API Top Ten.
  • Basic familiarity with vulnerability management concepts, including vulnerability scanning, CVSS scoring, findings prioritization, and remediation tracking.
  • Foundational knowledge of cloud computing concepts and cloud security principles, including basic familiarity with AWS and/or Microsoft Azure security services and configurations.
  • Strong written communication skills in English with the demonstrated ability to produce clear, concise, grammatically correct, and professionally formatted technical documentation aligned to provided templates and style guidance.
  • Strong organizational and time management skills with the ability to manage multiple concurrent technical tasks and documentation assignments with a high degree of accuracy and attention to detail.
  • Ability to follow detailed technical instructions, established procedures, and engineering standards to produce consistent and compliant outputs under senior staff direction.
  • Proficiency with Microsoft Office Suite, including Word, Excel, and PowerPoint, and enterprise collaboration tools such as Microsoft Teams and SharePoint.
  • Eagerness to learn, grow, and develop technical expertise in DevSecOps, application security, cloud security, and federal cybersecurity engineering under the mentorship of senior engineers and program leadership.
  • Strong interpersonal and teamwork skills with the ability to collaborate effectively across cross-functional engineering, security, and compliance teams in a dynamic federal IT environment.

Nice To Haves

  • Prior internship, co-op, or entry-level work experience supporting DevSecOps, application security testing, vulnerability management, or cybersecurity engineering activities in a federal agency or federal contractor environment.
  • Hands-on experience with CI/CD pipeline tooling, including Azure DevOps, Jenkins, GitLab CI/CD, or equivalent platforms.
  • Exposure to static code analysis (SAST) or dynamic application security testing (DAST) tools, including configuration, scan execution, or results interpretation experience.
  • Familiarity with cloud computing environments, including AWS or Microsoft Azure, particularly as they relate to security configuration and cloud security posture management.
  • CompTIA Security+, CompTIA CySA+, CompTIA PenTest+, or equivalent entry-level cybersecurity certification demonstrating foundational information security knowledge.
  • AWS Certified Cloud Practitioner, Microsoft Azure Fundamentals (AZ-900), or equivalent entry-level cloud platform certification.
  • Foundational familiarity with Azure DevOps for CI/CD pipeline management, backlog tracking, and automated security testing integration.
  • Basic experience with static code analysis (SAST) tools (e.g., SonarQube, Checkmarx, Veracode) or dynamic application security testing (DAST) tools (e.g., OWASP ZAP, Burp Suite Community Edition) in a development or testing environment.
  • Basic familiarity with API testing methodologies and API security concepts, including REST API structure, authentication mechanisms, and common API vulnerabilities aligned to the OWASP API Top Ten.
  • Exposure to containerization and container security concepts, including basic familiarity with Docker, Kubernetes, or equivalent container management platforms.
  • Familiarity with Infrastructure as Code (IaC) concepts and tools (e.g., Terraform, AWS CloudFormation, Azure Resource Manager templates) and associated security considerations.
  • Basic experience with version control systems, particularly Git, including branching strategies, pull request workflows, and secure code repository management practices.
  • Foundational familiarity with the NIST Risk Management Framework (RMF), NIST SP 800-53 security controls, and NIST SP 800-160 systems security engineering principles.
  • Familiarity with Zero Trust Architecture (ZTA) concepts, including basic knowledge of NIST SP 800-207 principles and their application to secure software development and cloud environments.
  • Basic exposure to enterprise cybersecurity tools present in the agency's security tool stack, including Microsoft Sentinel, Microsoft Defender for Endpoint, Tenable Nessus/Security Center, or AWS security services.
  • Foundational knowledge of DISA STIG and CIS Benchmark hardening standards and their application to operating system, application, and network device configurations.
  • Familiarity with Agile and Scrum software development methodologies, including participation in sprint planning, backlog management, and daily stand-up ceremonies.
  • Basic exposure to digital forensics, malware analysis, or incident response concepts as they relate to DevSecOps and application security engineering activities.
  • Demonstrated academic or professional interest in DevSecOps, application security, cloud security, or federal cybersecurity engineering through coursework, personal projects, Capture the Flag (CTF) competitions, or professional development activities.

Responsibilities

  • Assist senior engineers with the assessment of current DevSecOps practices and the integration of security tooling and processes into the agency's development-to-delivery pipeline under established guidance and direction.
  • Support the implementation of security controls and automated security checks within CI/CD pipelines, including code scanning, dependency analysis, and vulnerability detection at the build and deployment stages.
  • Assist with the integration of enterprise and security tools and practices into the development pipeline, supporting DevSecOps integration activities across agency IT Services and Business Technology Solutions projects as directed.
  • Contribute to the development and documentation of DevSecOps methods of procedures (MOPs), governance structures, standard operating procedures, and operational runbooks under senior staff direction.
  • Support the configuration, maintenance, and troubleshooting of DevSecOps tooling integrated into the agency's Azure DevOps environment, including pipeline configurations, security scan integrations, and automated testing frameworks.
  • Assist with the development of recommendations for DevSecOps governance structures and workforce development plans, contributing research, analysis, and draft documentation under senior engineer direction.
  • Support the automation and orchestration of CI/CD pipelines with ongoing security enhancements, assisting senior engineers in identifying and implementing improvements to pipeline security posture.
  • Assist with the execution of static code analysis (SAST) activities, supporting the configuration of static analysis tools, interpretation of scan results, and preparation of findings reports under senior staff direction.
  • Support dynamic code analysis (DAST) activities, including test environment setup coordination, scan execution assistance, and results documentation for review by senior engineers.
  • Assist with API security testing activities, supporting the execution of API scans against the OWASP API Top Ten criteria, organizing test results, and preparing formatted findings reports for senior staff review and stakeholder out-briefs.
  • Contribute to sprint-based penetration and API testing activities, supporting test coordination, results documentation, and remediation tracking under senior engineer direction.
  • Assist with the validation of remediation activities for identified application security findings, supporting re-testing execution and documentation of remediation verification results.
  • Research and document common application security vulnerabilities, attack vectors, and remediation strategies to support the development of senior engineer recommendations and findings reports.
  • Assist with the scheduling and execution of vulnerability scans across the enterprise IT environment using Tenable Security Center, supporting scan configuration, results export, and preliminary findings review under senior staff direction.
  • Support the preparation of weekly vulnerability debrief slides and reports, compiling scan data, formatting outputs, and organizing findings for senior staff review and stakeholder distribution.
  • Assist with the review of vulnerability reports from Microsoft Threat and Vulnerability Management (TVM) to support the confirmation of CVE impact and applicability to the enterprise environment.
  • Contribute to the tracking and reporting of zero-day vulnerabilities, assisting senior staff with status tracking, closure documentation, and ad hoc reporting activities.
  • Support the management of scanning infrastructure, assisting with monitoring scanner operational status, performing basic troubleshooting under senior guidance, and escalating issues requiring advanced resolution.
  • Assist with compliance scans of newly provisioned servers and newly created OS baseline images, supporting scan execution and results documentation in accordance with established procedures.
  • Assist senior engineers with the administration, configuration, and maintenance of enterprise cybersecurity tools across the agency's security tool stack, including endpoint protection, SIEM, vulnerability management, and application security platforms.
  • Support the development and maintenance of tools inventory documentation, standard operating procedures (SOPs), and tools procedures documentation, ensuring all materials are current, accurately formatted, and uploaded to the designated SharePoint repository.
  • Assist with the identification of misconfigurations in security tools and capabilities for agency-operated systems, documenting findings and supporting remediation coordination under senior staff direction.
  • Contribute to the design, development, integration, and testing of automated security testing tools and scripts in support of Assessment and Authorization (A&A) activities.
  • Support the development and maintenance of compliance content leveraging the agency's Continuous Diagnostics and Mitigation (CDM) toolset, assisting senior engineers with content configuration and alignment to approved Security Configuration Specifications.
  • Research and document emerging cybersecurity tools, technologies, and capabilities, supporting senior engineer assessments of potential additions or enhancements to the agency's security tool stack.
  • Assist senior security architects and engineers with the development and maintenance of cybersecurity architecture documentation, including architecture diagrams, data flow diagrams, topology maps, and recommendation documents under senior staff direction.
  • Support the development of Security Configuration Baselines (SCBs), assisting with research, documentation, and alignment to DISA STIGs, CIS Benchmarks, and agency-approved hardening standards.
  • Contribute to security design reviews for new technologies and services by researching security considerations, documenting relevant standards and requirements, and preparing supporting materials for senior engineer review.
  • Assist with the development of Zero Trust Architecture (ZTA) documentation and implementation support materials, contributing research, diagram drafts, and supporting content under senior architect direction in alignment with NIST SP 800-207 and applicable federal ZTA guidance.
  • Support configuration management activities, assisting senior engineers with the maintenance of the Configuration Management Database (CMDB) and contributing to the development of configuration management process documentation.
  • Assist with tracking and documenting new, revised, or emerging applicable federal policies and regulations, supporting senior architects in assessing impacts to the agency's cybersecurity architecture and engineering posture.
  • Assist senior engineers with security engineering activities for cloud-hosted systems and services across AWS and Microsoft Azure Government environments, supporting configuration review, security assessment, and documentation activities under established guidance.
  • Support the monitoring and review of cloud security posture management outputs from AWS Security Hub, Amazon GuardDuty, Microsoft Defender for Cloud, and related cloud security tools, assisting with findings documentation and escalation to senior engineers.
  • Contribute to the development and maintenance of cloud security architecture documentation, assisting senior engineers with diagram preparation, findings write-ups, and recommendation documentation.
  • Assist with ensuring that FedRAMP JAB Provisional ATO or Agency ATO requirements are considered in cloud solution implementations, supporting senior engineers with documentation and compliance verification activities.
  • Assist senior engineers with the development, testing, and maintenance of automation scripts and tools supporting security operations, vulnerability management, compliance monitoring, and DevSecOps pipeline integration activities.
  • Support the development of PowerShell, Python, or equivalent scripts for automating routine security administration, compliance data collection, and reporting tasks under senior engineer direction.
  • Assist with the development and maintenance of Extract-Transform-Load (ETL) processes and data normalization routines supporting security dashboards and visualization outputs.
  • Contribute to the testing and validation of automation tools and scripts prior to production deployment, supporting quality assurance activities under senior engineer guidance.
  • Assist with the preparation and maintenance of technical documentation, project plans, recommendation documents, hardware/software review reports, procedure documents, and system diagrams in support of cybersecurity engineering activities.
  • Prepare and maintain weekly and monthly status reports, enterprise ticketing system reports, and other recurring reporting deliverables in accordance with established formats and submission schedules.
  • Ensure all documentation is peer-reviewed for accuracy, grammar, and formatting consistency prior to submission, and that all deliverables are uploaded to the designated SharePoint or GRC repository.
  • Respond to documentation requests and ad hoc reporting requirements within established timelines as directed by senior staff and program leadership.
  • Complete all required annual cybersecurity awareness training within established deadlines and maintain all required certifications as current and unexpired throughout the period of performance.
  • Ensure all work products are Section 508 accessibility compliant where required, government-owned, and free of proprietary or company-specific markings or restrictions.
  • Adhere to all applicable Federal security, privacy, and compliance requirements, including FISMA, NIST SP 800-53, NIST SP 800-160, OMB Circular A-130, and agency-specific cybersecurity policies, in the performance of all assigned duties.

Benefits

  • health, dental and vision insurance
  • 401K with company matching
  • flexible spending accounts
  • paid holidays
  • three weeks paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service