Senior DevSecOps Engineer

Pantheon DataReston, VA
Hybrid

About The Position

Pantheon Data is seeking a Senior DevSecOps Engineer to design, build, and operate secure, cloud-native platforms in AWS GovCloud supporting ML-enabled workloads and applications that process CUI, PII, and PHI. GitLab Ultimate is our DevSecOps platform: you will own our GitLab CI/CD architecture end to end - pipelines, runners, security scanning, policy enforcement, and compliance evidence - and lead the migration of existing repositories and pipelines onto it. The role combines secure pipeline engineering with platform operations: hardened infrastructure as code, production Amazon EKS administered through GitOps, and gated security controls that satisfy NIST 800-53, FedRAMP, and DoD SRG requirements while keeping delivery fast. Successful candidates can walk through pipelines and platforms they have personally built - stage design, security gates, runner architecture, failure modes, and the compliance evidence they produced.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Information Systems, Engineering, or a related technical field, from an ABET accredited university.
  • 5+ years in DevSecOps /DevOps engineering with responsibility for production AWS environments. Plus an additional 5 years of experience in a related technical field.
  • Deep, hands-on GitLab expertise: GitLab CI/CD pipeline design at scale, GitLab Ultimate security and compliance features (SAST/DAST/secret detection/dependency/container/ IaC scanning, scan execution and approval policies, security dashboards), and GitLab Runner administration.
  • Experience implementing gated DevSecOps controls in CI/CD - pipelines that block on security findings, enforce approvals, and produce auditable evidence.
  • Deep hands-on expertise with Amazon EKS: cluster hardening, OCI-compliant image management, Helm, and GitOps deployment patterns (Argo CD or Flux).
  • Proficiency in Terraform for complex networking and security stacks: modular design, state management, and multi-environment promotion.
  • Practical understanding of NIST SP 800-53, FedRAMP, and DoD RMF/SRG, and their application to technical configurations in AWS GovCloud (STIGs, CIS benchmarks, boundary controls, audit logging).
  • Scripting proficiency in Python or Bash for operational automation and security tooling.
  • Current AWS Certified DevOps Engineer – Professional or AWS Certified Security – Specialty.
  • Ability to work effectively in remote, cross-functional teams; meet deadlines; and produce quality work with clear written communication.
  • Proficient in Microsoft Suite software including Outlook, Word, Excel, SharePoint, and PowerPoint.

Nice To Haves

  • Experience administering self-managed GitLab (or GitLab Dedicated for Government) in GovCloud or another isolated/restricted-egress environment, including upgrades, backups, and instance hardening.
  • Experience migrating organizations from GitHub/GitHub Actions (including GitHub Advanced Security) to GitLab Ultimate.
  • Experience supporting FedRAMP High or DoD IL4/IL5 ATO efforts: control implementation statements, POA&M management, continuous monitoring, and assessor engagement.
  • Supply-chain security depth: SLSA, Sigstore /cosign artifact signing, SBOM management, and dependency provenance.
  • Experience supporting ML/AI platforms (model serving, GPU workloads, Amazon Bedrock integrations, or data pipelines) in regulated environments.
  • Secrets management with AWS KMS, Secrets Manager, or HashiCorp Vault; policy-as-code tools such as OPA/ Kyverno; and admission control for Kubernetes.
  • Additional AWS certifications such as Solutions Architect or SysOps Administrator; Kubernetes certifications (CKA/CKS).

Responsibilities

  • Design, implement, and operate enterprise-grade GitLab CI/CD pipelines, including multi-project/parent-child pipeline orchestration, environment promotion gates, protected branches and environments, and reusable pipeline templates and CI components.
  • Deploy, configure, and tune the full GitLab Ultimate security suite as required pipeline gates: Advanced SAST, DAST, secret detection (including push protection), dependency scanning, container scanning, IaC scanning, license compliance, and API security - with findings triaged through the vulnerability management dashboard and merge request security widgets.
  • Enforce security centrally using scan execution policies, merge request approval policies, compliance frameworks, and compliance pipelines so scanning is mandatory across all projects; maintain audit events and evidence packages that support ATO, POA&M, and continuous-monitoring activities.
  • Generate and manage SBOMs (CycloneDX), enforce dependency and license policies, sign and verify build artifacts and container images, and maintain a secure, traceable path from commit to production.
  • Architect and operate GitLab Runner fleets in GovCloud (autoscaling, isolation, hardened images) and implement keyless OIDC authentication from GitLab to AWS IAM roles - no long-lived cloud credentials in CI.
  • Design and maintain hardened AWS GovCloud environments with Terraform (modular design, remote state, multi-repo dependency ordering), aligned to NIST 800-53 and FedRAMP High baselines and DISA STIG/CIS benchmarks.
  • Manage lifecycle, networking, and security for production Amazon EKS clusters; orchestrate deployments with Helm and GitOps tooling (Argo CD or Flux) for declarative state management; harden clusters, registries, and OCI image workflows.
  • Deploy and scale containerized ML models and data pipelines; build observability (metrics, logging, alerting, tracing) for regulated, restricted-egress environments.
  • Lead the migration of repositories, pipelines, and integrations from GitHub/GitHub Actions to GitLab, including translation of workflows, secrets strategy, branch protection parity, and developer enablement.
  • Mentor engineers on secure delivery practices, author runbooks and pipeline documentation, and partner with security and compliance teams on control implementation and assessment support.

Benefits

  • Competitive salaries and benefits
  • SmartBenefits through the Washington Metro Area Transportation Authority
  • Tuition assistance may be available for continuing education expenses and certifications related to their position.

Similar Senior DevSecOps Engineer job opportunities

© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service