Senior DevSecOps Engineer

Peraton•Reston, VA
•$146,000 - $234,000•Onsite

About The Position

Peraton is seeking a Senior DevSecOps Engineer to join our team in Reston, VA. This role focuses on building and operating an Agentic AI platform, encompassing delivery, infrastructure, runtime operations, and platform health. The engineer will contribute to the technical backbone ensuring the platform is secure, reliable, and scalable, covering CI/CD pipelines, automated testing, EKS cluster operations, AWS infrastructure, monitoring, alerting, and health checking. The ideal candidate possesses strong technical execution, operational discipline, and a builder mindset, with the ability to design functional, supportable, observable, secure, and audit-ready systems. This position offers an opportunity to shape the platform layer of a significant Agentic AI environment, directly impacting platform resilience and advanced AI-enabled capabilities delivery in secure, compliant, and production-ready ways.

Requirements

  • Bachelor's degree with 12 years professional experience, or Associate's degree with 14 years professional experience, or MS degree with 10 years professional experience, or high school diploma/equivalent with 16 years professional experience
  • Hands-on experience building and maintaining CI/CD pipelines in GitHub Actions, GitLab CI, or comparable systems — including pipeline-as-code, reusable workflows, and integrated quality/security gates
  • Production experience operating Kubernetes, ideally Amazon EKS — cluster upgrades, RBAC, Helm-based deployments, and troubleshooting workload issues
  • Practical AWS experience across core services: VPC, IAM, S3, RDS, CloudTrail, and KMS
  • Infrastructure-as-code experience with OpenTofu, Terraform, or comparable — writing modules, managing state, and driving change through code review
  • Experience implementing and tuning monitoring, logging, and alerting using CloudWatch, Prometheus/Grafana, or equivalent tooling
  • Familiarity with identity and access management patterns — SSO/SAML/OIDC integration, RBAC, and provisioning/deprovisioning workflows
  • Experience integrating security testing into delivery pipelines (SAST, DAST, SCA, secrets scanning, or dependency scanning) and driving findings to closure
  • Solid scripting and automation skills in Python, Go, Bash, or comparable
  • Working knowledge of secrets management, least-privilege design, and software supply chain integrity practices
  • Comfort with modern engineering delivery patterns: trunk-based development, merge-request-driven change, and automated release quality controls
  • Clear written and verbal communication — able to document runbooks, write actionable alerts, and coordinate with security, program, and customer stakeholders
  • U.S. Citizenship required
  • Must have the ability to obtain and maintain a Public Trust clearance

Nice To Haves

  • Experience operating Amazon EKS at scale, including add-on lifecycle, node group strategy, pod identity, and IRSA
  • GitOps experience with ArgoCD, Flux, or comparable
  • Experience with DAST and runtime security tooling such as OWASP ZAP, Burp Suite, Nuclei, or equivalent
  • Experience implementing SLIs/SLOs and error-budget-driven operational practices
  • Experience building synthetic and transactional monitoring that exercises real authentication flows and critical user journeys
  • Familiarity with IAVM tracking, vulnerability remediation workflows, and evidence generation for compliance reporting
  • Exposure to policy-as-code frameworks: OPA/Rego, Kyverno, or Conftest
  • Experience with software supply chain integrity: SBOM generation, image signing (Cosign/Sigstore), SLSA provenance
  • Experience supporting FedRAMP, NIST 800-53, RMF, or comparable federal compliance environments
  • Experience with distributed tracing and modern observability stacks: OpenTelemetry, Loki, Tempo, or ELK
  • Active security clearance or eligibility
  • Relevant certifications such as CKA/CKS, AWS Solutions Architect / Security, or Terraform Associate
  • Prior experience supporting AI/ML or Agentic AI platforms in production

Responsibilities

  • Operate the Agentic AI platform across CI/CD, cloud infrastructure, Kubernetes operations, observability, and runtime reliability.
  • Build and maintain CI/CD pipelines using GitHub Actions and/or GitLab CI for secure, repeatable, and efficient delivery workflows.
  • Implement and improve automated testing and quality gates within the software delivery lifecycle, including build validation, integration checks, security testing, and deployment controls.
  • Plan and execute releases and deployments, managing change windows, release artifacts, deployment automation, post-deployment health validation, and rollback procedures.
  • Support operational ownership of Amazon EKS / Kubernetes environments, including cluster lifecycle, upgrades, troubleshooting, RBAC, Helm-based deployments, pod identity, and GitOps-aligned workflows.
  • Build and maintain AWS infrastructure for platform and application needs using services like VPC, IAM, S3, RDS, CloudTrail, and KMS.
  • Contribute to infrastructure provisioning and lifecycle management through OpenTofu / Terraform and infrastructure-as-code practices.
  • Administer user management for the platform, including identity provider integration (SSO/SAML/OIDC), role-based access control (RBAC), provisioning/deprovisioning workflows, and access reviews.
  • Design and operate a monitoring, logging, and alerting stack using CloudWatch, Prometheus/Grafana, or equivalent tooling.
  • Assess system logs to detect anomalies, configuration drift, misuse, and security-relevant events; triage findings and drive remediation.
  • Develop actionable alerts, service health indicators, and SLO-aligned operational thresholds.
  • Build and maintain synthetic and transactional monitoring for authentication flows, user journeys, and critical service transactions.
  • Track and remediate Information Assurance Vulnerability Management (IAVM) notices and other vulnerability advisories, maintaining inventory accuracy, driving patching, and producing compliance evidence.
  • Implement and maintain DAST and runtime security testing in delivery pipelines using tools like OWASP ZAP, Burp, Nuclei, or equivalent.
  • Support security-focused CI/CD practices including secrets management, least privilege, software supply chain integrity, and audit evidence generation.
  • Apply modern engineering delivery patterns such as trunk-based development, merge-request-driven change, and automated release quality controls.

Benefits

  • Employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service