- Company Name
- Credence
- Job Title
- Senior DevSecOps Engineer
- Job Description
-
Job Title: Senior DevSecOps Engineer
Role Summary:
Design, build, and manage secure, scalable, and compliant AWS GovCloud environments for defense and federal agency applications. Spearhead DevSecOps pipelines, IaC, container orchestration, and automated security testing to ensure adherence to NIST, RMF, FedRAMP, and Zero Trust standards.
Expectations:
- 7+ years of hands‑on DevSecOps, cloud engineering, or infrastructure automation (mid‑level 5+ years).
- U.S. citizenship with eligibility for DoD SECRET clearance.
- Proven experience with AWS GovCloud services and federal cybersecurity frameworks.
Key Responsibilities:
- Architect and maintain AWS GovCloud infrastructures (EC2, EKS, ECS, Fargate, S3, RDS, VPC).
- Develop and optimize CI/CD pipelines using GitLab CI/CD, Jenkins, and AWS CodePipeline with Terraform, CloudFormation, or Ansible.
- Implement security baselines (NIST 800‑171/53, RMF, STIG, Zero Trust) and automate compliance checks (SAST, DAST, SBOM).
- Provision and manage Docker containers and Kubernetes clusters; configure IAM, GuardDuty, Security Hub, Config, KMS, WAF, Secrets Manager.
- Deploy monitoring, logging, and incident response solutions (CloudWatch, GuardDuty, Security Hub, Splunk/ELK).
- Create automation scripts (Python, Bash, PowerShell) for deployment and security enforcement.
- Collaborate with dev, security, and cloud teams to embed security into the SDLC.
Required Skills:
- AWS GovCloud architecture, IAM, Security Hub, GuardDuty, KMS, WAF, Config, Secrets Manager
- CI/CD tools: GitLab CI/CD, Jenkins, AWS CodePipeline
- IaC: Terraform, CloudFormation, Ansible
- Containerization and orchestration: Docker, Kubernetes, EKS, ECS, Fargate
- Automated security scanning: SAST, DAST, vulnerability tools, SBOM management
- Scripting: Python, Bash, PowerShell
- Federal cybersecurity frameworks: NIST 800‑171/53, RMF, FedRAMP, STIG, Zero Trust
Required Education & Certifications:
- Security+ or equivalent
- AWS Certified Security – Specialty (or comparable)
- Bachelor’s degree in Computer Science, Information Security, or related field (preferred)