- Company Name
- SciTec, Inc.
- Job Title
- Senior / Principal DevSecOps Engineer
- Job Description
-
**Job Title:** Senior / Principal DevSecOps Engineer
**Role Summary:**
Lead end‑to‑end DevSecOps lifecycle for high‑value U.S. Government defense software projects. Design, implement, and maintain secure CI/CD pipelines, Kubernetes‑based deployments, and vulnerability management processes to ensure compliance with DoD security standards. Mentor cross‑functional teams, embody continuous improvement, and drive secure coding and release practices across all stages of the software development lifecycle.
**Expectations:**
- U.S. citizenship required for DoD security clearance.
- Demonstrated independence: ability to execute tasks with limited supervision and align with team/product goals.
- Strong communication skills to provide thought leadership, mentorship, and clear project insights.
**Key Responsibilities:**
- Design, evolve, and maintain GitLab CI pipelines for secure build, test, and deployment automation.
- Orchestrate automated deployments to dev, test, and prod using Kubernetes, Helm, and Kustomize.
- Integrate pipeline stages with artifact repositories, static & dynamic scanning, code quality, and security tools.
- Monitor, troubleshoot, and optimize CI/CD performance and deployment incidents.
- Manage release processes: version promotion, branching strategy, integration, and validation.
- Develop and maintain Helm charts for application deployments.
- Validate deployment integrity and resolve issues within Kubernetes environments.
- Enforce secure coding practices and cybersecurity protocols across all phases.
- Facilitate vulnerability scanning, remediation, and penetration testing workflows.
- Collaborate with security, QA, and product teams to embed security & compliance early in delivery.
**Required Skills:**
- 8+ years of professional software development experience.
- 5+ years experience with: Python 3, Git, GitLab CI (or equivalent), Docker, Kubernetes, Helm/Kustomize.
- Strong attention to detail, problem‑solving, and self‑direction.
- Proficient with Linux system administration.
- Hands‑on expertise in:
- Container security tools (Grype, Syft).
- SAST/SCA platforms (Fortify, SonarQube, Snyk, Trivy, ZAP).
- AWS services (EKS, EC2, Lambda).
- Service mesh and ingress (Istio, NGINX, Traefik).
- Observability (Prometheus, Grafana).
- Authentication/Authorization (Keycloak).
- Artifact repositories (JFrog Artifactory, Nexus).
- Familiarity with secure SDLC practices, vulnerability lifecycle, and compliance frameworks.
**Required Education & Certifications:**
- Bachelor’s degree in a STEM discipline (Computer Science, Engineering, Information Technology, or related field).
- Eligibility for a DoD security clearance (U.S. citizenship).
---