Cybersecurity Engineer – DevSecOps
Accountabilities Conduct code and container vulnerability assessments using approved DoD vulnerability scanning tools, DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and applicable software assurance tools.
Assess operating system security configurations against applicable DISA STIGs, SRGs, and cybersecurity requirements.
Perform cybersecurity assessments, security audits, and risk analyses to identify vulnerabilities, security weaknesses, and compliance gaps.
Apply Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies throughout the software development lifecycle.
Integrate and assess cybersecurity policies and controls within CI/CD pipelines to support secure software delivery.
Serve as a GitLab security reviewer and approver for merge requests, evaluating scan results and confirming that findings are remediated or appropriately documented before release.
Review GitLab SAST, dependency, secret detection, and container scanning results and coordinate remediation with development teams.
Track cybersecurity findings through closure and ensure appropriate risk-management processes are followed for unresolved issues.
Review changes to GitLab security policies, pipeline controls, and protected branch settings to ensure required security checks and approvals remain enforced.
Provide cybersecurity oversight for containerized workloads using NeuVector, including vulnerability findings, admission control decisions, and runtime security alerts.
Collaborate with application and platform teams to investigate NeuVector findings, refine security policies, and document remediation or accepted risks.
Ensure security provisions within system acquisition and program documentation address identified cybersecurity requirements.
Provide cybersecurity guidance and support the development of mitigation strategies for DoD information systems.
Prepare Risk Management Framework (RMF) artifacts and Memoranda of Agreement (MoAs) supporting system interfaces and networking implementations.
Identify and evaluate Common Criteria and National Information Assurance Partnership (NIAP)-certified technologies when applicable.
Evaluate cybersecurity products and technologies to determine alignment with applicable DoD and DoN requirements.
Collaborate with engineering, development, platform, and program teams throughout the software lifecycle to address security requirements and manage cybersecurity risks.
Support business development activities as needed, including technical interviews, technical documentation, proposal writing, and proposal review activities.
Requirements
Active Secret security clearance required.
Bachelor’s degree with 8 years of relevant experience, or high school diploma/equivalent with 13 years of relevant experience.
Experience working within the DoD Risk Management Framework (RMF) and familiarity with DoDI 8510.01.
DoD 8570.01-M Information Assurance Manager (IAM) Level II certification, such as CISSP, GSLC, or CISM.
Strong knowledge of DoD cybersecurity requirements, including DISA STIGs and SRGs.
Experience with software security testing methodologies, including SAST and DAST.
Demonstrated experience supporting cybersecurity within CI/CD pipelines or DevSecOps environments.
Experience with GitLab security tools and processes, including reviewing security scan results and coordinating vulnerability remediation.
Experience with container security and vulnerability management is preferred.
Proficiency with GitLab, NeuVector, and Sonatype is preferred.
Experience supporting cybersecurity initiatives within a DoD or Department of the Navy environment is preferred.
Experience with the Navy’s Rapid Assess and Incorporate Software Engineering (RAISE) methodology and RAISE Platform of Choice (RPOC) is advantageous.
Experience evaluating Common Criteria and NIAP-certified technologies is preferred.
Experience developing or supporting RMF artifacts, security documentation, and cybersecurity mitigation strategies is advantageous.
Strong analytical, problem-solving, documentation, and communication skills.
Ability to collaborate effectively with technical teams, security stakeholders, program leadership, and system owners.
Ability to work independently in a fully remote environment while maintaining strong attention to detail and compliance.
Candidates located in or near major U.S. Navy installations are preferred, particularly in the New Orleans, Orlando, and Washington, DC metropolitan areas. Candidates near other major Navy facilities may also be considered.
Comfortable working for prolonged periods at a desk and on a computer.
Able to lift approximately 10–15 pounds when required.
Benefits
Annual compensation range of $125,000–$135,000 , with final compensation determined by relevant education, experience, knowledge, skills, abilities, and other applicable factors.
Fully remote work arrangement.
Opportunity to support cybersecurity and secure software delivery within a DoD/DoN mission environment.
Hands-on exposure to DevSecOps, application security, CI/CD security, container security, vulnerability management, and cybersecurity compliance.
Opportunity to work with technologies and tools including GitLab, NeuVector, Sonatype, SAST, DAST, and container security platforms.
Exposure to Risk Management Framework processes and federal cybersecurity standards.
Opportunity to collaborate with engineering, development, platform, and program professionals on mission-focused initiatives.
Potential involvement in technical business development, proposal development, and strategic growth activities.
Professional development opportunities through exposure to evolving cybersecurity technologies and methodologies.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1