ForgeApply
Try it free

ForgeApply · Job listing

DevSecOps Security Engineer

GDIT

Remote · US$191k – $259k

See all 364 open roles at GDIT

Tailor your resume for this GDIT job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for GDIT's site. Free trial, no card required.

About this role

Type of Requisition: Regular

Clearance Level Must Currently Possess: None

Clearance Level Must Be Able to Obtain: None

Public Trust/Other Required: BI Full 6C (T4)

Job Family: Cyber and IT Risk Management

Job Qualifications: Skills: AWS Cloud Computing, CI/CD, DevSecOps Certifications: None Experience: 8 + years of related experience US Citizenship Required: Yes

Job Description: DevSecOps Security Engineer

Help us simplify the complex as a DevSecOps Security Engineer at GDIT, where we tailor advanced cloud security solutions to critical client missions. In this role, your priority will be engineering automated, secure compliance and vulnerability-management workflows for our program, while we focus on supporting your professional growth.

Our work on the AED program depends on a senior security engineer who has managed the security portion of a DevSecOps pipeline operating under a continuous ATO (cATO). You’ll leverage a modern stack, including AWS GovCloud security services, Terraform, and CI/CD pipeline tooling, to shift our security posture from reactive to proactive across a highly secure, automated environment.

HOW A DEVSECOPS SECURITY ENGINEER WILL MAKE AN IMPACT: • Architect and automate security workflows across our CI/CD pipeline and compliance operations, reducing manual effort in vulnerability scan analysis, security inventory auditing, and continuous monitoring reporting. • Partner with development and platform teams to integrate, automate, and monitor security tool components (scan ingestion, finding triage, evidence generation) within automated pipelines. • Build automation for compliance and ATO artifacts, including continuous monitoring reports, SPIAs, and control evidence mapping against NIST 800-53 / 800-171. • Perform automated inventory delta analysis and drift detection across cloud accounts to maintain an accurate, auditable security posture. • Champion DevSecOps culture by mentoring junior/mid-level engineers, educating teams on modern security tooling, and resolving complex configuration or performance issues. • Leverage Generative AI engineering tools (such as Claude, Gemini, Copilot) to accelerate the development of security automation, compliance reporting, and Infrastructure as Code (IaC) scanning workflows. • Define guidelines and standards for securing AWS Cloud and container environments, implementing advanced solutions for system security, logging, and audit correlation. • Drive engineering excellence by guiding the preparation of comprehensive technical documentation, processes, and procedures.

WHAT YOU’LL NEED TO SUCCEED:

Technical Expertise: • Continuous ATO Pipeline Security (Required): Direct, hands-on experience managing the security portion of a DevSecOps pipeline in a continuous ATO (cATO) environment. Candidates must have owned automated security gates, control evidence, and compliance posture within a live continuous-authorization pipeline, not point-in-time ATO or general DevOps exposure. • Education & Experience: BA/BS Degree and 8+ years of relevant experience (or an equivalent combination of education and experience). • Compliance Automation: Hands-on automation of compliance workflows: scan ingestion, finding triage, evidence generation, and continuous monitoring reporting. • Cloud Security Tooling: Familiarity with AWS GovCloud security services (Security Hub, Inspector, GuardDuty, Config) and centralizing/correlating their findings, along with scanning and monitoring tooling such as Qualys, CrowdStrike, Nexus/Sonatype, SonarQube, and Datadog. • Infrastructure as Code Security: Experience building and scanning IaC (Terraform, CloudFormation) for security and compliance. • Standards & Frameworks: Background in NIST 800-53 or 800-171 control implementation and evidence mapping; familiarity with FedRAMP and IAM. • Scripting/Development: Strong proficiency in automation scripting (Python, Bash, or similar) for building internal security tooling; Linux/Unix administration (RHEL or CentOS preferred). • Compliance: Active Security+ Certification (or equivalent DoD 8570/8140 baseline).

Leadership & Professional Skills: • Team Leadership Potential: Demonstrated capability or strong desire to mentor junior/mid-level engineers, drive technical consensus, and serve as a technical anchor for the team. • Problem Solving: Exceptional critical thinking skills with a proven track record of delivering simple, elegant solutions to highly complex security and compliance problems. • Communication: Highly effective communication and collaboration skills, with the ability to bridge technical concepts between development teams and program stakeholders. • Growth Mindset: A strong commitment to continuous learning, engineering best practices, and driving process improvements.

Preferred Background: • Prior experience at a company that builds security products or DevSecOps tooling for software development, with a focus on cyber automation. • Experience with continuous monitoring automation and proactive compliance posture management. • Experience supporting a security audit cadence and evidence collection at scale. • Exposure to security analytics platforms (e.g., Databricks) for correlating and analyzing security telemetry at scale.

GDIT IS YOUR PLACE: • True Work-Life Autonomy: Enjoy a full-flex work week designed to give you ownership over your personal and professional priorities. • Total Well-being: Comprehensive health, dental, vision, and wellness packages to support you and your family. • Invested in Your Wealth: A robust 401(k) program with a competitive company match. • Continuous Technical Evolution: Access to paid advanced certifications, higher education, and dedicated professional growth opportunities to keep your skills sharp. • Internal Career Mobility: A dedicated internal talent team focused entirely on helping you navigate and advance your career path within GDIT. • Scale & Innovation: Work with complex, mission-critical technologies an

Tailor your resume for this GDIT role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Remote Security & Cybersecurity Jobs · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)