Are you looking to advance your IT career in being a DevSecOps Engineer? Let's chat and see if we are a good match!
Opportunity:
The DevSecOps Engineer is a hands-on practitioner responsible for building, automating, and sustaining the delivery infrastructure that enables mission-critical software to move fast without compromising compliance. You will actively build and maintain CI/CD pipelines, harden and manage Kubernetes environments, automate security compliance, and leverage AI as a force multiplier across the entire delivery lifecycle. When team capacity demands it, you will contribute directly to feature development — bringing a security-first perspective to application code.
Primary Responsibilities:
- Design, implement, and maintain automated CI/CD pipelines that carry code from development through security scanning, compliance validation, and deployment into Navy and DoD environments
- Build and maintain hardened Kubernetes environments aligned to DISA STIG requirements across cloud and restricted network deployment contexts
- Automate security artifact generation including SBOM production, CVE scanning, and continuous compliance validation
- Drive adoption of Infrastructure as Code, GitOps practices, and controls-as-code across the team
- Leverage AI tooling to accelerate pipeline development, vulnerability triage, compliance remediation, and operational documentation
- Partner closely with software engineers, systems engineers, and ISSE's to embed security and compliance requirements from the start of development
- Maintain and evolve deployment infrastructure across multiple secure environments, including cloud and air-gapped or intermittently connected contexts
- Support ATO processes through automated evidence generation, documentation as code, and direct collaboration with the security team
- Establish and promote standards for pipeline design, container security, secrets management, and deployment consistency
- Contribute to feature development when team capacity requires, applying security-first development practices to application code
- Maintain operational documentation including runbooks, deployment guides, and architecture diagrams as version-controlled artifacts
- BS degree and 4+ years of professional DevSecOps or DevOps engineering experience
- Hands-on experience designing and maintaining CI/CD pipelines using GitLab CI; experience with additional pipeline tools a plus
- Experience with Kubernetes administration and hardening in DoD or compliance-driven environments — RKE2 or K3S experience strongly preferred
- Experience implementing DISA STIG compliance in containerized and Linux environments (RHEL or Rocky Linux)
- Proficiency with Infrastructure as Code tooling, particularly Terraform
- Experience with Helm chart authoring and Kubernetes deployment management
- Experience with automated security scanning, SBOM generation, and CVE triage and remediation
- Scripting proficiency in Python or Bash for pipeline and operational automation
- Demonstrated use of AI tooling to accelerate engineering workflows
- Background contributing to application feature development alongside infrastructure work
- Ability to operate independently and manage workload across competing priorities in a small, fast-moving team
- Must possess and maintain an active Secret security clearance or above
- Please note that pursuant to a government contract, this specific position requires U.S. citizenship status.
Preferred Qualifications:
- Experience operating in air-gapped or disconnected network environments
- Experience supporting ATO through automation, documentation, and technical leadership
- Active Security+ certification or equivalent IAT Level II certification
- Experience with secrets management tooling such as Vault, Sealed Secrets, or SOPS
- Familiarity with observability and monitoring tools such as Prometheus or Grafana
- Certified Kubernetes Administrator (CKA) or willingness to obtain upon onboarding
- Experience applying “as code” approaches beyond infrastructure (e.g., configuration-as-code, policy-as-code, workflows-as-code, documentation-as-code)
What is Important to Us:
- You are an excellent communicator in writing and speaking.
- You have the ability to work independently but also value teamwork.
- Your problem-solving skills are excellent.
- You are looking for a job where performance appraisals occur regularly, and you look forward to advancing your career.
- You seek a community of virtue-centered co-workers and clients.
What we offer you: As part of the VSO company, you will be part of a virtue-centered team who value their work and teammates. We provide ongoing learning and development opportunities to foster continuous growth.
More About VSO: VSO is a hybrid cloud and managed services consulting firm. Much of VSO’s success can be attributed to our deep partnerships with IT services industry leaders such as AWS, IBM, Microsoft and others. VSO leverages numerous other partner relationships so as to provide our customers with optimal support. Additionally, we take pride in taking care of our employees. We offer a wide variety of benefits for eligible employees related to health, retirement, professional development, and more! For more information, please visit our website at https://vso-inc.com/careers