Contingent Upon Contract Award
Remote with occasional on-site support
Connected Logistics
is seeking a
DevSecOps Engineer
to support the
Cybersecurity Architecture and Engineering Services
supporting the
Department of Veterans Affairs (VA) Office of Information Security (OIS) Cybersecurity Operations Systems Engineering (COSE) program
.
The
DevSecOps Engineer
provides specialized cybersecurity and DevSecOps expertise supporting the design, development, integration, deployment, and operation of secure applications and information systems. The DevSecOps Engineer integrates security throughout the software development lifecycle (SDLC), evaluates security requirements and technology capabilities, identifies and mitigates cybersecurity risks, and develops solutions that enable secure and reliable delivery of mission-critical capabilities. The DevSecOps Engineer works with development, security, operations, and engineering teams to incorporate automated security controls, continuous monitoring, vulnerability management, and compliance activities into development and deployment processes. The position also supports technical risk analysis, including risk assessments, and provides technical direction and daily supervision to assigned staff.
Key Responsibilities
- Analyze and define cybersecurity and system security requirements for applications, platforms, infrastructure, and development environments.
- Design, develop, engineer, and implement secure solutions that address application, infrastructure, cloud, container, and DevSecOps security requirements.
- Integrate security controls and testing throughout the SDLC and CI/CD pipeline.
- Implement and support automated security testing, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), dependency scanning, container scanning, and infrastructure-as-code security scanning, as applicable.
- Evaluate security products, platforms, and tools to determine suitability for technical and mission requirements.
- Identify vulnerabilities, security deficiencies, and technical risks and coordinate remediation activities with development and operations teams.
- Perform cybersecurity risk analysis, including risk identification, assessment, prioritization, mitigation, and tracking.
- Support secure configuration, vulnerability management, continuous monitoring, and security compliance activities across development, test, staging, and production environments.
- Gather and organize technical information regarding organizational mission objectives, system requirements, existing security capabilities, architectures, products, and cybersecurity initiatives.
- Collaborate with developers, system engineers, security engineers, architects, and operations personnel to embed security into application and infrastructure engineering processes.
- Develop and maintain security-related technical documentation, engineering artifacts, procedures, implementation guidance, and risk assessment information.
- Support investigation / resolution of security findings identified through automated testing, vulnerability assessments, security reviews, or compliance activities.
- Promote consistent application of secure coding, secure configuration, least privilege, secrets management, identity and access management, and other cybersecurity engineering practices.
- Provide technical guidance, daily supervision, direction to assigned technical staff.
- Communicate cybersecurity risks, technical recommendations, remediation priorities, and implementation considerations to technical and program stakeholders.