DevSecOps Security Engineer
Gaithersburg, Maryland
Job Id:
0000175305
Job Category:
Cyber Security
Job Location:
Gaithersburg, Maryland
Security Clearance:
Public Trust or Uncleared
Business Unit:
Zachary Piper
Division:
Not Defined
Position Owner:
JD Buck
Zachary Piper Solutions is seeking a DevSecOps Security Engineer to support a company focused on developing and securing next-generation air traffic management systems through a hybrid cloud automation platform, modern DevSecOps practices, and AI-enabled engineering solutions. This position is hybrid in Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ, with the possibility of 100% remote work for qualified candidates outside commutable areas. The DevSecOps Security Engineer will be responsible for building, automating, and maintaining security controls throughout the software delivery lifecycle while ensuring compliance, reliability, and operational security within mission-critical environments. Join a team securing the technology that powers national air traffic operations and supports millions of travelers every day.
Responsibilities for the DevSecOps Security Engineer include:
- Implement and maintain automated security controls within CI/CD pipelines, including SAST, DAST, software composition analysis, container scanning, and IaC security scanning.
- Enforce security gates, artifact signing, provenance verification, and SBOM generation to ensure secure software delivery.
- Secure and harden Kubernetes and containerized environments through RBAC, network policies, admission controls, secrets management, and vulnerability remediation.
- Develop and maintain policy-as-code and infrastructure security guardrails using tools such as OPA/Rego, Kyverno, and cloud-native security solutions.
- Partner with platform, application, and DevOps teams to remediate vulnerabilities, support incident response activities, and generate security evidence for compliance and authorization requirements.
Required Qualifications for the DevSecOps Security Engineer include:
- 4+ years of experience with DevSecOps, cybersecurity engineering, cloud security, or application security.
- Hands-on experience with CI/CD security tools including SAST, DAST, software composition analysis, container scanning, and vulnerability management solutions.
- Experience securing Kubernetes environments, containerized workloads, secrets management platforms, and cloud infrastructure (AWS and/or Azure).
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent combination of education and experience).
- Ability to obtain and maintain a Public Trust clearance and meet government background investigation requirements.
Compensation for the DevSecOps Security Engineer include:
Salary Range: $87,100 - $157,450 depending on experience
Full Benefits Package: PTO, Paid Holidays, Medical, Dental, Vision, 401K, Tuition Reimbursement, Sick Leave as required by law
#LI-JB1
Keywords: DevSecOps Security Engineer, Cybersecurity Engineer, DevSecOps, CI/CD Security, Application Security, Kubernetes Security, Container Security, Docker, Kubernetes, RBAC, Network Policies, SAST, DAST, Software Composition Analysis, SCA, Vulnerability Management, Nessus, Trivy, Grype, Qualys, Cloud Security, AWS Security, Azure Security, Infrastructure as Code, IaC Security, Terraform, CloudFormation, Policy as Code, OPA, Rego, Kyverno, GitLab CI, GitHub Actions, Jenkins, HashiCorp Vault, Secrets Management, Security Automation, Python, Bash, Go, SBOM, CycloneDX, SPDX, Artifact Signing, Supply Chain Security, GitOps, ArgoCD, Flux, NIST 800-53, Public Trust Clearance, Security Engineer, Platform Security, DevOps Security, Air Traffic Management, Mission Critical Systems, AI-Enabled Engineering, Hybrid Cloud Security.