DevSecOps Engineer, AWS

Opendatajobs — United States · Posted ~12 hours ago

Full-time

Skills

AWS CI/CD DevSecOps Infrastructure as Code security automation Risk Management Framework continuous monitoring RMF

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Own the secure delivery path for critical systems by building CI/CD pipelines with integrated security controls, reproducible infrastructure, and automation for monitoring and compliance evidence. You’ll work across cloud and on-premises environments and have substantial ownership over reliable, secure delivery practices.

Highlights

High-ownership role focused on secure software delivery for mission-critical systems, combining automation, cloud infrastructure, security engineering, monitoring, and compliance work.

Description

Peregrine Advisors is a firm founded on a simple conviction: the best solutions come from the people closest to the problem, given real ownership and the tools to deliver. We are a data and technology innovation hub and a Benefit Corporation working at the center of the federal government's mission to deliver for client stakeholders and the US public, looking for highly motivated contributors who thrive when trusted to own a hard problem and equipped to deliver the solution. Your first assignment Your first assignment is to own a secure delivery path for federal systems: continuous integration and delivery (CI/CD) pipelines with security gates built in, infrastructure-as-code that makes environments reproducible, and the automation, monitoring, and evidence that support Risk Management Framework (RMF) authorization and continuous monitoring. You will work in Amazon Web Services (AWS) or in a client-managed, on-premises environment, and what you build will carry real systems into production. The work is real, hard, and it matters. It is also where you start, not the shape of your career here: we hire people, not seats, and we move our best to where the hardest problems are. What You'll Build CI/CD pipelines with security built into the path: automated security testing (SAST, DAST, SCA), policy-as-code checks, and controlled promotion, so a release passes review because the pipeline enforced the required controls and produced evidence for reviewThe infrastructure under them, as code: reproducible environments with containerization and container-image scanning, least-privilege access, secrets management, and encryption as defaults rather than add-onsThe operational fabric: monitoring, logging, and vulnerability scanning; progressive delivery and low-downtime deployment strategies, including blue/green and canary deployments, with automated health checks and rollback; incident response; pipeline reliability and software-delivery performance metrics; and the evidence that supports an Authority to Operate (ATO) and continuous monitoringIn time, the firm itself: new capabilities, tools, and lines of business you help spin up Who you are You treat security and reliability as part of the build, not a gate at the end, because in a federal environment they cannot be an afterthought. You automate what others do by hand and you leave an audit trail behind you. You experiment, fail, learn, and repeat quickly. You would rather own an outcome than be handed a task. What You Bring Hands-on CI/CD (AWS-native or comparable), infrastructure-as-code, and containerization for deploying real systems in AWS or in a client-managed, on-premises environmentThe security craft around the pipeline: automated security testing (SAST, DAST, SCA), vulnerability scanning, secrets management, and least-privilege designThe scripting to automate what the tools do not: Python or Bash beyond pipeline configurationThe judgment to build where security and auditability are not optional What you'll need Sole United States citizenship and the ability to obtain a Public Trust determination are required for this initial engagement. This is a hybrid role based in the Washington, DC metropolitan area, and it requires commuting into DC regularly. Everything else, the years, the certifications, the specific tools, we ask in the application and get into during the interview. What We Offer A high-performing team of developers, engineers, data scientists, architects, and strategists solving complex, real-world problems, with work that runs from strategy formulation to hands-on implementation. We develop people across roles and clients, with extensive onboarding and sponsored training and professional development. And Peregrine has been a Benefit Corporation from day one: public value is built into the work itself, not bolted on afterward. Work worth your best years. What We Commit To As a Benefit Corporation, our commitment runs three ways: real, measurable value for our clients; government that works better for the public; and a team that makes everyone in it better. We hire people who want to help build the firm, not just work at it. If that is you, apply. Peregrine Advisors is an equal opportunity employer. Peregrine exclusively works with OPEN Data Jobs to recruit our team. Register with OPEN Data Jobs to be considered for this opening and future roles. Requirements 4+ years of DevSecOps or platform engineering experienceBachelor's Degree in Computer Science or related fieldHands-on CI/CD pipeline automation with security gates, AWS-native (CodePipeline, CodeBuild) or comparable (GitHub Actions, GitLab CI)Infrastructure-as-code (CloudFormation or Terraform) and containerizationAutomated security testing (SAST, DAST, SCA) and vulnerability scanningScripting in Python or BashGit-based version controlMonitoring and loggingBasic proficiency in writing, PowerPoint, and Excel Preferred Federal security experience: supporting FISMA compliance, implementing NIST SP 800-53 controls, and Authority to Operate (ATO) supportAmazon Web Services certificationKubernetesSecrets management (HashiCorp Vault, AWS Secrets Manager, or comparable)Experience applying zero trust principles: identity-centered access, least privilege, and continuous verificationSoftware supply-chain integrity practice: software bills of materials (SBOMs) and artifact signingFederal information technology experienceFamiliarity with AI-assisted developer tooling Benefits Medical, dental, and vision with the employee premium fully paid and half of dependent premiums; employer-paid life, accidental death, and short-term and long-term disability insurance; a 401(k) matched 100% up to 4% of salary, vesting immediately; unlimited paid time off; and sponsored professional certifications and continuing education.