Cybersecurity Engineer - DevSecOps

Jobgether — United States · Posted ~3 hours ago

Mid Full-time Remote

Skills

DevSecOps Application security CI/CD security Container security Vulnerability management Security assessment Secure software development Compliance Risk management Security controls CI/CD Containers

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A fully remote cybersecurity engineering opportunity supporting secure software development and delivery in a highly regulated environment. You will integrate security throughout the development lifecycle, assess application and container risks, secure CI/CD pipelines, manage vulnerabilities, and collaborate with engineering teams on remediation and release requirements.

Highlights

Fully remote cybersecurity engineering role focused on secure software delivery, application and container security, vulnerability management, compliance, and collaboration across engineering and development teams.

Description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cybersecurity Engineer – DevSecOps based in the United States. This is a fully remote cybersecurity engineering opportunity supporting software assurance and secure development within a Department of Defense and Department of the Navy environment. The role focuses on integrating cybersecurity throughout the software development and delivery lifecycle, from code development through deployment. You will work across application security, CI/CD pipeline security, container security, vulnerability management, and compliance. The position combines hands-on security assessment with collaboration across development, platform, engineering, and program teams. You will help strengthen secure software delivery by reviewing security controls, vulnerability findings, remediation activities, and release requirements. The role also involves supporting Risk Management Framework activities and translating DoD cybersecurity requirements into practical engineering solutions. Success requires strong DevSecOps expertise, knowledge of federal security standards, and the ability to operate effectively in a mission-focused technical environment. Accountabilities Conduct code and container vulnerability assessments using approved DoD vulnerability scanning tools, DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and applicable software assurance tools. Assess operating system security configurations against applicable DISA STIGs, SRGs, and cybersecurity requirements. Perform cybersecurity assessments, security audits, and risk analyses to identify vulnerabilities, security weaknesses, and compliance gaps. Apply Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies throughout the software development lifecycle. Integrate and assess cybersecurity policies and controls within CI/CD pipelines to support secure software delivery. Serve as a GitLab security reviewer and approver for merge requests, evaluating scan results and confirming that findings are remediated or appropriately documented before release. Review GitLab SAST, dependency, secret detection, and container scanning results and coordinate remediation with development teams. Track cybersecurity findings through closure and ensure appropriate risk-management processes are followed for unresolved issues. Review changes to GitLab security policies, pipeline controls, and protected branch settings to ensure required security checks and approvals remain enforced. Provide cybersecurity oversight for containerized workloads using NeuVector, including vulnerability findings, admission control decisions, and runtime security alerts. Collaborate with application and platform teams to investigate NeuVector findings, refine security policies, and document remediation or accepted risks. Ensure security provisions within system acquisition and program documentation address identified cybersecurity requirements. Provide cybersecurity guidance and support the development of mitigation strategies for DoD information systems. Prepare Risk Management Framework (RMF) artifacts and Memoranda of Agreement (MoAs) supporting system interfaces and networking implementations. Identify and evaluate Common Criteria and National Information Assurance Partnership (NIAP)-certified technologies when applicable. Evaluate cybersecurity products and technologies to determine alignment with applicable DoD and DoN requirements. Collaborate with engineering, development, platform, and program teams throughout the software lifecycle to address security requirements and manage cybersecurity risks. Support business development activities as needed, including technical interviews, technical documentation, proposal writing, and proposal review activities. Requirements Active Secret security clearance required. Bachelor’s degree with 8 years of relevant experience, or high school diploma/equivalent with 13 years of relevant experience. Experience working within the DoD Risk Management Framework (RMF) and familiarity with DoDI 8510.01. DoD 8570.01-M Information Assurance Manager (IAM) Level II certification, such as CISSP, GSLC, or CISM. Strong knowledge of DoD cybersecurity requirements, including DISA STIGs and SRGs. Experience with software security testing methodologies, including SAST and DAST. Demonstrated experience supporting cybersecurity within CI/CD pipelines or DevSecOps environments. Experience with GitLab security tools and processes, including reviewing security scan results and coordinating vulnerability remediation. Experience with container security and vulnerability management is preferred. Proficiency with GitLab, NeuVector, and Sonatype is preferred. Experience supporting cybersecurity initiatives within a DoD or Department of the Navy environment is preferred. Experience with the Navy’s Rapid Assess and Incorporate Software Engineering (RAISE) methodology and RAISE Platform of Choice (RPOC) is advantageous. Experience evaluating Common Criteria and NIAP-certified technologies is preferred. Experience developing or supporting RMF artifacts, security documentation, and cybersecurity mitigation strategies is advantageous. Strong analytical, problem-solving, documentation, and communication skills. Ability to collaborate effectively with technical teams, security stakeholders, program leadership, and system owners. Ability to work independently in a fully remote environment while maintaining strong attention to detail and compliance. Candidates located in or near major U.S. Navy installations are preferred, particularly in the New Orleans, Orlando, and Washington, DC metropolitan areas. Candidates near other major Navy facilities may also be considered. Comfortable working for prolonged periods at a desk and on a computer. Able to lift approximately 10–15 pounds when required. Benefits Annual compensation range of $125,000–$135,000, with final compensation determined by relevant education, experience, knowledge, skills, abilities, and other applicable factors. Fully remote work arrangement. Opportunity to support cybersecurity and secure software delivery within a DoD/DoN mission environment. Hands-on exposure to DevSecOps, application security, CI/CD security, container security, vulnerability management, and cybersecurity compliance. Opportunity to work with technologies and tools including GitLab, NeuVector, Sonatype, SAST, DAST, and container security platforms. Exposure to Risk Management Framework processes and federal cybersecurity standards. Opportunity to collaborate with engineering, development, platform, and program professionals on mission-focused initiatives. Potential involvement in technical business development, proposal development, and strategic growth activities. Professional development opportunities through exposure to evolving cybersecurity technologies and methodologies. How Jobgether Works We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.