DevSecOps Engineer (SMA 3)
Job Description:
We are looking for a highly skilled and proactive DevSecOps Engineer to join our team supporting the Congressional Budget Office (CBO) under the SENTRY Blanket Purchase Agreement (BPA). As a DevSecOps Engineer, you will integrate seamlessly with CBO's engineering team to build upon established procedures and guidelines, contributing meaningfully across Infrastructure as Code (IaC), Configuration as Code (CaC), CI/CD pipeline development, and container orchestration. You will inherit existing patterns, adhere to CBO engineering standards, and incrementally enhance capabilities within an active production environment. You will integrate security practices throughout the software delivery lifecycle (Shift-Left security) and support NIST SP 800-53 and FISMA compliance requirements.
Key Responsibilities:
- Infrastructure as Code (IaC): Maintain, extend, and improve existing Terraform and OpenTofu codebases used to provision and manage CBO's cloud and hybrid infrastructure.
- Configuration as Code (CaC): Develop and maintain Ansible playbooks and roles to automate system configuration, compliance enforcement, patch management, and application deployment.
- CI/CD Pipeline Development: Build, maintain, and improve GitHub Actions workflows to automate build, test, security scanning, and deployment processes.
- Container Management: Support containerized application delivery using Docker for image builds and Kubernetes for orchestration; manage Kubernetes manifests and Helm charts.
- Security Integration: Incorporate SAST/DAST scanning tools into pipelines; enforce CIS benchmarks and CBO security baselines; support NIST SP 800-53 and FISMA compliance requirements.
- Secrets Management: Utilize secrets management tools (e.g., HashiCorp Vault) to secure sensitive information within pipelines and infrastructure.
Required Qualifications:
- Clearance: Active Top Secret (TS) security clearance is required.
- Experience: Hands-on experience with the core DevSecOps toolchain.
- Technical Proficiency: Demonstrated hands-on experience with:
- Terraform and OpenTofu (module development, remote state management)
- Ansible (playbook and role development, dynamic inventories)
- GitHub Actions (workflow development, matrix builds, security gate integration)
- Docker and Kubernetes (image authoring, Helm charts, container security scanning)
- Security scanning tools (Trivy, Grype, Checkov, Semgrep, Gitleaks)
- Scripting: Proficiency in Python and Bash scripting.
- Version Control: Experience with Git-based workflows, branching strategies, and pull request reviews.
Desired Experience:
- Experience in federal or highly regulated environments.
- Familiarity with NIST SP 800-53, FISMA, and FedRAMP compliance.
- Experience with policy-as-code frameworks (OPA/Rego).
- Cloud platform experience (AWS).
Clearance Requirement: Active Top Secret (TS) security clearance required
Citizenship: U.S. Citizenship is required
Job Type: Full-time
Equal Opportunity Employer Statement
E-Logic, Inc. is an equal opportunity employer and is committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.