Lead DevSecOps & Compliance Engineer
hace 15 días
Arlington
Job Description POSITION DESCRIPTION: The Lead DevSecOps & Compliance Engineer is a senior technical leader responsible for embedding security, auditability, and compliance automation across the full software delivery lifecycle. This role ensures the platform is secure by design, continuously compliant, and aligned with Zero Trust principles. Working at the intersection of cybersecurity, DevOps, and compliance engineering, this engineer defines and enforces platform-wide security policies, hardens build and deployment processes, and maintains traceability of technical controls to federal mandates such as FIAR, NDAA, FedRAMP, and Zero Trust Architecture. This role operates as a core member of the technical leadership team, collaborating with cloud platform engineers, backend developers, AI/ML teams, and project leadership to safeguard every layer of the stack—from infrastructure to middleware to deployment artifacts. The ideal candidate brings deep hands-on experience implementing and maintaining Azure infrastructure (especially AKS and Mission Landing Zones), security automation, policy-as-code, and compliance in a federal environment. U.S. Citizenship is required and the candidate must be able to obtain and maintain a U.S. Secret security clearance. This is a hybrid, full-time position with an onsite requirement of 3 days a week at our Crystal City HQ. Key Responsibilities: Azure Platform Security Engineering (AKS + MLZ) • Design, implement, and maintain secure Azure infrastructure in production, including AKS and Mission Landing Zones (MLZs)., • Operate AKS securely (upgrades, node pools, ingress, RBAC/Entra ID integration, network policies, and observability)., • Integrate and enforce security scanning within CI/CD pipelines (SAST, DAST, SCA, SBOM generation)., • Implement gated releases and release verification, including artifact integrity and provenance controls (e.g., signing/attestation where applicable)., • Harden containers and Kubernetes workloads using least privilege and defense-in-depth (Pod Security Standards, admission controls, secure baselines)., • Define runtime policy enforcement using tools such as OPA/Gatekeeper and Azure-native controls (Azure Policy for Kubernetes where applicable)., • Establish and maintain secure secrets management using Azure Key Vault (including access policies/RBAC, rotation patterns, and operational safeguards)., • Map technical controls to federal frameworks (e.g., NIST 800-53, FedRAMP, FIAR/NDAA as applicable) and drive continuous evidence generation., • Define and enforce policy-as-code and compliance-as-code standards using Terraform and/or Azure-native policy tooling., • Implement vulnerability detection and remediation workflows (CVE/CVSS triage, prioritization, SLA tracking, and reporting)., • Centralize logging and monitoring using Azure Monitor / Log Analytics, including retention, alerting, and traceability for audit evidence., • Collaborate with the Technical Lead (Enterprise Technical Authority) and Program/Project Manager to define security priorities, operational standards, and delivery guardrails. Critical Skills (Must-Have) • Demonstrated experience implementing and maintaining Azure infrastructure in production, including AKS and Mission Landing Zones (MLZs)., • Strong AKS operations experience: upgrades, node pools, ingress, RBAC/Entra ID, policy enforcement, and observability., • MLZ/landing zone governance: management groups, Azure Policy, hub-and-spoke networking, identity integration, and private networking patterns., • Experience securing and operating Azure Database for PostgreSQL Flexible Server (networking/private access, backups/restore, HA, and hardening)., • 7+ years of experience in DevSecOps, cloud security, infrastructure security, or platform security for production systems., • Hands-on experience with CI/CD pipeline security (e.g., GitHub Actions, GitLab CI/CD, Bitbucket Pipelines) and automated security testing (SAST/DAST/SCA/SBOM)., • Hands-on experience with Azure security foundations, including: Entra ID, VNets/NSGs, Private Link, Key Vault, and Azure Monitor/Log Analytics., • Proven experience mapping technical controls to federal compliance frameworks (e.g., NIST 800-53, FedRAMP; plus FIAR/NDAA where applicable)., • Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or a related technical field. Security Engineering & Compliance Tooling • Policy-as-code frameworks and admission controls (OPA/Gatekeeper, Azure Policy for Kubernetes, Sentinel)., • Secure software supply chain tooling (e.g.,Sigstore/Cosign, in-toto, provenance/attestation)., • Cloud-native security tooling and posture management:, • Azure: Defender for Cloud, Azure Policy, Azure Monitor, • Experience operating secure AWS infrastructure and workloads, including:, • ECS, CloudWatch, IAM, VPC, Secrets Manager (and related security controls/patterns), • Infrastructure-as-code beyond Terraform (Azure Bicep) and secure module patterns., • Experience with AI/ML security practices or secure metadata handling for model pipelines. In addition to competitive salaries and opportunities for professional development and advancement, our employees enjoy a comprehensive range of benefits. To keep pace with the changing needs of our employees, we continually evaluate benefit plans. • Paid time off, • 10 paid holidays, • Medical insurance, • Dental insurance, • Vision insurance, • Legal assistance, • Company-paid life insurance and AD&D, • Company-paid long term and short-term disability insurance, • Tuition reimbursement, • 401(k) plan with company contribution, • Continuing Education Opportunities