Cleared2Hire

DevSecOps Engineer

Government Contractor · San Antonio, TX
Clearance: ts_sci hybrid 4+ yrs

Supporting Department of Defense missions from San Antonio, this DevSecOps Engineer owns the full software delivery pipeline — building, hardening, and maintaining CI/CD workflows that move code from development to production without sacrificing security or compliance. Day to day, the role involves designing and managing containerized environments with Kubernetes, enforcing container security policies, and writing Terraform configurations to provision and manage cloud infrastructure as code. Python scripting ties automation together across scanning, testing, and deployment stages, ensuring vulnerabilities are caught early and remediated before they reach operational environments. The engineer works closely with development and operations teams to embed security controls at every phase of the pipeline, supports ATO processes, and contributes to continuous monitoring practices aligned with DoD standards. This is a hybrid position requiring an active Top Secret/SCI clearance and at least four years of hands-on experience in DevSecOps or a closely related discipline. Candidates who thrive here are equally comfortable writing infrastructure code and engaging with security and compliance stakeholders to keep mission-critical systems running securely and reliably.

What you'll do

- Design, build, and maintain CI/CD pipelines that integrate automated security scanning, static code analysis, and compliance checks at each stage of the software delivery lifecycle

- Deploy and manage containerized applications on Kubernetes clusters operating in classified and hybrid cloud environments, enforcing pod security policies and network segmentation

- Author and maintain Terraform modules to provision and configure DoD cloud infrastructure in a consistent, auditable, and policy-compliant manner

- Develop Python scripts and automation tooling to streamline vulnerability remediation workflows, secrets management, and operational monitoring tasks

- Apply and validate STIG configurations and RMF controls across pipeline tooling, container images, and infrastructure components to support ATO processes

- Monitor pipeline health, container runtime security events, and infrastructure drift, responding to anomalies and driving root-cause resolution

- Collaborate with software engineers, cybersecurity teams, and platform architects to evaluate emerging DevSecOps tooling and continuously improve security posture across the delivery platform

Required skills

View this role & get matched on Cleared2Hire