DevSecOps Lead

๐Ÿข Concept Plus ยท all Concept Plus jobs
๐Ÿ“ United States
๐Ÿ“… Posted 2026-08-09 ยท via Himalayas
๐Ÿท DevSecOps-Lead,Platform-Engineering,Cloud-Engineer,Security-Engineering,DevOps-Engineer,Lead-DevSecOps-Engineer,DevSecOps-Director,VP-Of-DevSecOps,Senior-DevSecOps-Engineer
Apply on original site โ†—

About Concept Plus

Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.

Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.

We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.

For more information, visit .

About the role

Concept Plus LLC is seeking an experienced DevSecOps Lead to drive the design, implementation, and continuous improvement of secure CI/CD pipelines, automated testing frameworks, and Infrastructure as Code (IaC) practices to provide common services for Oracle eBusiness applications hosted on Oracle Cloud Infrastructure (OCI) platforms. The DevSecOps Lead will embed security, quality, and automation throughout the entire service lifecycle โ€” from development through operations โ€” ensuring that all common services on the Cloud One Oracle Cloud Infrastructure (OCI) platform are delivered with speed, rigor, and compliance. This is a key leadership role requiring a minimum of 5 years of hands-on DevSecOps experience, including demonstrated proficiency with YAML, Ansible, Git, Jenkins or equivalent pipeline tooling (e.g., GitLab CI/CD), Terraform-based IaC, and Kubernetes (K8s) container orchestration, along with experience operating in a DoD or Federal security-controlled environment. An active Secret clearance and DoD 8140/8570 IAT-II or higher certification are required to start.

What you'll do

- Design, implement, and maintain secure CI/CD pipelines using Jenkins, GitLab CI/CD, or comparable enterprise tooling to automate build, test, and deployment workflows for all common services on OCI

- Develop and maintain Infrastructure as Code (IaC) using Ansible, YAML, and Terraform to automate environment provisioning, configuration management, and compliance enforcement across OCI environments

- Architect, deploy, and manage containerized workloads using Kubernetes (K8s) or OCI Container Engine (OKE), including cluster configuration, workload scheduling, secrets management, and runtime security controls

- Integrate SAST, DAST, software composition analysis (SCA), and container image scanning tools into all CI/CD pipelines to enforce security-left practices throughout the development lifecycle

- Establish and maintain a comprehensive automated test framework โ€” including unit, integration, regression, and performance testing โ€” in support of the Government's Test Automation objectives

- Enforce code quality, branching strategies, and version control governance across all development teams using Git (GitHub, GitLab, or equivalent)

- Embed DoD RMF controls and security compliance checks into CI/CD workflows to support continuous ATO and audit readiness

- Collaborate with the Cybersecurity Lead/ISSO to ensure all pipeline artifacts, container images, and deployed services meet required security scanning thresholds and DoD 8140/8570 compliance baselines

- Lead DevSecOps toolchain onboarding, training, and standards adoption across all integrated team members

- Monitor pipeline performance, test coverage metrics, and deployment frequency; report results to the Program Manager and Government stakeholders as part of recurring performance reporting

- Support the Technical Lead in aligning DevSecOps practices with the OCI platform architecture, including OCI DevOps services, OCI Ar

โ† All remote jobs