DevSecOps Security Engineer

🏢 General Dynamics Information Technology · all General Dynamics Information Technology jobs
📍 United States
💰 USD 191,250 - 258,750 / annual
📅 Posted 2026-08-20 · via Himalayas
🏷 DevSecOps-Engineer,Security-Engineer,Cloud-Security-Engineer,DevOps-Engineer,Cybersecurity-Engineer,DevOps-Security-Engineer,Security-DevOps-Engineer,Senior-DevSecOps-Engineer,Secure-DevOps-Engineer,Lead-DevSecOps-Engineer,Cloud-DevSecOps-Engineer,DevSecOps-Engineering
Apply on original site ↗

Type of Requisition:
Regular
Clearance Level Must Currently Possess:
None
Clearance Level Must Be Able to Obtain:
None Public Trust/Other Required:
BI Full 6C (T4)
Job Family:
Cyber and IT Risk Management Job Qualifications:
Skills:
AWS Cloud Computing, CI/CD, DevSecOps Certifications:
None Experience:
8 + years of related experience US Citizenship Required:
Yes
Job Description:
DevSecOps Security Engineer

Help us simplify the complex as a DevSecOps Security Engineer at GDIT, where we tailor advanced cloud security solutions to critical client missions. In this role, your priority will be engineering automated, secure compliance and vulnerability-management workflows for our program, while we focus on supporting your professional growth.

Our work on the AED program depends on a senior security engineer who has managed the security portion of a DevSecOps pipeline operating under a continuous ATO (cATO). You’ll leverage a modern stack, including AWS GovCloud security services, Terraform, and CI/CD pipeline tooling, to shift our security posture from reactive to proactive across a highly secure, automated environment.

HOW A DEVSECOPS SECURITY ENGINEER WILL MAKE AN IMPACT:

- Architect and automate security workflows across our CI/CD pipeline and compliance operations, reducing manual effort in vulnerability scan analysis, security inventory auditing, and continuous monitoring reporting.

- Partner with development and platform teams to integrate, automate, and monitor security tool components (scan ingestion, finding triage, evidence generation) within automated pipelines.

- Build automation for compliance and ATO artifacts, including continuous monitoring reports, SPIAs, and control evidence mapping against NIST 800-53 / 800-171.

- Perform automated inventory delta analysis and drift detection across cloud accounts to maintain an accurate, auditable security posture.

- Champion DevSecOps culture by mentoring junior/mid-level engineers, educating teams on modern security tooling, and resolving complex configuration or performance issues.

- Leverage Generative AI engineering tools (such as Claude, Gemini, Copilot) to accelerate the development of security automation, compliance reporting, and Infrastructure as Code (IaC) scanning workflows.

- Define guidelines and standards for securing AWS Cloud and container environments, implementing advanced solutions for system security, logging, and audit correlation.

- Drive engineering excellence by guiding the preparation of comprehensive technical documentation, processes, and procedures.

WHAT YOU’LL NEED TO SUCCEED:
Technical Expertise:

-
Continuous ATO Pipeline Security (Required): Direct, hands-on experience managing the security portion of a DevSecOps pipeline in a continuous ATO (cATO) environment. Candidates must have owned automated security gates, control evidence, and compliance posture within a live continuous-authorization pipeline, not point-in-time ATO or general DevOps exposure.

-
Education & Experience: BA/BS Degree and 8+ years of relevant experience (or an equivalent combination of education and experience).

-
Compliance Automation: Hands-on automation of compliance workflows: scan ingestion, finding triage, evidence generation, and continuous monitoring reporting.

-
Cloud Security Tooling: Familiarity with AWS GovCloud security services (Security Hub, Inspector, GuardDuty, Config) and centralizing/correlating their findings, along with scanning and monitoring tooling such as Qualys, CrowdStrike, Nexus/Sonatype, SonarQube, and Datadog.

-
Infrastructure as Code Security: Experience building and scanning IaC (Terraform, CloudFormation) for security and compliance.

-
Standards & Frameworks: Background in NIST 800-53 or 800-171 control implementation and evidence mapping; familiarity with FedRAMP and IAM.

-
Scripting/Development: Strong proficiency in automation scripting (Python, Bash, or similar) for building internal security t

← All remote jobs