Whitespace (inthewhitespace.com) Logo

Whitespace (inthewhitespace.com)

DevSecOps Engineer

Reposted 4 Days Ago
In-Office or Remote
Hiring Remotely in United States
Senior level
In-Office or Remote
Hiring Remotely in United States
Senior level
The Senior DevSecOps Engineer integrates security into development processes, focusing on compliance with DoD standards and automation using CI/CD pipelines.
The summary above was generated by AI

Position: DevSecOps Engineer

Location: Remote / Alexandria, VA

Clearance: Preferred US Gov Secret or above clearance (not a hard requirement)

Whitespace is dedicated to delivering innovative technological solutions that meet the highest standards of security and compliance. We are seeking a highly experienced Senior DevSecOps Engineer to join our team and play a key role in strengthening our cybersecurity posture and supporting federal compliance requirements.

We are seeking a DevSecOps Engineer with deep expertise in DoD DevSecOps Reference Architecture, secure CI/CD implementation, and Defense cloud environments (AWS GovCloud, Azure Government, DoD Cloud or Air gapped environments). The ideal candidate combines hands-on engineering capability with a strong understanding of DoD cybersecurity requirements, RMF compliance, and infrastructure automation.

The Senior DevSecOps Engineer will lead efforts to integrate security practices into our development and operations processes, with a primary focus on assisting the company in obtaining and maintaining a DoD/DoW Authorization to Operate (ATO). If you're passionate about making a difference in the world and being part of groundbreaking technology in national security, this position is for you!

This position is 100% remote! We're looking for a candidate who is a U.S. citizen and resides in the contiguous United States. You'll be a W-2 employee of GeoDelphi, Inc., and we do not accept third-party applications. This role requires less than 10% travel.


Requirements

1. Secure CI/CD and Cloud Infrastructure

  • Design, implement, and maintain secure CI/CD pipelines aligned with DoD Enterprise DevSecOps Reference Design (DSOP).
  • Automate deployment of secure environments using Terraform, Ansible, or CloudFormation for DoD or FedRAMP-compliant systems.
  • Integrate static code analysis (SAST), dynamic testing (DAST), container scanning and various security toolsets within pipelines to enforce continuous compliance.

2. Security Baselines & Compliance Integration

  • Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC).
  • Translate DoD security controls into automated enforcement and validation within development pipelines.
  • Develop scripts and tools for compliance validation (e.g., OpenSCAP, Chef InSpec, PowerSTIG).
  • Help co-develop & maintain technical documentation for RMF authorization and continuous monitoring processes.

3. Automation & Toolchain Management

  • Implement and manage DevSecOps tools such as GitLab, Jenkins, ArgoCD, Harbor, Nexus, SonarQube, Anchore, etc.
  • Automate container security and orchestrate deployments using Kubernetes (Big Bang, Iron Bank images or similar.
  • Manage secret storage, credential rotation, and logging using Vault, DoD-approved KMS, or AWS Secrets Manager.

4. Collaboration and Governance

  • Work closely with security, development, and operations teams to ensure alignment with DoD RMF, NIST SP 800-53, and/or FedRAMP.
  • Collaborate with Information System Security Officers (ISSOs), Information Systems Security Managers (ISSMs) and Security Control Assessors for ATO package development.
  • Serve as an internal primary subject matter expert in federal compliance standards and cybersecurity practices.

EXPERIENCE

  • Bachelor’s degree in Computer Science or related field (or equivalent experience).
  • 7+ years of hands-on experience with DevSecOps in AI/ML or data-intensive systems.
  • Familiarity with OpenShift or Kubernetes security hardening.
  • Knowledge of Zero Trust Architecture (ZTA) concepts.
  • Proven experience managing and driving successful ATO processes.
  • Expertise with DevSecOps tools, practices, and frameworks.
  • Strong understanding of federal security compliance standards (e.g., NIST 800-53, RMF, FedRAMP).
  • Hands-on experience with cloud environments (AWS, Azure, or GCP) and containerization (Docker, Kubernetes).
  • Strong scripting and automation skills (Python, Bash, or similar).
  • Excellent leadership, communication, and documentation abilities.
  • Active security clearance or eligibility to obtain one.

DESIRED SKILLS

  • Previous experience directly supporting government contracting or federal agencies.
  • Relevant certifications such as: Certified Kubernetes Administrator (CKA), AWS Certified Security or DevOps Engineer, HashiCorp Certified Terraform Associate

Benefits

GEODELPHI BENEFITS

  • Medical, Dental, and Vision plans
  • Unlimited PTO ⎯ Federal Holiday Paid Leave
  • 12 weeks of paid Parental Leave
  • Employer paid STD/LTD
  • Employer Paid Life Insurance
  • 401K plan and Employer Match Professional Development Assistance
  • Equity Incentive Plan

Who we are: GeoDelphi, Inc. dba Whitespace is building AI solutions for global leaders. Recognized as the most innovative company in the Geospatial Industry, Whitespace exponentially accelerates speed-to-answer with powerful analytics, high-cadence data feeds, and human expert-machine teaming. Our answers are rooted in truth data about human activity, delivering reliable decision advantage that keeps pace with world events. Whitespace is headquartered in Alexandria, Virginia. For further information, visit: http://www.inthewhitespace.com.

GeoDelphi, Inc. is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, sex, sexual orientation, pregnancy, gender identity, national origin, disability, or Veteran status.

Top Skills

Anchore
Ansible
Argocd
AWS
Azure
Bash
CloudFormation
Gitlab
Harbor
Jenkins
Kubernetes
Nexus
Python
Sonarqube
Terraform

Similar Jobs

Yesterday
In-Office or Remote
Senior level
Senior level
Healthtech • Pharmaceutical
The Senior DevSecOps Engineer will implement and maintain application security testing tools, integrate them into CI/CD pipelines, and manage secure software delivery processes for the organization.
Top Skills: Application Security TestingAzure DevopsCi/CdDastDevsecopsGithub ActionsIastJfrog ArtifactoryPythonSastScaSnyk
2 Days Ago
Remote
USA
Mid level
Mid level
Software
The Cloud DevSecOps Engineer leads the automation, security, and operation of cloud environments, focusing on CI/CD, IaC, and providing expert guidance on cloud operations and DevSecOps best practices, while collaborating with teams to enhance application delivery and maintain secure practices.
Top Skills: AnsibleAWSAzureBitbucketCi/CdCloudFormationCloudwatchDockerElkGithub ActionsGitlab CiIacJenkinsKubernetesNexusPackerPrometheusSeleniumSonarqubeSplunkTerraform
9 Days Ago
Remote
USA
90K-135K Annually
Mid level
90K-135K Annually
Mid level
Computer Vision • Software
The DevSecOps Engineer contributes to security automation, manages AWS infrastructure, develops CI/CD pipelines, and collaborates across teams to enhance security in software development.
Top Skills: Amazon BedrockArgo WorkflowsAWSAws Security HubCursorFedrampFismaGeminiGithub CopilotJenkinsKubernetesTerraform

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account