5 days ago
Base Salary
$108k - $195k/yr
Responsibilities
- Design, implement, and maintain CI/CD pipelines covering development, security scanning, compliance validation, and deployment.
- Build and maintain hardened Kubernetes environments aligned with DISA STIG requirements across cloud and restricted networks.
- Automate SBOM generation, CVE scanning, security compliance validation, and ATO evidence production.
- Drive Infrastructure as Code, GitOps, controls-as-code, and other version-controlled operational practices.
- Use AI tooling to accelerate pipeline development, vulnerability triage, compliance remediation, and documentation.
- Maintain deployment infrastructure across secure, air-gapped, and intermittently connected environments.
- Establish standards for pipeline design, container security, secrets management, and deployment consistency.
- Partner with software engineers, systems engineers, and ISSEs to embed security and compliance into development.
- Contribute to application feature development with a security-first approach when team capacity requires.
- Maintain runbooks, deployment guides, architecture diagrams, and other operational documentation as version-controlled artifacts.
Requirements
- Active Secret security clearance is required and must be maintained.
- BS degree and at least 4 years of professional DevSecOps or DevOps engineering experience, with 8 years of total relevant experience.
- Hands-on experience designing and maintaining GitLab CI pipelines; additional pipeline tools are a plus.
- Experience administering and hardening Kubernetes in DoD or compliance-driven environments; RKE2 or K3S experience is strongly preferred.
- Experience implementing DISA STIG compliance in containerized and Linux environments, including RHEL or Rocky Linux.
- Proficiency with Infrastructure as Code tools, particularly Terraform.
- Experience authoring Helm charts and managing Kubernetes deployments.
- Experience with automated security scanning, SBOM generation, and CVE triage and remediation.
- Python or Bash scripting proficiency for pipeline and operational automation.
- Demonstrated use of AI tooling to accelerate engineering workflows.
- Experience contributing to application feature development alongside infrastructure work.
- Ability to work independently and manage competing priorities in a small, fast-moving team.
- Preferred experience includes air-gapped or disconnected environments, ATO automation, technical leadership, secrets management, observability, and broader as-code practices.
- Active Security+ or equivalent IAT Level II certification is preferred; CKA certification or willingness to obtain it is also preferred.
Benefits
- Pay range is $107,900.00-$195,050.00 annually.
- The posting anticipates remaining open for at least 3 days, with a close date no earlier than 3 days after September 24, 2026.
- The role supports cloud, restricted, air-gapped, and intermittently connected deployment contexts.
Tech Stack
About Leidos
Leidos builds and operates technology and engineering solutions for defense, intelligence, civil, and health agencies, including systems integration, cyber, enterprise IT, sensors, and healthcare IT. It primarily sells through government contracts and long-term programs, plus managed services and mission software. Founded in 1969 and headquartered in Reston, Virginia, Leidos is a Fortune 500 public company on the NYSE; customers include U.S. defense and intelligence agencies and civil bodies such as the FAA.
