
Senior DevSecOps Engineer
CACI International2 days ago
Base Salary
$99k - $207k/yr
Responsibilities
- Deploy, configure, and sustain Kubernetes-based platforms and mission applications using Big Bang, Helm, and GitOps practices.
- Develop and maintain Terraform infrastructure as code for cloud infrastructure, networking, IAM, Kubernetes resources, and platform services.
- Build, secure, and optimize CI/CD pipelines with reusable templates, automated testing, and controlled release promotion.
- Triage, remediate, and validate infrastructure, container, and application security findings according to vulnerability-management SLAs.
- Implement hardened Kubernetes and cloud configuration baselines aligned with DISA STIGs, NIST 800-53, RMF, and organizational security requirements.
- Manage Kubernetes security controls including RBAC, network policies, pod security standards, admission controls, secrets management, and secure ingress and egress.
- Maintain GitOps workflows with Git as the authoritative source and keep deployed environments aligned with approved code.
- Monitor CI/CD platforms, runners, deployments, and Kubernetes workloads while troubleshooting build, deployment, performance, and availability issues.
- Develop automated patching, configuration-management, and compliance-validation processes.
- Produce security and operational documentation, scan evidence, remediation plans, architecture diagrams, and POA&M updates.
- Support RMF and ATO lifecycle activities by collecting control evidence, addressing assessment findings, and maintaining continuous-monitoring artifacts.
Requirements
- Active Secret clearance is required.
- At least seven years of relevant professional experience and a related degree are required.
- Strong experience developing Terraform modules and reusable infrastructure-as-code patterns for cloud, network, and Kubernetes resources is required.
- Experience implementing GitOps workflows with Argo CD, Flux, GitLab, GitHub, or similar platforms is required.
- Three to five years of experience designing and deploying Kubernetes-based solutions is required; Big Bang experience is a plus.
- Experience with CI/CD pipelines, containerization, and secure DevSecOps practices is required.
- Strong familiarity with DISA STIGs, RMF, NIST SP 800-53, ATO processes, POA&M management, continuous monitoring, and security-compliance evidence generation is required.
- Desired qualifications include five to ten years of experience in DevSecOps, platform engineering, cloud engineering, SRE, or software delivery roles.
- Experience with CAC authentication, PIV tokens, client-side PKI certificate handling, AWS services, and automation using Python, Bash, PowerShell, or Go is preferred.
- Relevant certifications such as CKA, CKAD, CKS, HashiCorp Terraform Associate, AWS certifications, Security+, CISSP, or CCSP are preferred.
- Experience with ATO/accreditation processes, RMF, ACAS, Twistlock, Prisma Cloud, multi-tenant identity services, and microservices is preferred.
Benefits
- Full-time, regular employment with up to 10% local travel.
- Flexible time off and access to learning and development resources.
- Healthcare, wellness, financial, retirement, family-support, continuing-education, and time-off benefits.
- The position may be worked from more than one location; the listed salary range is a national average.
About CACI International
CACI International is a public government contractor that delivers enterprise IT, cybersecurity, electronic warfare, space, and intelligence solutions to U.S. defense, intelligence, and federal civilian customers. It provides systems engineering, software and data services, and mission support across C4ISR and business systems, primarily through long-term government contracts. Founded in 1962 and headquartered in Reston, Virginia, CACI trades on the NYSE under the ticker CACI.