
Senior DevSecOps Engineer
Logistics Management Institute5 days ago
Colorado Springs, CO, USASenior
Base Salary
$122k - $200k/yr
Responsibilities
- Design and maintain reusable GitLab CI/CD pipelines and templates.
- Integrate automated testing, code-quality checks, and security scanning into delivery workflows.
- Build secure workflows for scanning, signing, attesting, and publishing containers and packages to Nexus.
- Develop cross-platform release processes for packaging, signing, versioning, and artifact promotion.
- Deploy and operate Kubernetes workloads across on-premises, Azure, and AWS environments.
- Support elastic and high-performance computing workloads using Slurm and Azure CycleCloud.
- Manage dependency updates and remediate vulnerabilities across applications, containers, build systems, and infrastructure.
- Establish security policies, remediation timelines, exceptions, and release quality gates.
- Improve pipeline reliability, performance, documentation, and developer self-service capabilities.
- Partner with engineering teams to strengthen security while maintaining delivery speed.
Requirements
- Bachelor’s degree in computer science, engineering, information security, or a related field.
- Significant experience in DevOps, DevSecOps, platform engineering, site reliability engineering, or release engineering.
- Advanced experience designing and operating GitLab CI/CD pipelines.
- Strong Linux and shell-scripting skills.
- Experience supporting build, test, and packaging workflows for JavaScript/TypeScript, Python, or Rust.
- Hands-on experience with automated security scanning, vulnerability management, and CI/CD quality gates.
- Experience building, scanning, signing, and publishing OCI container images.
- Experience with artifact repositories such as Sonatype Nexus Repository.
- Strong Kubernetes experience and familiarity with Azure or AWS.
- Working knowledge of infrastructure as code and configuration management.
- Experience creating releases for Linux, Windows, or macOS.
- Strong troubleshooting, documentation, communication, and cross-team collaboration skills.
- Preferred experience with Slurm, Azure CycleCloud, HPC, or compute-intensive workloads.
- Preferred familiarity with Helm, Kustomize, Terraform, Ansible, SBOMs, artifact provenance, SLSA, Sigstore/Cosign, code-signing systems, dependency automation, self-hosted GitLab runners, observability, or incident response.
- Knowledge of OWASP, CWE, CVE, CVSS, CIS benchmarks, NIST guidance, and secure SDLC practices is preferred.
- Relevant cloud, Kubernetes, security, or GitLab certifications are preferred.
Tech Stack
AnsibleAWSAzureCypressGitLab CI/CDHelmJavaScriptKubernetesLinuxmacOSpytestPythonRustSonarQubeTerraformTypeScriptWindows
About Logistics Management Institute
Logistics Management Institute (LMI) provides consulting, software development, and analytics services to U.S. federal agencies, with strengths in supply chain, digital engineering, AI, and modeling and simulation. It builds and sustains government systems—such as Army acquisition and contract-writing platforms—while delivering data-driven modernization and program support across defense, space, healthcare, and energy. Founded in 1961 and headquartered in Tysons, Virginia, LMI operates as a privately held contractor to the public sector.