Leidos

DevSecOps Security Engineer

Leidos
Apply
1 day ago
Gaithersburg, MD, USA or Eagan, MN, USAMid Level
H1B sponsor

Base Salary

$87k - $157k/yr

Responsibilities

  • Implement and maintain automated SAST, DAST, software composition analysis, container scanning, and infrastructure-as-code scanning in CI/CD pipelines.
  • Enforce security gates, artifact signing, provenance verification, and CycloneDX/SPDX SBOM controls.
  • Remediate container vulnerabilities and harden minimal base images.
  • Implement Kubernetes pod security, network policies, RBAC, admission controls, and security context controls.
  • Secure workloads through secrets management, mutual TLS, service mesh policies, and Linux/container hardening.
  • Build policy-as-code and infrastructure guardrails using OPA/Rego, Kyverno, or equivalent tools.
  • Produce security evidence for authorization and continuous monitoring requirements.
  • Partner with platform and application teams on vulnerability triage, remediation, incident response, and root cause analysis.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field with 4+ years of relevant experience; additional experience, education, and training may substitute for the degree.
  • Hands-on experience integrating SAST, DAST, software composition analysis, and container scanning into CI/CD pipelines.
  • Experience securing Kubernetes and container environments, including pod security, network policies, RBAC, admission controls, and hardened or minimal base images.
  • Experience with vulnerability scanning and remediation using tools such as Nessus, Trivy, Grype, or Qualys.
  • Experience with secrets management and security automation using Python, Bash, or Go.
  • Experience with Git-based workflows and CI/CD tools such as GitLab CI, GitHub Actions, or Jenkins.
  • Working knowledge of NIST 800-53, automated security evidence, and AWS or Azure cloud security.
  • Understanding of network security, segmentation, and default-deny policies.
  • U.S. citizenship and the ability to obtain and maintain a Public Trust investigation are required.
  • Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the prior 5 years.
  • Preferred qualifications include Security+ CE, CySA+, DoD 8570 IAT Level II, CKA, or CKS certification.
  • Preferred experience includes SLSA, Sigstore/cosign, in-toto, FIPS 140-3, OPA/Rego, Kyverno, Terraform, CloudFormation, OpenShift, Istio, Linkerd, ArgoCD, Flux, aviation or FAA systems, and SAFe delivery.

Benefits

  • Hybrid schedule of 3 days onsite and 2 days remote for candidates within commuting distance of Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ.
  • Candidates outside the specified commuting areas may be considered for a 100% remote role.

Tech Stack

AWSAzureBashGitGitHub ActionsGitLab CI/CDGoIstioJenkinsKubernetesLinuxOpenShiftPythonTerraform

Categories

Leidos

About Leidos

10,000+ employees

Leidos builds and operates technology and engineering solutions for defense, intelligence, civil, and health agencies, including systems integration, cyber, enterprise IT, sensors, and healthcare IT. It primarily sells through government contracts and long-term programs, plus managed services and mission software. Founded in 1969 and headquartered in Reston, Virginia, Leidos is a Fortune 500 public company on the NYSE; customers include U.S. defense and intelligence agencies and civil bodies such as the FAA.

Contact me