
DevSecOps Engineer (DoD)
RapidFort, Inc.Base Salary
$140k - $175k/yr
Responsibilities
- Design and maintain Kubernetes infrastructure, including cluster provisioning, RBAC, network policies, and workload management.
- Package and deploy applications with Helm and manage chart repositories and release lifecycles.
- Implement policy controls with Istio, OPA Gatekeeper, Kyverno, and Kubernetes admission controllers.
- Build and maintain CI/CD pipelines with automated security scanning and compliance gates.
- Deploy and operate workloads on AWS GovCloud and Azure Government with high availability, disaster recovery, and cross-region compliance.
- Manage and harden container images and integrate approved registries such as Iron Bank and Platform One.
- Configure observability platforms including Prometheus, Grafana, and Datadog, with alerting, dashboards, and SLO frameworks.
- Support ATO processes, STIG/CIS scanning, System Security Plans, and related compliance documentation.
- Design offline image transfer, registry mirroring, and artifact management solutions for air-gapped and classified environments.
- Collaborate with development, security, program, government platform, and managed service provider teams to sustain approved DoD software factories.
Requirements
- At least four years of hands-on Kubernetes experience in production environments.
- Experience deploying and managing applications with Helm across multiple environments.
- Working knowledge of Istio, OPA Gatekeeper, Kyverno, or equivalent Kubernetes policy and service mesh tooling.
- Experience with GitLab CI, GitHub Actions, Jenkins, or an equivalent CI/CD platform.
- Hands-on experience with AWS and/or Azure, including IAM, networking, storage, and managed Kubernetes services such as EKS or AKS.
- Experience building, scanning, hardening, and distributing container images through OCI registries.
- Familiarity with Prometheus, Grafana, and/or Datadog for monitoring and observability.
- Experience with SSO and identity federation, with familiarity with Keycloak or equivalent OIDC/SAML providers.
- Active Department of War security clearance at the Secret level or higher is required.
- U.S. citizenship and eligibility for a federal background investigation are required.
- Preferred experience includes Iron Bank, Registry1, Platform One, Big Bang, GitLab Ultimate security features, military branch programs, software supply chain security, cATO or continuous authorization, and DoD compliance frameworks such as NIST 800-53, STIGs, RMF, and FedRAMP.
- CKA, CKS, AWS GovCloud, or equivalent certifications are preferred.
Benefits
- Full-time remote position
- Benefits and equity are offered where applicable
- Opportunity to support Department of War programs, classified systems, and air-gapped environments
Tech Stack
Categories
About RapidFort, Inc.
RapidFort, Inc. is a leading software supply chain security company that provides an innovative platform designed to automatically secure container applications and accelerate compliance processes. The company's comprehensive solution addresses critical cybersecurity challenges by removing up to 95% of Common Vulnerabilities and Exposures (CVEs) from container images without requiring any code changes. RapidFort's unified platform offers three core capabilities: curated near-zero CVE container images with FIPS 140-3 validation and daily builds, DevTime protection tools that generate Software Bill of Materials (SBOM) and Real Bill of Materials (RBOM) for vulnerability remediation, and RunTime protection that automatically secures unused components and reduces software attack surfaces by 60-90%. The platform serves organizations seeking to reduce development costs by 10%, accelerate software releases by 2-3 weeks, and achieve faster compliance with FedRAMP, cATO, CMMC, and SOC2 standards. RapidFort's solution integrates seamlessly with existing development workflows and technology stacks, consuming less than 1% system overhead while providing comprehensive security hardening. Trusted by government agencies including the U.S. Air Force and Space Force, as well as enterprise customers, RapidFort addresses the growing challenge of software supply chain security by eliminating "zombie code" – the 50-90% of unused software components that create unnecessary security risks. The company's approach enables organizations to spend more time building products rather than maintaining and updating dormant code, ultimately strengthening security posture while improving operational efficiency.