7 hours ago
San Antonio, TX, USAMid Level
Responsibilities
- Build and maintain GitLab CI, Jenkins, and other CI/CD pipelines for an enterprise with hundreds of applications.
- Develop and maintain containerized applications, source-control workflows, and build and release tooling.
- Develop infrastructure as code and configuration as code using Packer, Terraform, and Ansible.
- Automate security control implementation, validation, and evidence collection for RMF, ATO, and cATO readiness.
- Integrate and tune SAST, DAST, SCA, container scanning, secrets detection, and policy gates in delivery pipelines.
- Support security-relevant changes, security impact assessments, control validation, vulnerability management, whitelisting decisions, and pipeline compliance.
- Architect logging, monitoring, and telemetry for continuous monitoring and maintain A&A evidence in eMASS.
- Develop automated GitLab security policies to detect end-of-life images, remediate vulnerabilities, prevent unauthorized deployments, and quarantine compromised artifacts.
- Collaborate with ISSEs, software developers, value stream engineers, COT, CPT, and government stakeholders.
Requirements
- U.S. citizenship and a TS/SCI clearance or ability to obtain one are required.
- A bachelor's degree in computer science, cybersecurity, IT, software engineering, or a related field is required.
- A DoD 8140/8570 IAT Level II certification such as Security+ CE or equivalent is required.
- At least four years of relevant experience is required.
- Experience with DevSecOps, Jenkins or GitLab, enterprise CI/CD pipelines, Packer, Terraform, Ansible, Kubernetes, Docker, Helm, cloud architectures, Linux, Bash, and Python is required.
- Preferred qualifications include an advanced technical degree and CKS, CKA, AWS, CCSP, or GitLab certifications.
- Preferred experience includes Java/Spring, Python, JavaScript/Node.js, Angular, microservices, REST, JMS, AMQP, Istio, government software factories, cATO, SBOMs, artifact signing, IL4/IL5/IL6 cloud environments, and security assessment roles.
- Preferred tool experience includes GitLab security policies, Twistlock, Anchore, Defect Dojo, cosign/sigstore, and end-of-life image detection.
Benefits
- Medical insurance cost sharing for employees and dependents.
- Company-paid dental, vision, short-term disability, and long-term disability insurance for employees and dependents as applicable.
- 401(k) plan with a generous match and immediate vesting.
- Paid leave and holiday package, tuition and training reimbursement, and life and AD&D insurance.
- Competitive pay.
- Full-time on-site work in San Antonio, Texas.
Tech Stack
AngularAnsibleAWSAzureBashDockerGitLab CI/CDGoogle CloudHelmIstioJavaJavaScriptJenkinsKubernetesLinuxNode.jsPythonTerraform
About AnaVation
AnaVation provides cybersecurity, software, cloud, and data engineering services to U.S. government customers, particularly the federal intelligence community. The company builds and supports cyber collection and processing systems, SOC/incident response capabilities, and big-data and cloud infrastructure used across multiple agencies, including AWS-based environments. Founded in 2013 and headquartered in Chantilly, Virginia, AnaVation is a private partnership focused on complex government programs.
