
DevSecOps Engineer
CHAOS Industries8 hours ago
Washington, DC, USAMid Level / Senior
H1B sponsor
Base Salary
$110k - $160k/yr
Responsibilities
- Design and maintain secure CI/CD pipelines using GitHub Actions, GitLab CI, Jenkins, or equivalent tools.
- Automate STIG/SRG validation, vulnerability scanning, compliance controls, and policy-as-code enforcement.
- Identify, triage, and remediate application security vulnerabilities while promoting secure coding, threat modeling, and developer security training.
- Manage container security, including image hardening, runtime protection, Kubernetes security configurations, and registry scanning.
- Maintain secure infrastructure-as-code using Terraform, CloudFormation, and Ansible, including least-privilege, secrets management, and configuration compliance.
- Automate RMF/ATO evidence collection, compliance reporting, and continuous monitoring for classified and CUI environments.
- Monitor security telemetry, pipeline health, and vulnerability metrics and produce remediation backlogs and trend reports.
- Coordinate DevSecOps practices with ISSM/ISSO teams and administrators to meet authorization boundary, CMMC, and DFARS requirements.
- Evaluate DevSecOps tooling and create documentation, runbooks, and playbooks for security automation.
- Travel up to 15% within the continental United States for site integrations, customer engagements, and security reviews.
Requirements
- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field, or equivalent experience.
- 4–7 years of experience in DevOps, software engineering, or cybersecurity with hands-on CI/CD and cloud security tooling integration.
- Proficiency in at least one of Python, Bash, Go, or an equivalent scripting or programming language.
- Production experience securing Docker and Kubernetes environments, including image scanning and runtime protection.
- Working knowledge of AWS GovCloud or Azure Government security, including IAM, network security groups, monitoring services, and secrets management.
- Familiarity with SAST, DAST, and SCA tools such as SonarQube, Checkmarx, Snyk, OWASP ZAP, or Black Duck.
- Eligibility for a security clearance.
- Active TS clearance preferred.
- Preferred experience includes NIST RMF/ATO processes, CMMC Level 2/3, DFARS 252.204-7012, GitOps, policy-as-code, SBOM generation, artifact signing, dependency provenance, classified or air-gapped environments, and relevant certifications such as Security+ or AWS Security Specialty.
Benefits
- Medical, dental, and vision benefits are 100% paid by the company.
- 401(k) with a 50% company match up to 6% of pay, plus FSA, HSA, and life insurance.
- Free daily lunch, no-meeting Fridays, unlimited PTO, and a casual dress code.
- Pre-IPO stock option grants, relocation assistance, and annual bonuses planned for the future.
- The role includes up to 15% CONUS travel and supports classified and unclassified work environments.
Tech Stack
About CHAOS Industries
CHAOS Industries builds networked sensing, communications, and real-time software systems for defense, government security, commercial aviation, and critical infrastructure operators. It sells integrated hardware–software platforms and related services to government and industrial customers. Founded in 2022 and headquartered in Los Angeles, the privately held company also maintains offices in Washington, D.C., San Francisco, San Diego, Seattle, and London, and its products are designed for fielded, time-critical operations.