
Government and Infrastructure - Cybersecurity - DevSecOps Senior Engineer
Ernst and Young1 day ago
McLean, VA, USAMid Level / Senior
H1B sponsor
Base Salary
$105k - $219k/yr
Responsibilities
- Assess application delivery toolchains, release processes, security posture, vulnerabilities, dependencies, SBOM availability, secrets handling, authentication patterns, and POA&Ms.
- Design, build, and maintain secure CI/CD pipelines with SAST/DAST, software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection, and quality gates.
- Implement policy-as-code and automated evidence collection supporting continuous Authorization to Operate and NIST SP 800-53 control traceability.
- Harden container images and environments against DISA STIGs and CIS Benchmarks.
- Define governance gates for AI-assisted development, including provenance, human review, and traceability of AI-generated code.
- Create reusable DevSecOps patterns and pipeline templates and report delivery and security metrics.
- Support vulnerability triage, remediation guidance, authorization reviews, and collaboration with client cybersecurity stakeholders.
- Own DevSecOps architecture and toolchain standards, lead security-posture assessment methodology, and ensure consistent scoring.
- Serve as the primary security engineering contact for clients and mentor the Staff DevSecOps engineer.
Requirements
- Bachelor's degree in computer science, software engineering, information systems, computer engineering, or a related field, or equivalent practical experience.
- 3–6+ years of experience in DevOps, software engineering, or security engineering.
- Hands-on CI/CD pipeline engineering experience with Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
- Experience with at least one application security scanning tool such as Fortify, Checkmarx, SonarQube, Snyk, Trivy, or OWASP ZAP.
- Working knowledge of containers and Infrastructure-as-Code.
- Scripting experience in Python, PowerShell, or Bash.
- Understanding of the NIST Risk Management Framework, NIST SP 800-53, and secure software development lifecycle practices.
- Ability to obtain and maintain a Secret-level clearance.
- Ability to communicate complex security concepts to technical and non-technical audiences.
- Preferred experience includes continuous ATO or FedRAMP authorizations, POA&M management, Kubernetes security, policy engines, and SBOM tooling.
- Preferred certifications include CompTIA Security+, CISSP, CCSP, Certified Kubernetes Security Specialist, or relevant GIAC certifications.
Benefits
- The base salary range is $104,800 to $192,200 for other US locations, with higher location-specific ranges for New York City, Boston, Washington, DC Metro, Washington State, Southern California, and Bay Area California offices.
- Benefits include medical and dental coverage, pension and 401(k) plans, paid time off, paid holidays, winter and summer breaks, personal and family care leave, and other leaves of absence.
- The role may require in-person work in the Washington, DC area and work at client, EY, or contractor sites.
- Travel of 20–30% or more may be required depending on client and project needs.
Tech Stack
About Ernst and Young
Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.