Ernst and Young

Government and Infrastructure - Cybersecurity - DevSecOps Engineer

Ernst and Young
Apply
1 day ago
McLean, VA, USAMid Level
H1B sponsor

Base Salary

$83k - $155k/yr

Responsibilities

  • Assess application delivery toolchains, security maturity, vulnerabilities, dependencies, SBOM availability, secrets handling, authentication patterns, and POA&Ms.
  • Design, build, and maintain secure CI/CD pipelines with application security testing, software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection, and quality gates.
  • Implement policy-as-code and automated evidence collection for continuous Authorization to Operate and NIST SP 800-53 traceability.
  • Harden container images and environments against DISA STIGs or CIS Benchmarks.
  • Define governance gates for AI-assisted development, including provenance, human review, and traceability of AI-generated code.
  • Create reusable DevSecOps patterns and pipeline templates, report DORA and vulnerability-aging metrics, and support vulnerability triage and remediation guidance.

Requirements

  • Bachelor's degree in computer science, software engineering, information systems, computer engineering, or a related field, or equivalent practical experience.
  • At least 2 years of experience in DevOps, software engineering, or security engineering.
  • Hands-on CI/CD pipeline engineering with Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
  • Experience with at least one application security scanning tool such as Fortify, Checkmarx, SonarQube, Snyk, Trivy, or OWASP ZAP.
  • Working knowledge of containers and Infrastructure-as-Code, plus scripting in Python, PowerShell, or Bash.
  • Understanding of the NIST Risk Management Framework, NIST SP 800-53, and secure software development lifecycle practices.
  • Ability to obtain and maintain a secret-level clearance.
  • Preferred qualifications include continuous ATO or FedRAMP experience, POA&M management, Kubernetes security, policy engines, SBOM tooling, and relevant security or Kubernetes certifications.
  • Must be comfortable working in person as needed in the Washington, DC area and willing to travel 20–30% or more.

Benefits

  • Base salary ranges from $82,500 to $136,000 in other US locations, $99,100 to $148,500 in specified metropolitan and regional areas, and $103,100 to $154,600 in Bay Area California offices.
  • Medical and dental coverage, pension and 401(k) plans, and paid time off are provided.
  • Benefits include flexible vacation, EY paid holidays, winter and summer breaks, personal and family care leave, and other leaves of absence.
  • Work may occur at client, EY, or contractor sites, with in-person work as needed and possible travel beyond the assigned work location.

Tech Stack

AnsibleBashDatadogDockerGitHub ActionsGitLab CI/CDJenkinsKubernetesPowerShellPythonSonarQubeTerraform

Categories

Ernst and Young

About Ernst and Young

10,000+ employees

Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.

Contact me