
Cyber Security Engineer / DevSecOps Engineer
Ad Hoc LLC · United States
- Hybrid
- Full-time
- $150,000 / year
- United States
Job highlights
- Remote Cyber Security Engineer role.
- Implement and maintain secure technology solutions.
- Focus on federal government systems.
- Utilize cloud and IaC technologies.
- Support ATO and compliance requirements.
About the role
Cyber Security Engineer DevSecOps at Ad Hoc LLC
Ad Hoc is seeking a Cyber Security Engineer to support the design, implementation, and maintenance of secure technology solutions within the federal government. This remote position offers the opportunity to work on impactful projects that transform public-sector service delivery.
About Ad Hoc
Ad Hoc is a technology company dedicated to empowering organizations with scalable, impactful digital services. We utilize modern, agile methodologies to create products that meet user needs and enhance government services. Our culture is built for remote work, fostering flexibility and collaboration among top talent nationwide. We value acceptance, accountability, and humility, operating in small, inclusive teams to solve problems and deliver effective software.
The Role
As a Cyber Security Engineer, you will play a crucial role in safeguarding technology solutions. You will be responsible for designing, implementing, and maintaining security controls across cloud and on-premises environments. This includes conducting security assessments, vulnerability analysis, and risk evaluations. You will also support continuous monitoring, incident response, and the development of essential security documentation like System Security Plans (SSPs). A key aspect of this role involves assisting with Authorization to Operate (ATO) activities and ensuring ongoing compliance with federal regulations.
Key Responsibilities
- Design, implement, and maintain security controls across cloud and on-premises environments.
- Conduct security assessments, vulnerability analysis, and risk evaluations of applications, infrastructure, and systems.
- Support continuous monitoring activities, including security event analysis and incident response efforts.
- Develop and maintain security documentation, including System Security Plans (SSPs), security procedures, and risk assessments.
- Assist with Authorization to Operate (ATO) activities and ongoing compliance requirements.
- Design, implement, and maintain secure CI/CD pipelines supporting application development and infrastructure deployments.
- Integrate automated security testing into the software development lifecycle.
- Develop Infrastructure as Code (IaC) solutions using tools such as Terraform, CloudFormation, or Ansible.
- Automate security controls, compliance checks, and deployment processes.
- Support Kubernetes, Docker, and cloud-native application deployments.
- Analyze security findings and develop remediation recommendations.
- Support vulnerability management activities, including tracking, prioritization, and remediation verification.
- Participate in security audits and assessments.
- Monitor emerging threats and recommend improvements to security posture.
Basic Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
- 5+ years of experience in cybersecurity, DevSecOps, cloud security, or related disciplines.
- Experience supporting federal government contracts and federal information systems.
- Hands-on experience with cloud platforms such as AWS, Azure, or Google Cloud Platform.
- Experience building and maintaining CI/CD pipelines using tools such as GitHub Actions, GitLab CI, Jenkins, or Azure DevOps.
- Experience with container technologies including Docker and Kubernetes.
- Knowledge of Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or Ansible.
- Experience implementing automated security testing within development pipelines.
- Understanding of secure software development principles and DevSecOps methodologies.
- Strong knowledge of vulnerability management, security monitoring, and incident response.
- Experience supporting compliance efforts under NIST, FISMA, and FedRAMP requirements.
Preferred Qualifications
- Experience supporting VA, DoD, HHS, CMS, or other federal civilian agencies.
- Experience with AWS GovCloud or Azure Government environments.
- Familiarity with SIEM and monitoring tools such as Splunk, ELK, DataDog, or Microsoft Sentinel.
- Experience securing Kubernetes and containerized environments.
- Knowledge of zero-trust architectures and cloud-native security controls.
- Experience supporting Authority to Operate (ATO) packages and security assessments.
- Relevant certifications such as CISSP, CISM, or CEH are highly valued.
Benefits and Culture
Ad Hoc offers a supportive remote work environment with competitive benefits, including company-subsidized health, dental, and vision insurance, flexible PTO, 401K with employer match, paid parental leave, and an Employee Assistance Program. We are an Equal Opportunity/Affirmative Action Employer committed to diversity and inclusion. We encourage veterans and transitioning service members to apply.
Key skills/competency
- Cyber Security Engineering
- DevSecOps
- Cloud Security
- CI/CD Pipeline Security
- Infrastructure as Code (IaC)
- Vulnerability Management
- Incident Response
- NIST Compliance
- Container Security (Docker, Kubernetes)
- Risk Management
Skills & topics
- Cyber Security
- DevSecOps
- Cloud Security
- AWS
- Azure
- GCP
- Terraform
- Ansible
- Docker
- Kubernetes
- CI/CD
- Vulnerability Management
- Incident Response
- NIST
- FISMA
- FedRAMP
- ATO
- Remote
How to get hired
- Tailor your resume: Highlight your 5+ years of cybersecurity experience, federal government contract support, and specific cloud (AWS, Azure, GCP) and IaC (Terraform, CloudFormation, Ansible) expertise.
- Showcase DevSecOps skills: Emphasize your experience with CI/CD pipelines, automated security testing, and container technologies (Docker, Kubernetes).
- Demonstrate compliance knowledge: Clearly list your experience with NIST, FISMA, and FedRAMP requirements, and ATO processes.
- Address preferred qualifications: If you have experience with VA, DoD, HHS, CMS, AWS GovCloud, Azure Government, or relevant certifications (CISSP, CISM, CEH), make sure to include them.
- Express mission alignment: Connect your desire to work on impactful public-sector projects with Ad Hoc's mission to transform government services.
Technical preparation
Behavioral questions
Frequently asked questions
- What is the work arrangement for the Cyber Security Engineer DevSecOps role at Ad Hoc LLC?
- This Cyber Security Engineer DevSecOps position at Ad Hoc LLC is a fully remote role, allowing you to work from anywhere nationwide. Ad Hoc is built for a remote life, with culture, communications, and tools designed to support distributed teams.
- What are the primary responsibilities of a Cyber Security Engineer at Ad Hoc LLC?
- The primary responsibilities include designing, implementing, and maintaining security controls in cloud and on-premises environments, conducting security assessments and vulnerability analysis, supporting continuous monitoring and incident response, developing security documentation, assisting with ATO activities, and securing CI/CD pipelines and Infrastructure as Code deployments.
- What is the required experience for the Cyber Security Engineer DevSecOps position?
- The basic qualifications require a Bachelor's degree in a related field and at least 5 years of experience in cybersecurity, DevSecOps, or cloud security. Experience supporting federal government contracts and federal information systems is also essential.
- What cloud platforms and IaC tools is Ad Hoc LLC looking for in a Cyber Security Engineer?
- Ad Hoc LLC requires hands-on experience with cloud platforms like AWS, Azure, or Google Cloud Platform. Knowledge of Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or Ansible is also a key requirement for this role.
- Are there any preferred qualifications for the Cyber Security Engineer role at Ad Hoc LLC?
- Preferred qualifications include experience supporting specific federal agencies like VA, DoD, HHS, CMS, or working with environments like AWS GovCloud or Azure Government. Familiarity with SIEM tools (Splunk, ELK), zero-trust architectures, and relevant certifications (CISSP, CISM, CEH) are also highly valued.
- How does Ad Hoc LLC support its remote employees?
- Ad Hoc LLC offers a culture, communications, and tools built for remote work, enabling flexibility and collaboration. They also provide benefits such as company-subsidized health, dental, and vision insurance, flexible PTO, 401K with employer match, and paid parental leave.
- What compliance frameworks is the Cyber Security Engineer expected to support at Ad Hoc LLC?
- The Cyber Security Engineer is expected to support compliance efforts under NIST, FISMA, and FedRAMP requirements. Experience assisting with Authorization to Operate (ATO) activities is also a crucial part of the role.