
DevSecOps Engineer (DoD)
RAPIDFORT · United States
- Hybrid
- Full-time
- $175,000 / year
- United States
Job highlights
- Design and maintain secure cloud infrastructure for DoD.
- Implement Kubernetes, CI/CD, and policy controls.
- Deploy and operate on AWS GovCloud and Azure Government.
- Manage container images and security scanning.
- Support ATO processes and DoD compliance.
About the role
About The Role
We are seeking a skilled DevSecOps Engineer to design, deploy, and maintain secure, cloud-native infrastructure supporting Department of War customers. You will work across container platforms, CI/CD pipelines, and government cloud environments to deliver hardened, compliant software systems at scale. This role sits at the intersection of platform engineering, security, and DevSecOps and requires a strong understanding of DoW policies, toolchains, and accreditation processes.
Key Responsibilities
- Design and maintain Kubernetes-based infrastructure, including cluster provisioning, RBAC configuration, network policy, and workload management.
- Package and deploy applications using Helm charts; maintain chart repositories and manage release lifecycle across environments.
- Implement and enforce policy controls using Istio service mesh, OPA Gatekeeper, Kyverno, and related Kubernetes admission controllers.
- Build and maintain CI/CD pipelines using GitLab CI, GitHub Actions, Jenkins, or equivalent tooling; integrate automated security scanning and compliance gates.
- Deploy and operate workloads on AWS GovCloud and Azure Government; architect for high availability, disaster recovery, and cross-region compliance requirements.
- Manage and harden container images; integrate with Iron Bank, Platform One, and other DoW-approved registry sources.
- Configure and maintain observability stacks including Prometheus, Grafana, and Datadog; develop alerting, dashboards, and SLO frameworks.
- Participate in ATO processes, support STIG/CIS compliance scanning, and contribute to System Security Plans (SSPs) and documentation artifacts.
- Collaborate with development, security, and program teams to establish and refine DevSecOps practices across the software delivery lifecycle.
- Support air-gapped and classified environment deployments; design solutions for offline image transfer, registry mirroring, and artifact management.
- Coordinate with government platform teams and managed service providers to integrate and sustain vendor tooling within approved DoD software factories.
Required Qualifications
- 4+ years of hands-on experience with Kubernetes in production environments.
- Demonstrated experience deploying and managing applications via Helm in multi-environment configurations.
- Working knowledge of Istio, OPA Gatekeeper, Kyverno, or equivalent Kubernetes policy and service mesh tooling.
- Experience with at least one major CI/CD platform: GitLab CI, GitHub Actions, Jenkins, or equivalent.
- Hands-on experience with AWS and/or Azure cloud platforms, including IAM, networking, storage, and managed Kubernetes services (EKS, AKS).
- Experience with container image workflows: building, scanning, hardening, and distributing images via OCI registries.
- Familiarity with monitoring and observability tools including Prometheus, Grafana, and/or Datadog.
- Experience with Single Sign-On (SSO) and identity federation; familiarity with Keycloak or equivalent OIDC/SAML providers.
- Active DoW security clearance (Secret or higher).
Preferred Qualifications
- Experience with Iron Bank, Registry1, Platform One, or Big Bang-based software factory environments.
- Familiarity with GitLab Ultimate features including security dashboards and dependency scanning.
- Experience supporting Air Force, Space Force, Navy, or other military branch programs.
- Exposure to software supply chain security tooling: Sigstore/cosign, vulnerability scanners, SBOM generation, and compliance scanning tools.
- Prior work in cATO, continuous authorization, or Ongoing Authorization environments.
- CKA, CKS, AWS GovCloud certifications, or equivalent credentials.
- Experience with AWS GovCloud and/or Azure Government.
- Understanding of DoD compliance frameworks: NIST 800-53, STIGs, RMF, FedRAMP.
Technical Environment
You will work within a modern DevSecOps stack including some or all of the following:
- Container Orchestration: Kubernetes (EKS, AKS, RKE2, OpenShift)
- Package Management: Helm, Kustomize
- Policy & Mesh: Istio, OPA Gatekeeper, Kyverno, Calico
- CI/CD: GitLab CI/CD, GitHub Actions, Jenkins
- Cloud: AWS GovCloud (East/West), Azure Government
- Registries: Iron Bank / Registry1, Harbor, Quay, AWS ECR
- Observability: Prometheus, Grafana, Datadog, Loki, OpenTelemetry
- Security Scanning: Trivy, Grype, Anchore, RapidFort, Twistlock/Prisma
- IaC: Terraform, Ansible, Crossplane
Clearance & Compliance
This position supports U.S. Department of War programs and may require a valid security clearance. Candidates must be U.S. citizens. Applicants are subject to a background investigation in accordance with federal requirements.
Compensation
Base Salary: $140,000 – $175,000 + Benefits + Equity: Where applicable
Key skills/competency
- DevSecOps Engineer
- Kubernetes
- CI/CD
- Cloud Security
- AWS GovCloud
- Azure Government
- Container Security
- Helm
- Istio
- DoD Compliance
Skills & topics
- DevSecOps Engineer
- Kubernetes
- CI/CD
- Cloud Security
- DoD
- AWS GovCloud
- Azure Government
- Container Security
- Helm
- Istio
- Platform Engineering
- Security Automation
- Compliance
- STIGs
- RMF
- Remote
- Government Contracting
- Secret Clearance
How to get hired
- Tailor your resume: Highlight experience with Kubernetes, CI/CD, cloud platforms (AWS/Azure GovCloud), and DoD compliance frameworks relevant to the DevSecOps Engineer role.
- Showcase DoD experience: Emphasize any background with specific DoD tools like Iron Bank, Platform One, and adherence to STIG/CIS standards.
- Quantify achievements: Use metrics to demonstrate impact, such as improvements in deployment speed, security posture, or compliance adherence in previous DevSecOps Engineer positions.
- Prepare for technical questions: Be ready to discuss Kubernetes architecture, Helm deployments, Istio configurations, and security scanning tools in detail.
- Understand clearance requirements: Clearly state your active DoD security clearance status (Secret or higher) and your eligibility.
Technical preparation
Behavioral questions
Frequently asked questions
- What is the work arrangement for the DevSecOps Engineer DoD role at RapidFort?
- This DevSecOps Engineer position is a full-time, remote role supporting Department of War customers. While remote, it requires a strong understanding of DoD policies and cloud environments like AWS GovCloud and Azure Government.
- What level of security clearance is required for the DevSecOps Engineer (DoD) position?
- An active Department of War security clearance of Secret or higher is required for this DevSecOps Engineer role. Candidates must also be U.S. citizens, and applicants are subject to a background investigation.
- What are the primary cloud platforms used for this DevSecOps Engineer role?
- This DevSecOps Engineer role involves deploying and operating workloads on AWS GovCloud and Azure Government. Experience with these specific government cloud environments is highly valued.
- What specific Kubernetes technologies are emphasized for this DevSecOps Engineer position?
- The DevSecOps Engineer role requires hands-on experience with Kubernetes, including cluster provisioning, RBAC, network policy, and workload management. Familiarity with policy and service mesh tools like Istio, OPA Gatekeeper, and Kyverno is also crucial.
- How does RapidFort support software supply chain security in this DevSecOps Engineer role?
- This DevSecOps Engineer role includes managing and hardening container images, integrating with DoD-approved registries like Iron Bank, and utilizing security scanning tools. Familiarity with software supply chain security concepts and tools is a plus.
- What is the salary range for the DevSecOps Engineer (DoD) position at RapidFort?
- The base salary for this DevSecOps Engineer role ranges from $140,000 to $175,000 annually, in addition to benefits and potential equity.
- What are the core responsibilities of a DevSecOps Engineer at RapidFort supporting DoD clients?
- A DevSecOps Engineer at RapidFort designs and maintains secure cloud infrastructure, builds CI/CD pipelines, implements security controls, manages container images, and ensures compliance with DoD policies and frameworks for government customers.