
DevSecOps Project Lead (Sr DevSecOps Engineer)
Red Cell Partners · United States
- Hybrid
- Full-time
- $215,000 / year
- United States
Job highlights
- Lead DevSecOps for AI program in government cloud.
- Build and operate CI/CD, infrastructure, and security.
- Hands-on role making architecture and implementation decisions.
- Support program authorization and security accreditation.
- Fully remote with occasional travel required.
About the role
About Us
Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.
About Defcon Ai
RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.
In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.
About The Role
As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.
This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer's security and accreditation staff.
We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government's timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.
Key Responsibilities
First Deliverable: Platform Into the Government Environment
- Own the initial platform deployment into the government IL-5 environment, which is the program's first contract deliverable and lands early.
- Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
- Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
- Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.
Platform and Pipeline Ownership
- Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
- Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
- Build the platform so it is reusable across programs rather than rebuilt for each one.
Cloud and Infrastructure Architecture
- Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
- Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer's cloud and security staff.
- Design for zero-downtime deployment and rehearsed rollback.
- Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
- Integrate CAC / PIV authentication and role-based access control.
Security Engineering and Authorization Support
- Implement security controls from week one and produce the control evidence continuously from the pipeline.
- Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
- Serve as the engineering counterpart to the customer's security and accreditation staff, and support the authorization decision on their timeline.
- Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
- Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.
Release Management and Delivery Performance
- Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
- Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
- Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
- Integrate monitoring and alerting with the customer's network and security operations centers.
Technical Leadership
- Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
- Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
- Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.
Required Qualifications
- 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
- 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
- Hands-on keyboard while leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
- Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion.
- Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
- Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
- Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
- A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
- Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
- An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
- US Citizenship Required
- Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
- Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.
Preferred Qualifications
- Active TS/SCI Clearance
- Experience taking a program from an empty government cloud account to a deployed, authorized production system.
- Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
- Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
- Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
- Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
- Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
- Experience integrating with enterprise ICAM or IdP services and DoD PKI.
- Experience working alongside partner or subcontractor engineering pods.
- Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.
What Success Looks Like
- A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
- The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
- Authorization evidence accepted by the customer's assessor as it is produced, rather than assembled into a package at the end.
- Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
- Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
- A platform and a set of practices that get reused on the next program instead of rebuilt.
What We Offer:
- A fully remote, results-based environment
- Competitive salary, bonus, and equity package
- 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
- Unlimited PTO, with your manager’s approval
- Flexible work environment where you manage your work day
- 14 weeks of fully-paid parental leave
Salary Range:
$175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.
Our Red Cell Partners Benefits:
- For full-time roles
- Career track opportunity with potential for rapid advancement with strong performance as the firm grows
- 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.
- Paid maternity and paternity for 14 weeks at employees' normal pay.
- Unlimited PTO, with management approval.
- Opportunities for professional development and continued learning.
- Optional 401K, FSA, and equity incentives available.
- Mental health benefits are available through Tara Mind. Cost effective GLP-1 solutions available through Crux.
We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
Applicant Data Disclosure
By submitting an application, you acknowledge that Red Cell Partners, LLC (
Skills & topics
- DevSecOps
- Project Lead
- DevOps
- CI/CD
- Cloud Security
- AWS GovCloud
- Infrastructure as Code
- Kubernetes
- Docker
- ATO
- Cybersecurity
- National Security
- Remote
How to get hired
- Tailor your resume: Highlight 8+ years DevOps/DevSecOps, 3+ years federal cloud (IL-5/AWS GovCloud preferred), and ATO/cATO support experience.
- Showcase leadership: Emphasize hands-on technical leadership, architecture calls, and direct building experience.
- Demonstrate initiative: Detail past projects involving hard deadlines and external dependencies in government environments.
- Prepare for clearance: Ensure US Citizenship and readiness for an Active US Secret clearance.
- Address remote work: Confirm availability for occasional travel (up to 25%).
Technical preparation
Behavioral questions
Frequently asked questions
- What are the key technical skills required for the DevSecOps Project Lead role at Red Cell Partners?
- The DevSecOps Project Lead at Red Cell Partners needs extensive experience (8+ years) in DevOps and DevSecOps, with a strong focus on building and operating CI/CD pipelines, infrastructure as code (Terraform, CloudFormation), container orchestration (Docker, Kubernetes), and security scanning tools within federal cloud environments (IL-4/IL-5, AWS GovCloud preferred). You should also have experience with observability practices and supporting ATO/cATO processes.
- Is this DevSecOps Project Lead position remote, and what is the travel expectation?
- Yes, this DevSecOps Project Lead position is fully remote. However, there is an expectation of occasional travel, up to 25%, to DEFCON AI HQ, customer sites, and vendor facilities as required.
- What level of security clearance is required for the DevSecOps Project Lead position?
- A US Secret clearance is required for this DevSecOps Project Lead role. US Citizenship is a prerequisite, and the work is performed in a controlled government cloud environment, necessitating a favorable investigation and CAC eligibility from the start.
- What does 'hands-on keyboard while leading' mean for this DevSecOps Project Lead role?
- This means the DevSecOps Project Lead is not just a management or oversight role. You will be actively involved in making architectural decisions and also responsible for building and implementing those solutions. It's a blend of technical leadership and direct engineering contribution.
- What is the significance of the first deliverable for the DevSecOps Project Lead at Red Cell Partners?
- The first deliverable is critical as it involves deploying the initial platform into the government IL-5 environment. This is the program's first contract deliverable and must be achieved on a fixed date, requiring the candidate to have a proven pipeline pattern ready to adapt.
- What experience is necessary regarding government cloud environments and authorization for the DevSecOps Project Lead role?
- The DevSecOps Project Lead must have at least 3 years of experience in DoW or federal cloud environments at IL-4 or IL-5 (AWS GovCloud preferred). Direct experience supporting an ATO, cATO, or equivalent authorization, including producing accepted artifacts for assessors, is also essential.
- How does Red Cell Partners approach security in this DevSecOps Project Lead role?
- Security is integrated from the first week. The pipeline enforces hardened baselines, runs scans, and generates control evidence on every commit. The role involves owning the security artifact package and serving as the engineering counterpart to customer security and accreditation staff.
- What is the typical salary range for the DevSecOps Project Lead at Red Cell Partners?
- The typical salary range for this DevSecOps Project Lead position is between $175,000 and $215,000 annually, based on factors such as experience, skills, and other qualifications.