Jobs via Dice ยท 21 hours ago
Mid-level DevSecOps Engineer
Knowledge Management, Inc. (KMI) is a Minority Business Enterprise that delivers innovative technology and management solutions. They are seeking a Mid-level DevSecOps Engineer to design, implement, and maintain secure software development pipelines, integrating security practices into the development lifecycle.
Computer Software
Responsibilities
Collaborate with development, operations, and security teams to integrate security practices into the software development lifecycle
Design, implement, and maintain CI/CD pipelines that incorporate automated security testing, vulnerability scanning, and compliance checks
Develop and maintain infrastructure as code (IaC) templates and configurations, ensuring security best practices are applied to cloud resources and infrastructure components
Perform regular security assessments, code reviews, and penetration testing to identify and address vulnerabilities and weaknesses in applications, code, and infrastructure
Monitor and analyze system and application logs to detect and respond to security incidents
Implement and manage identity and access management (IAM) solutions, ensuring appropriate authentication and authorization mechanisms are in place
Collaborate with software engineers to provide guidance on secure coding practices and assist in remediation of security findings
Participate in incident response activities, helping to investigate and mitigate security incidents in a timely manner
Contribute to the development and maintenance of security policies, procedures, and documentation
Qualification
Required
Active TS/SCI Clearance with CI poly
At least 5 -10+ years of experience as a DevSecOps Engineer or similar role, with a focus on integrating security into the software development lifecycle
Strong experience with DevOps practices, CI/CD pipelines, and automation tools (e.g., Jenkins, GitLab CI/CD, Artifactory, SonarQube, Selenium, Fortify, Acunetix, and Prisma Cloud)
Strong Experience building DevSecOps solutions at scale across IL5 to IL6+ classification domains
Experience with infrastructure as code (IaC) tools such as Terraform, CloudFormation, or Ansible
Experience with cloud platforms (e.g., AWS, Azure, Google Cloud Platform) and securing cloud-based applications and services
Experience with scripting languages (e.g., Python, Bash) for automation and tool integration
Knowledge of security best practices, common vulnerabilities, and exposure to security frameworks (e.g., OWASP, NIST)
Company
Jobs via Dice
Welcome to Jobs via Dice, the go-to destination for discovering the tech jobs you want.
Funding
Current Stage
Early StageCompany data provided by crunchbase