
DevSecOps Engineer
- Cheyenne, WY
- Permanent
- Full-time
- Provides Development, Security, and Operations (DevSecOps) areas of incident response, vulnerability scanning and management, problem management, certificate management, penetration testing, password policy management, data analysis of network security, remediation patching coordination, and compliance efforts.
- Implements automated application security testing tools, making users aware of how to best use application security features.
- Collaborates to develop an automated security framework for strong deployment tools and processes, leveraging various scripting languages and open-source solutions.
- Recommends automation improvements to replace manual tasks for network infrastructure provisions and security operational processes.
- Gathers requirements, designs and implements solutions, and fixes network or security operational issues.
- Manages end-user and administration access for access control.
- Performs network or security analysis and troubleshooting; diagnoses root cause analysis, using monitoring tools and system analytics; and applies system patches to DevOps tooling.
- Updates security procedures and maintains operations runbooks to report procedures and operations to avoid recurring issues.
- Sets up, conducts risk assessment, monitors, and maintains proxy servers, systems, and firewalls.
- Performs penetration testing and security code reviews.
- Coordinates change requests and provide status updates.
- Researched technology trends and best practices for cloud site reliability engineering.
- Candidates must have an active Top Secret with SCI eligibility required.
- BS in Computer Science, information Technology, or related field. 10 years of experience or multiple IT certifications may be substituted for a degree.
- 8 years of work-related experience required.
- Security+ or DoD 8570 IAT-II certification required.
- Ability to travel 10% - 20%.
- Certified Kubernetes Application Developer (CKAD), Red Hat Certified Engineer (RHCE), Certified Jenkins Engineer (CJE), AWS Certified DevOps Engineer, Certified Kubernetes Engineer (CKA), GitLab Certified DevOps Professional, or similar certifications.
- Familiar with technical aspects for IT and IAT-Level II Certifications.
- Experience with CI/CD pipelines, infrastructure as code, and containerization technologies
- Expertise in cloud platforms, automation tools, scripting languages, and security testing tools
- Understanding of AWS, Azure, or GCP and their security services
- Understanding of USAF IT systems, networks, and platforms.
- Experience with Jenkins, GitLab CI, Azure DevOps, or similar tools for automating the build, test, and deployment process.
- Proficiency with tools like Terraform, Ansible, or CloudFormation to automate infrastructure provisioning and configuration.
- Familiarity with Docker, Kubernetes, and related technologies.
- Proficiency in scripting languages like Python, Bash, or PowerShell to automate security tasks and workflows.
- Experience with static analysis (SAST), dynamic analysis (DAST), and software composition analysis (SCA) tools, as well as vulnerability scanners.
- Solid understanding of network security principles, including firewalls, intrusion detection/prevention systems, and network segmentation.
- Familiarity with SIEM solutions (like Splunk or ELK) and log aggregation tools for security monitoring.
- Familiarity with Identity and Access Management (IAM) and Zero Trust (ZT) security models.
eQuest