
About This Role
Alright, let's get straight to it. We need someone who lives and breathes DevSecOps for a critical Air Force program. This isn't about checking boxes; it's about building security into the foundation of everything we develop.
What you'll be doing
You'll lead the charge on embedding security into our software development lifecycle from day one. That means designing and implementing the security practices within our DevOps pipeline for DoD applications, making sure everything aligns with regulatory requirements.
- Evaluate and select the right security tools, then integrate them directly into our CI/CD workflows.
- Conduct vulnerability assessments, threat modeling, and penetration testing to find risks before they find us.
- Work with development teams to build secure coding practices, incident response plans, and security training programs.
- A big part of this is mentoring junior and mid level engineers. You're here to help the team grow.
- Automate security testing and compliance processes using Infrastructure as Code (IaC) and other automation tools.
- You'll also assess, design, develop, test, and implement Business Continuity & Disaster Recovery solutions in a complex environment.
- The landscape changes fast. Staying on top of industry trends, emerging threats, and new best practices is non negotiable.
The essentials you need to start
This role has some non negotiable requirements due to the nature of the work. Here’s what you must have:
- You must be a US Citizen with an active Top Secret clearance. You also need to be able to obtain and maintain a SCI clearance prior to your start date.
- A Bachelor’s degree with 8+ years of experience or a Master’s Degree with 6+ years of experience. Additional relevant experience can substitute for a degree.
- At least 2 years of hands on experience with JAVA.
- A DoD 8140 intermediate certification or a DoD 8570 IAM Level II certification (or higher).
The skills you bring to the table
We're looking for deep technical expertise across several areas. Your background should include:
- A strong understanding of software development paradigms: change management, version control (like Git), CI/CD pipelines, and Agile planning tools such as Jira or Gitlab.
- A solid background using Infrastructure as Code (IaC) and Configuration as Code (CaC).
- Hands on experience configuring CI/CD pipelines in a DevSecOps environment.
- A strong background in relational databases like PostgreSQL, MySQL, or MS SQL Server.
- Experience administering complex environments with both Linux and Windows operating systems. You should understand network administration and protocols like HTTP/HTTPS, SSL/TLS, SMTP, and DNS.
- Extensive experience integrating security tooling into hybrid cloud environments; you know what each component can do well…and where it falls short.
- Extensive experience provisioning and managing resources within hybrid IaaS/Cloud infrastructures like Azure, AWS, or Google Cloud Platform.
Job Location
Huntsville, AL