SteerBridge logo

DevSecOps Engineer

SteerBridge

Hybrid
Vienna, VA
Full-time
Senior
5+ yrs
Salary not listedPosted 37m ago

Real job — pulled straight from SteerBridge’s careers page · Verified September 30, 2026 · No reposts.

Job description

SteerBridge is hiring a DevSecOps Engineer — a full-time, based in Vienna, VA role. Apply directly on SteerBridge's careers page below.

DevSecOps

Team: MDC

Location: Vienna, VA

Commitment: Full-time

Workplace Type: hybrid

Salary:

The posted compensation range reflects the scope and requirements of this position. A final offer will be determined based on the candidate’s relevant experience, skills, education, certifications, and work location, along with the responsibilities of the position. Where applicable, contract requirements, wage determinations, and federal contract labor categories may also inform the offer.

 

SteerBridge also offers benefits that may include health and life insurance, paid time off, paid holidays, disability coverage, retirement savings, and professional development opportunities. Benefits vary by position and eligibility.

SteerBridge is a modern technology company delivering innovative, mission‑focused solutions to the U.S. Government and private sector. Leveraging deep expertise in federal acquisition, digital transformation, and emerging technologies, we deliver agile, commercial‑grade capabilities that accelerate operational effectiveness and drive measurable mission success.
At the core of SteerBridge is our people—especially the veterans whose leadership, problem‑solving mindset, and commitment to excellence elevate every project we support. We don’t simply hire exceptional talent; we cultivate it, creating meaningful career pathways for veterans, military spouses, and professionals who share our passion for advancing technology and strengthening the missions we serve.

POSITION OVERVIEW

SteerBridge is seeking a DevSecOps Engineer to own the security infrastructure and automation behind a mission-critical VA Disability Claims platform that supports Veterans and federal customers in AWS GovCloud. This role builds and runs the systems that security depends on: the log pipelines that feed our SIEM, the CI/CD and infrastructure-as-code pipelines that deploy every environment, and the scanning, patching, and security services deployed across our accounts.

The engineer partners closely with our security team, which monitors the environment, triages alerts, and leads incident response. This role makes sure that team has complete, reliable data and working tools, and turns their requirements into code, guardrails, and pipelines that run automatically. The engineer will also work with cloud engineers, solutions and security architects, application developers, and program leadership.

This is a hands-on role. The ideal candidate writes Terraform and pipeline code, onboards new log sources end to end, keeps security tooling deployed and healthy, and fixes the root cause when a pipeline, agent, or integration breaks. They are comfortable reviewing a merge request, debugging a broken data connector, and documenting how a control is implemented.

This is a hybrid position based in Vienna, VA.

 

Key Responsibilities

  • Own end-to-end security log pipelines from AWS and SaaS sources into Microsoft Sentinel, including CloudTrail, VPC Flow Logs, DNS query logs, GuardDuty, WAF, identity provider, and zero-trust platform logs.

  • Onboard and validate new log sources using native delivery paths, including data collection endpoints and rules, S3/SQS connectors, and vendor streaming; monitor pipeline health, ingestion gaps, data completeness, and parsing accuracy.

  • Manage security log retention, centralization, and immutability in accordance with federal logging and compliance requirements.

  • Own GitLab CI/CD pipelines used to plan and deploy Terraform and Terragrunt across multiple AWS GovCloud accounts and organizations.

  • Implement and maintain CI/CD security controls, including IaC scanning, secrets detection, container image scanning, dependency and SBOM checks, least-privilege deployment roles, protected branches, approval rules, and secure state and secrets handling.

  • Standardize secure container build and release practices for ECS and Fargate workloads, including immutable image tags, signed and scanned images, and ECR lifecycle policies.

  • Maintain security baselines across cloud environments, including IAM Identity Center permission sets, least-privilege roles, encryption, network segmentation, zero-trust access through Zscaler ZPA/ZIA, and inline inspection using Palo Alto VM-Series.

  • Document infrastructure security controls and maintain operational runbooks supporting NIST SP 800-53, RMF, and ATO activities.

 

Required Qualifications

  • Eligibility requirements: U.S. citizenship is required for this position under applicable federal contract requirements. Candidate must also be able to obtain and maintain the security clearance required for the role.

  • 5+ years of hands-on experience in DevOps, cloud security, security engineering, or a related field, preferably within AWS environments.

  • Strong experience with infrastructure as code, including Terraform, and familiarity with Terragrunt, policy-as-code, and IaC security scanning tools such as Checkov or tfsec.

  • Experience building and securing CI/CD pipelines using GitLab CI, GitHub Actions, or similar platforms, including SAST, DAST, SCA, secrets detection, container image scanning, and secrets management using tools such as SonarQube, Snyk, Trivy, Checkmarx, AWS Secrets Manager, or KMS.

  • Experience building and troubleshooting security log pipelines into SIEM platforms such as Microsoft Sentinel, Splunk, or Elastic, including log-source onboarding and ingestion monitoring.

  • Experience implementing AWS security services across multi-account environments, including CloudTrail, GuardDuty, Security Hub, Config, and IAM, with a strong understanding of cloud networking, identity, least-privilege access, and zero-trust principles.

  • Experience securing containerized workloads using Docker with ECS, Fargate, or Kubernetes, along with scripting and automation skills in Python, Bash, or PowerShell and strong troubleshooting, documentation, and cross-functional communication skills.

 
Preferred Qualifications
  • Experience with AWS GovCloud or other regulated or federal cloud environments, including familiarity with NIST SP 800-53, RMF, FedRAMP, or federal ATO processes.

  • Experience with multi-account AWS Organizations, service control policies (SCPs), and AWS landing zone patterns such as Trusted Secure Enclaves or Landing Zone Accelerator.

  • Familiarity with Terragrunt and log transformation tools such as Vector.

  • Experience with Azure Monitor data collection, including data collection endpoints and rules, and working knowledge of KQL for validating ingested data.

  • Experience with security and infrastructure platforms such as Zscaler ZPA/ZIA, Palo Alto or comparable next-generation firewalls, Tenable vulnerability scanning, and AWS Systems Manager patching at scale.

  • Relevant certifications such as AWS Certified Security – Specialty or AWS Certified DevOps Engineer – Professional.

Benefits

  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life Insurance
  • 401(k) Retirement Plan with matching
  • Paid Time Off
  • Paid Federal Holidays
SteerBridge is proud to be an Equal Opportunity Employer. We are committed to creating a diverse and inclusive workplace where all qualified applicants and employees are treated with respect and dignity—regardless of race, color, gender, age, religion, national origin, ancestry, disability, veteran status, genetic information, sexual orientation, or any other characteristic protected by law.
We also provide reasonable accommodations for individuals with disabilities in accordance with applicable laws. If you require assistance during the application process, we encourage you to reach out so we can support your needs.

Get DevSecOps Engineer jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Inetum logo

Linux Systems Engineer

Rennes, FR
✓ From careers page· 17h ago
Inetum logo

Windows Systems Engineer

Rennes, FR
✓ From careers page· 17h ago
Inetum logo

DevOps Engineer

Bogotá, CO
✓ From careers page· 17h ago
Inetum logo

Data Engineer

Nantes, FR
✓ From careers page· 17h ago

Frequently asked questions

What skills are required for DevSecOps Engineer at SteerBridge?

The required skills for DevSecOps Engineer at SteerBridge include: DevOps, AWS, Terraform, GitLab CI, GitHub Actions, Splunk, IAM, Docker, ECS, Python, Bash, PowerShell.

What is the seniority level for DevSecOps Engineer at SteerBridge?

DevSecOps Engineer at SteerBridge is a Senior level position.

How do I apply for DevSecOps Engineer at SteerBridge?

You can view the full description and apply for DevSecOps Engineer at SteerBridge on EchoJobs: https://echojobs.io/job/steerbridge-devsecops-hcdtd.