
Real job — pulled straight from SteerBridge’s careers page · Verified September 30, 2026 · No reposts.
Job description
SteerBridge is hiring a DevSecOps Engineer — a full-time, based in Vienna, VA role. Apply directly on SteerBridge's careers page below.
DevSecOps
Team: MDC
Location: Vienna, VA
Commitment: Full-time
Workplace Type: hybrid
Salary:
The posted compensation range reflects the scope and requirements of this position. A final offer will be determined based on the candidate’s relevant experience, skills, education, certifications, and work location, along with the responsibilities of the position. Where applicable, contract requirements, wage determinations, and federal contract labor categories may also inform the offer.
SteerBridge also offers benefits that may include health and life insurance, paid time off, paid holidays, disability coverage, retirement savings, and professional development opportunities. Benefits vary by position and eligibility.
POSITION OVERVIEW
SteerBridge is seeking a DevSecOps Engineer to own the security infrastructure and automation behind a mission-critical VA Disability Claims platform that supports Veterans and federal customers in AWS GovCloud. This role builds and runs the systems that security depends on: the log pipelines that feed our SIEM, the CI/CD and infrastructure-as-code pipelines that deploy every environment, and the scanning, patching, and security services deployed across our accounts.
The engineer partners closely with our security team, which monitors the environment, triages alerts, and leads incident response. This role makes sure that team has complete, reliable data and working tools, and turns their requirements into code, guardrails, and pipelines that run automatically. The engineer will also work with cloud engineers, solutions and security architects, application developers, and program leadership.
This is a hands-on role. The ideal candidate writes Terraform and pipeline code, onboards new log sources end to end, keeps security tooling deployed and healthy, and fixes the root cause when a pipeline, agent, or integration breaks. They are comfortable reviewing a merge request, debugging a broken data connector, and documenting how a control is implemented.
This is a hybrid position based in Vienna, VA.
Key Responsibilities
-
Own end-to-end security log pipelines from AWS and SaaS sources into Microsoft Sentinel, including CloudTrail, VPC Flow Logs, DNS query logs, GuardDuty, WAF, identity provider, and zero-trust platform logs.
-
Onboard and validate new log sources using native delivery paths, including data collection endpoints and rules, S3/SQS connectors, and vendor streaming; monitor pipeline health, ingestion gaps, data completeness, and parsing accuracy.
-
Manage security log retention, centralization, and immutability in accordance with federal logging and compliance requirements.
-
Own GitLab CI/CD pipelines used to plan and deploy Terraform and Terragrunt across multiple AWS GovCloud accounts and organizations.
-
Implement and maintain CI/CD security controls, including IaC scanning, secrets detection, container image scanning, dependency and SBOM checks, least-privilege deployment roles, protected branches, approval rules, and secure state and secrets handling.
-
Standardize secure container build and release practices for ECS and Fargate workloads, including immutable image tags, signed and scanned images, and ECR lifecycle policies.
-
Maintain security baselines across cloud environments, including IAM Identity Center permission sets, least-privilege roles, encryption, network segmentation, zero-trust access through Zscaler ZPA/ZIA, and inline inspection using Palo Alto VM-Series.
-
Document infrastructure security controls and maintain operational runbooks supporting NIST SP 800-53, RMF, and ATO activities.
Required Qualifications
-
Eligibility requirements: U.S. citizenship is required for this position under applicable federal contract requirements. Candidate must also be able to obtain and maintain the security clearance required for the role.
-
5+ years of hands-on experience in DevOps, cloud security, security engineering, or a related field, preferably within AWS environments.
-
Strong experience with infrastructure as code, including Terraform, and familiarity with Terragrunt, policy-as-code, and IaC security scanning tools such as Checkov or tfsec.
-
Experience building and securing CI/CD pipelines using GitLab CI, GitHub Actions, or similar platforms, including SAST, DAST, SCA, secrets detection, container image scanning, and secrets management using tools such as SonarQube, Snyk, Trivy, Checkmarx, AWS Secrets Manager, or KMS.
-
Experience building and troubleshooting security log pipelines into SIEM platforms such as Microsoft Sentinel, Splunk, or Elastic, including log-source onboarding and ingestion monitoring.
-
Experience implementing AWS security services across multi-account environments, including CloudTrail, GuardDuty, Security Hub, Config, and IAM, with a strong understanding of cloud networking, identity, least-privilege access, and zero-trust principles.
-
Experience securing containerized workloads using Docker with ECS, Fargate, or Kubernetes, along with scripting and automation skills in Python, Bash, or PowerShell and strong troubleshooting, documentation, and cross-functional communication skills.
-
Experience with AWS GovCloud or other regulated or federal cloud environments, including familiarity with NIST SP 800-53, RMF, FedRAMP, or federal ATO processes.
-
Experience with multi-account AWS Organizations, service control policies (SCPs), and AWS landing zone patterns such as Trusted Secure Enclaves or Landing Zone Accelerator.
-
Familiarity with Terragrunt and log transformation tools such as Vector.
-
Experience with Azure Monitor data collection, including data collection endpoints and rules, and working knowledge of KQL for validating ingested data.
-
Experience with security and infrastructure platforms such as Zscaler ZPA/ZIA, Palo Alto or comparable next-generation firewalls, Tenable vulnerability scanning, and AWS Systems Manager patching at scale.
-
Relevant certifications such as AWS Certified Security – Specialty or AWS Certified DevOps Engineer – Professional.
Benefits
- Health insurance
- Dental insurance
- Vision insurance
- Life Insurance
- 401(k) Retirement Plan with matching
- Paid Time Off
- Paid Federal Holidays
Get DevSecOps Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for DevSecOps Engineer at SteerBridge?
The required skills for DevSecOps Engineer at SteerBridge include: DevOps, AWS, Terraform, GitLab CI, GitHub Actions, Splunk, IAM, Docker, ECS, Python, Bash, PowerShell.
What is the seniority level for DevSecOps Engineer at SteerBridge?
DevSecOps Engineer at SteerBridge is a Senior level position.
How do I apply for DevSecOps Engineer at SteerBridge?
You can view the full description and apply for DevSecOps Engineer at SteerBridge on EchoJobs: https://echojobs.io/job/steerbridge-devsecops-hcdtd.