DevSecOps Engineer
Whitespace · Remote · United States · Remote
Posted Jul 1, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Position: DevSecOps Engineer
Location: Remote / Alexandria, VA
Clearance: Preferred US Gov Secret or above clearance (not a hard requirement)
Whitespace is dedicated to delivering innovative technological solutions that meet the highest standards of security and compliance. We are seeking a highly experienced Senior DevSecOps Engineer to join our team and play a key role in strengthening our cybersecurity posture and supporting federal compliance requirements.
We are seeking a DevSecOps Engineer with deep expertise in DoD DevSecOps Reference Architecture, secure CI/CD implementation, and Defense cloud environments (AWS GovCloud, Azure Government, DoD Cloud or Air gapped environments). The ideal candidate combines hands-on engineering capability with a strong understanding of DoD cybersecurity requirements, RMF compliance, and infrastructure automation.
The Senior DevSecOps Engineer will lead efforts to integrate security practices into our development and operations processes, with a primary focus on assisting the company in obtaining and maintaining a DoD/DoW Authorization to Operate (ATO). If you're passionate about making a difference in the world and being part of groundbreaking technology in national security, this position is for you!
This position is 100% remote! We're looking for a candidate who is a U.S. citizen and resides in the contiguous United States. You'll be a W-2 employee of GeoDelphi, Inc., and we do not accept third-party applications. This role requires less than 20% travel.
Requirements
1. Secure CI/CD and Cloud Infrastructure
Design, implement, and maintain secure CI/CD pipelines aligned with DoD Enterprise DevSecOps Reference Design (DSOP).
Automate deployment of secure environments using Terraform, Ansible, or CloudFormation for DoD or FedRAMP-compliant systems.
Integrate static code analysis (SAST), dynamic testing (DAST), container scanning and various security toolsets within pipelines to enforce continuous compliance.
2. Security Baselines & Compliance Integration
Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC).
Translate DoD security controls into automated enforcement and validation within development pipelines.
Develop scripts and tools for compliance validation (e.g., OpenSCAP, Chef InSpec, PowerSTIG).
Help co-develop & maintain technical documentation for RMF authorization and continuous monitoring processes.
3. Automation & Toolchain Management
Implement and manage DevSecOps tools such as GitLab, Jenkins, ArgoCD, Harbor, Nexus, SonarQube, Anchore, etc.
Automate container security and orchestrate deployments using Kubernetes (Big Bang, Iron Bank images or similar.
Manage secret storage, credential rotation, and logging using Vault, DoD-approved KMS, or AWS Secrets Manager.
4. Collaboration and Governance
Work closely with security, development, and operations teams to ensure alignment with DoD RMF, NIST SP 800-53,…