JobRaahGet matched free

Jobs

Senior DevSecOps Engineer

Hyertek · Hybrid - DMV Area · United States · Remote

Pay: USD 145,000 – 186,500 a year

Posted Sep 28, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Apply Description Description HyerTek is a federal technology consulting firm delivering secure enterprise applications, data analytics, cloud infrastructure, and modernization solutions to federal government agencies. HyerTek is hiring a Senior DevSecOps Engineer to own the software supply chain and delivery pipeline behind our federal solutions. The role spans the full delivery cycle from developer commit through hardened container builds, automated security and compliance gates, artifact signing, and controlled releases into Azure Government environments supporting DoW Impact Levels 5, 6, and 7, equivalent classification levels, and other accredited environments as required by the customer. A successful candidate will incorporate approved AI coding agents into the engineering workflow to accelerate development and automation. These tools will be used to author pipeline and policy-as-code, triage findings, and generate technical documentation and control evidence. The DevSecOps Engineer will make security a built-in property of the pipeline rather than a review at the end of the process, while automating the collection of technical evidence needed to support and maintain an Authority to Operate (ATO). Candidates must possess a Top Secret security clearance and reside in the Washington, DC, metropolitan area. Some work will be performed at customer facilities, including accredited Secure Areas and SCIFs at Ft. Meade. Responsibilities Design, maintain, and improve secure CI/CD pipelines using GitHub Actions and Azure DevOps across multiple repositories and environments, including disconnected or air-gapped deployments. Build and maintain secure containerized applications for Kubernetes platforms such as AKS and OpenShift. Integrate automated security and compliance checks into development pipelines, ensuring critical findings are identified, evaluated, and remediated or resolved before release. Implement secure artifact management practices, including software bills of materials (SBOMs), artifact signing, provenance attestation, and controlled promotion between environments. Manage secrets and environment-specific configuration using approved vault and configuration-management solutions. Automate compliance evidence, configuration monitoring, audit logging, and security reporting in support of RMF and ATO requirements. Improve application and pipeline observability, reliability, and operational readiness through logging, monitoring, testing, alerting, and incident-response practices. Develop and validate backup, recovery, and disaster-recovery procedures with documented recovery objectives. Partner with developers, cybersecurity engineers, and operations teams to resolve vulnerabilities, improve delivery processes and support production deployments. Create clear technical documentation, operational runbooks, and customer-handoff materials. Monitor and troubleshoot CI/CD pipelines, build infrastructure,…