DevSecOps Engineer
Bethesda, MD - USA
Job Summary
Leidos High Fidelity Simulation Business Area is responsible for architecting and implementing large-scale System of Systems solutions in support of world class simulation training and analysis products for the US Navy. You will get to work with state-of-the art technology developing the most sophisticated and game changing trainers the US Navy deploys. You will be constantly learning new skills and be encouraged and supported to develop the career you want to achieve. The hallmark of Leidos is empowered employees doing meaningful work. Join Leidos for a career not just a job.
Leidos is seeking an energetic motivated self-starter for this technically sophisticated and challenging engineering position developing a variety of naval training and simulation systems such as CIAT - Combined Integrated Air and Missile Defense (IAMD) and Anti-Submarine Warfare (ASW) Trainer - YouTube .
You will serve as an integral part of a development team that is focused on building and maintaining state-of-the-art Simulation Systems for our US Navy customers. You will administer DevSecOps and Configuration Management (CM) practices tools and techniques for the use by the team to increase our ability to deliver trainers more quickly and with improved quality. You will be responsible for setting up cloud environments to be used by development teams for continuous integration and development of Navy systems in both the public cloud and on-premises in private clouds. You will work directly with the management team to help standardize these same practices across our entire development group and demonstrate the effectiveness and value of modern DevSecOps and CM to our Navy customers. Come join us as a front-line leader who can help to shape the future of our team and our incredible products!
Remote/Telework: This position allows at least 75% remote work. Candidate must be local to the office and able to work onsite as needed to accomplish required tasks for the role.
Core Responsibilities
Kubernetes and Containers
- Design deploy and maintain Kubernetes-based platforms such as AWS EKS and RKE2.
- Deploy and manage containerized applications using Docker or Podman.
- Develop maintain and troubleshoot Helm charts and Kubernetes manifests.
- Configure and support Istio service mesh Kubernetes networking ingress service discovery configmaps secrets and workload security.
Infrastructure Automation
- Design deploy and maintain infrastructure using OpenTofu or Terraform.
- Develop Ansible automation for system configuration software deployment patching and operational tasks.
- Build reusable infrastructure modules automation roles templates and deployment patterns.
- Apply infrastructure-as-code principles including version control peer review testing and controlled promotion.
- Support infrastructure provisioning and configuration across development test and production environments.
CI/CD and Software Factory Operations
- Design implement and maintain secure CI/CD pipelines using GitLab and GitLab Runners or Jenkins.
- Integrate automated build test security packaging and deployment stages.
- Install configure troubleshoot and integrate GitLab GitLab Runners Jenkins Keycloak Red Hat Identity Management or LDAP Artifactory Mattermost Jira Confluence and SonarQube.
- Establish secure Git workflows including branching merge requests code reviews tagging releases and change control.
- Create reusable pipeline templates and shared CI/CD components.
DevSecOps and Continuous Authorization
- Integrate security practices into all stages of the software development lifecycle.
- Implement automated static application security testing software composition analysis dependency scanning container image scanning infrastructure-as-code scanning secrets detection license compliance and software quality gates.
- Support secure software supply chain practices including artifact integrity provenance and traceability.
- Support cATO continuous monitoring and automated compliance evidence collection.
- Translate security and compliance requirements into technical controls pipeline checks and operational procedures.
- Support vulnerability remediation patch management configuration compliance and security assessment activities.
Linux and Cloud Operations
- Administer and troubleshoot Red Hat Enterprise Linux (RHEL) or Rocky Linux systems.
- Troubleshoot processes services networking DNS storage permissions package management logging and system performance.
- Apply system hardening and operational security practices.
- Design deploy and maintain cloud infrastructure in Amazon Web Services (AWS).
- Support cloud networking identity and access management compute storage monitoring and security services.
- Develop procedures for backup recovery upgrades patching and incident response.
Collaboration and Technical Leadership
- Collaborate with developers cybersecurity engineers system administrators cloud engineers and technical leadership.
- Lead troubleshooting for complex platform pipeline networking authentication and deployment issues.
- Participate in architecture reviews design sessions code reviews incident response and root-cause analysis.
- Establish reusable engineering standards and operational practices.
- Maintain technical documentation diagrams runbooks and standard operating procedures.
Required Education
- Bachelors Degree in Electrical Engineering Computer Engineering or Computer Science Math or the Sciences Network Engineering Systems Software Information Technology or a related technical degree.
Required Experience
- You must have U.S. Citizenship and be eligible to obtain a U.S. Government granted security clearance. Employment is contingent upon receiving an interim Secret security clearance.
- You must have 2 years of experience in DevSecOps platform engineering systems engineering cloud engineering software engineering or a related field.
- You must have professional experience with Kubernetes Git Istio or similar K8s service mesh Helm charts Ansible OpenTofu or Terraform and Docker or Podman.
- You must have experience administering and troubleshooting Linux systems particularly RHEL or Rocky Linux.
- You must have experience designing deploying securing or operating infrastructure in AWS.
- You must have experience administering integrating or troubleshooting multiple software factory applications listed in this description (e.g. GitLab Artifactory etc.)
- Practical experience with Git workflows CI/CD pipelines infrastructure as code (IaC) container delivery automated security testing vulnerability management continuous monitoring and cATO.
- Experience writing automation using Bash Python etc.
- You must be able to diagnose complex technical problems across multiple infrastructure and application layers.
- You must be able to communicate technical concepts clearly and produce high-quality documentation.
- You must currently hold or be able to obtain certifications for Security entry-level Linux such as Linux or LPI Linux Essentials and entry-level AWS such as AWS Cloud Practitioner.
Desired Experience
- Certifications for Kubernetes Network or CCNA.
- Operating RKE2 Kubernetes clusters and software factories in air-gapped disconnected or highly restricted environments.
- Monitoring tools such as Grafana Prometheus and Loki.
- Security tools such as Falco AWS GuardDuty and Inspector.
- UDS CLI and UDS packages.
- Zarf for packaging deploying and managing applications in disconnected or air-gapped environments.
- Zero-trust architecture software bills of materials artifact signing image signing provenance or supply chain verification.
- Deploying securing or maintaining AI and large language model platforms.
- Policy as code automated compliance enforcement and observability platforms.
- Supporting regulated defense classified healthcare financial or other highly controlled environments.
- Atlassian Software Development and Collaboration products (Jira Confluence).
If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
IC
About Company
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.