Knowledge Management - Washington, DC

posted 9 days ago

Full-time - Entry Level
Washington, DC
Professional, Scientific, and Technical Services

About the position

As a Jr./Mid/Sr. DevSecOps Engineer at Knowledge Management, Inc. (KMI), you will be instrumental in designing, implementing, and maintaining secure software development and deployment pipelines. This role involves collaborating with cross-functional teams to integrate security practices into the development and operations lifecycle, ensuring the delivery of high-quality, secure, and reliable software solutions. You will work in a multi-year contract position requiring a TS/SCI clearance with CI Poly, contributing to the security and efficiency of software development processes.

Responsibilities

  • Collaborate with development, operations, and security teams to integrate security practices into the software development lifecycle.
  • Design, implement, and maintain CI/CD pipelines that incorporate automated security testing, vulnerability scanning, and compliance checks.
  • Develop and maintain infrastructure as code (IaC) templates and configurations, ensuring security best practices are applied to cloud resources and infrastructure components.
  • Perform regular security assessments, code reviews, and penetration testing to identify and address vulnerabilities and weaknesses in applications, code, and infrastructure.
  • Monitor and analyze system and application logs to detect and respond to security incidents.
  • Implement and manage identity and access management (IAM) solutions, ensuring appropriate authentication and authorization mechanisms are in place.
  • Collaborate with software engineers to provide guidance on secure coding practices and assist in remediation of security findings.
  • Participate in incident response activities, helping to investigate and mitigate security incidents in a timely manner.
  • Contribute to the development and maintenance of security policies, procedures, and documentation.

Requirements

  • Active TS/SCI Clearance with CI poly.
  • At least 2-6+ years of experience as a DevSecOps Engineer or similar role, with a focus on integrating security into the software development lifecycle.
  • Strong experience with DevOps practices, CI/CD pipelines, and automation tools (e.g., Jenkins, GitLab CI/CD, Artifactory, SonarQube, Selenium, Fortify, Acunetix, and Prisma Cloud).
  • Strong experience building DevSecOps solutions at scale across IL5 to IL6+ classification domains.
  • Experience with infrastructure as code (IaC) tools such as Terraform, CloudFormation, or Ansible.
  • Experience with cloud platforms (e.g., AWS, Azure, Google Cloud Platform) and securing cloud-based applications and services.
  • Experience with scripting languages (e.g., Python, Bash) for automation and tool integration.
  • Knowledge of security best practices, common vulnerabilities, and exposure to security frameworks (e.g., OWASP, NIST).
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service