{"id":1284443,"url":"https://alion.io/job/steerbridge-devsecops","title":"DevSecOps","company":{"id":685505,"name":"SteerBridge","domain":"steerbridge.com","url":"https://alion.io/company/steerbridge","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Lever","truth_index":{"grade":"B","score":75,"open_postings":8,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-27T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Vienna, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":125000,"max":170000,"currency":"USD","period":"year","gross":null,"usd_annual":170000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon ECS","optional":false},{"name":"Amazon S3","optional":false},{"name":"AWS","optional":false},{"name":"AWS Fargate","optional":false},{"name":"Checkmarx","optional":false},{"name":"Checkov","optional":false},{"name":"CI/CD","optional":false},{"name":"DNS","optional":false},{"name":"Docker","optional":false},{"name":"GitHub Actions","optional":false},{"name":"GitLab CI","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"NIST 800-53","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SBOM","optional":false},{"name":"SIEM","optional":false},{"name":"Snyk","optional":false},{"name":"SonarQube","optional":false},{"name":"Splunk","optional":false},{"name":"Terraform","optional":false},{"name":"Terragrunt","optional":false},{"name":"tfsec","optional":false},{"name":"Trivy","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":false},{"name":"Azure","optional":true},{"name":"FedRAMP","optional":true}],"status":"live","first_seen_at":"2026-09-25T21:41:39Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-09-28T02:01:23Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"POSITION OVERVIEW\nSteerBridge is seeking a DevSecOps Engineer to own the security infrastructure and automation behind a mission-critical VA Disability Claims platform that supports Veterans and federal customers in AWS GovCloud. This role builds and runs the systems that security depends on: the log pipelines that feed our SIEM, the CI/CD and infrastructure-as-code pipelines that deploy every environment, and the scanning, patching, and security services deployed across our accounts.\nThe engineer partners closely with our security team, which monitors the environment, triages alerts, and leads incident response. This role makes sure that team has complete, reliable data and working tools, and turns their requirements into code, guardrails, and pipelines that run automatically. The engineer will also work with cloud engineers, solutions and security architects, application developers, and program leadership.\nThis is a hands-on role. The ideal candidate writes Terraform and pipeline code, onboards new log sources end to end, keeps security tooling deployed and healthy, and fixes the root cause when a pipeline, agent, or integration breaks. They are comfortable reviewing a merge request, debugging a broken data connector, and documenting how a control is implemented.\nThis is a hybrid position based in Vienna, VA.\nKEY RESPONSIBILITIES\nSecurity Log Pipelines\nOwn the end-to-end security log pipelines from AWS and SaaS sources into Microsoft Sentinel, including CloudTrail, VPC flow logs, DNS query logs, GuardDuty, WAF, identity provider, and zero-trust platform logs\nOnboard new log sources using native delivery paths (data collection endpoints and rules, S3 and SQS connectors, vendor streaming) and validate that data lands, parses, and stays complete\nMonitor pipeline health and ingestion gaps so a silent feed is caught and fixed before the security team loses visibility\nManage log retention, centralization, and immutability in line with federal logging requirements\nCI/CD and Infrastructure as Code\nOwn the GitLab CI/CD pipelines that plan and apply Terraform and Terragrunt across multiple AWS GovCloud accounts and organizations\nBuild security gates into pipelines, including IaC scanning, secrets detection, container image scanning, and dependency and SBOM checks\nHarden the pipelines themselves: least-privilege deployment roles, protected branches, approval rules, and state and secrets handling\nStandardize container build and release practices for ECS and Fargate workloads, including immutable image tags, signed and scanned images, and ECR lifecycle policies\nSecurity Posture, Compliance, and Collaboration\nMaintain the security baseline across accounts, including IAM Identity Center permission sets, least-privilege roles, encryption, and network segmentation\nSupport zero-trust access (Zscaler ZPA and ZIA) and inline inspection (Palo Alto VM-Series) configuration and change management\nDocument how controls are implemented in infrastructure, and maintain runbooks that support NIST 800-53, RMF, and ATO activities\nREQUIRED QUALIFICATIONS\n U.S. citizenship is required for this position under applicable federal contract requirements.\n5+ years of hands-on experience across DevOps, cloud security, or security engineering, preferably with AWS\nStrong experience with infrastructure as code (Terraform required; Terragrunt a plus) and policy-as-code and IaC security scanning (e.g. Checkov, tfsec)\nExperience building and securing CI/CD pipelines (GitLab CI preferred; GitHub Actions or similar acceptable), including integrated SAST, DAST, SCA, secrets, and container image scanning (e.g., SonarQube, Snyk, Trivy, Checkmarx) and secrets management (e.g., AWS Secrets Manager, KMS)\nExperience building log pipelines into a SIEM (Microsoft Sentinel preferred; Splunk or Elastic acceptable), including onboarding sources and troubleshooting ingestion\nExperience deploying AWS security services including CloudTrail, GuardDuty, Security Hub, Config, and IAM across multiple accounts\nExperience deploying and securing containerized workloads (Docker with ECS, Fargate, or Kubernetes)\nSolid understanding of cloud networking, identity, least-privilege access, and zero-trust principles\nScripting and automation skills in Python, Bash, or PowerShell\nStrong troubleshooting, communication, and documentation skills (diagrams, runbooks), with a methodical, root-cause approach and the ability to work across development, operations, and security teams to balance security with delivery speed\nPREFERRED QUALIFICATIONS\nExperience in AWS GovCloud or other regulated or federal cloud environments\nFamiliarity with Vector or other log transformation tools\nExperience with multi-account AWS Organizations, service control policies, or AWS landing zone patterns such as Trusted Secure Enclaves or Landing Zone Accelerator\nExperience with Azure Monitor data collection (data collection endpoints and rules) and enough KQL to validate ingested data\nExperience with Zscaler (ZPA and ZIA) or a comparable ZTNA or SASE platform, and with Palo Alto or similar next-generation firewalls\nExperience deploying vulnerability scanning tools such as Tenable, and running AWS Systems Manager patching at scale\nFamiliarity with NIST 800-53, RMF, FedRAMP, or federal ATO processes\nCertifications such as AWS Security Specialty or AWS DevOps Engineer Professional,\nBenefits\nHealth insurance\nDental insurance\nVision insurance\nLife Insurance\n401(k) Retirement Plan with matching\nPaid Time Off\nPaid Federal Holidays","description_format":"text","description_chars":5521,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Dental insurance","Health insurance","Life insurance","Retirement plans","Vision insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps"],"lifecycle":[{"event":"open","at":"2026-09-26T04:16:19Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":24,"reasons":["conf:0","velocity","win:early"],"computed_at":"2026-09-27T05:45:00Z"},"pay":{"stated_usd_annual":170000,"is_top_pay":false},"html_url":"https://alion.io/job/steerbridge-devsecops","json_url":"https://alion.io/job/steerbridge-devsecops.json","meta":{"generated_at":"2026-09-28T05:07:13Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3358,"day_limit":5000,"remaining_today":1642,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}