Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Sr DevSecOps Engineer image - Rise Careers
Job details

Sr DevSecOps Engineer

hatch I.T. is partnering with Expression to find a Sr DevSecOps Engineer. See details below:


About The Role:

Expression is seeking an experienced Senior DevSecOps Engineer to join their team. This role will work within their government facility with the Operations team while representing the interests of their DevSecOps leadership. Ensuring flawless software deployment in the production environment and bridging the gap between their DevSecOps and Operations teams is crucial.


About the Company:

Founded in 1997 and headquartered in Washington DC, Expression provides data fusion, data analytics, software engineering, information technology, and electromagnetic spectrum management solutions to the U.S. Department of Defense, Department of State, and national security community. Expression’s “Perpetual Innovation” culture focuses on creating immediate and sustainable value for our clients via agile delivery of tailored solutions built through constant engagement with our clients. Expression was ranked #1 on the Washington Technology 2018's Fast 50 list of fastest growing small business Government contractors and a Top 20 Big Data Solutions Provider by CIO Review.


Responsibilities:
  • Lead the implementation and maintenance of end-to-end CI/CD pipelines using our mature DevSecOps platform
  • Develop and execute Infrastructure as Code (IaC) solutions using Ansible for consistent and repeatable deployments across cloud and data center environments
  • Create comprehensive Systems Design documents and Architecture definitions
  • Ensure seamless deployment of containerized applications on OpenShift and non-containerized applications in the data center
  • Integrate and optimize DataOps and AI/ML workflows within our DevSecOps processes
  • Implement and maintain monitoring solutions using Prometheus and Grafana for reporting
  • Track and report on DORA metrics for KPI measurement
  • Ensure compliance with government security standards, including FIPS requirements
  • Collaborate with development teams to improve code quality, security, and performance
  • Troubleshoot and resolve issues in the production environment
  • Provide technical guidance and mentorship to team members


Required Qualifications:
  • Proven experience in a senior DevSecOps or Site Reliability Engineering (SRE) role within a DoD or highly regulated environment
  • Strong proficiency in our DevSecOps toolchain, including:
  • GitLab
  • SonarQube
  • Fortify
  • Snyk
  • Nexus Lifecycle Manager
  • Nexus Repo
  • Nexus Firewall
  • Tenable
  • Red Hat Advanced Cluster Security (ACS)
  • OpenShift
  • Expert-level knowledge of Ansible for Infrastructure as Code
  • Experience with FIPS-compliant libraries and security implementations
  • Strong background in cloud-native architectures and microservices
  • Proficiency in YAML, JSON, HELM Charts, Node.js, .NET
  • Experience with DataOps and AI/ML integration in DevSecOps workflows
  • Strong understanding of security principles and best practices in software development
  • Excellent technical writing skills for creating Systems Design documents and Architecture definitions
  • Experience with Prometheus and Grafana for monitoring and reporting
  • Familiarity with DORA metrics and KPI tracking in DevSecOps environments
  • Strong problem-solving and analytical skills


Preferred Qualifications:
  • Relevant professional-level certifications in DevSecOps (e.g., Redhat, CKA, CKAD, AWS/Azure/GCP certifications)
  • Familiarity with government compliance frameworks (e.g., NIST, FISMA, FedRAMP)
  • Experience with multi-cloud environments


$150,000 - $195,000 a year
Hatch IT Glassdoor Company Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
Hatch IT DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Hatch IT
Hatch IT CEO photo
Unknown name
Approve of CEO

Average salary estimate

$172500 / YEARLY (est.)
min
max
$150000K
$195000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Sr DevSecOps Engineer, Hatch IT

At Expression, we're on the lookout for a talented Senior DevSecOps Engineer who would love to join our dynamic team at our facilities in Annapolis, MD or Ft. Meade, MD. If you thrive in a fast-paced government environment and have a knack for implementing cutting-edge solutions, we want to hear from you! In this role, you'll have the opportunity to lead the development and maintenance of robust CI/CD pipelines while ensuring flawless software deployment in production environments. Your mastery of Infrastructure as Code (IaC) using Ansible will be key to creating consistent deployments across both cloud and data center realms. You will also work hand-in-hand with our development teams to enhance code quality, security, and performance, while integrating DataOps and AI/ML workflows into our DevSecOps processes. With your expertise, you'll mentor fellow team members and improve our operations continuously. If you're passionate about bridging the gap between DevSecOps and Operations while maintaining government compliance and security standards, we invite you to apply and become a part of our mission to deliver innovative solutions for national security clients. Join us at Expression, where our “Perpetual Innovation” culture prioritizes immediate and sustainable value for our customers, and where your contributions make a real difference!

Frequently Asked Questions (FAQs) for Sr DevSecOps Engineer Role at Hatch IT
What are the primary responsibilities of a Senior DevSecOps Engineer at Expression?

As a Senior DevSecOps Engineer at Expression, your main responsibilities will include leading the implementation and maintenance of end-to-end CI/CD pipelines, developing Infrastructure as Code (IaC) solutions using Ansible, and ensuring smooth deployment of applications. You'll also work with development teams to enhance code quality and security while managing monitoring solutions through Prometheus and Grafana.

Join Rise to see the full answer
What qualifications are required for the Senior DevSecOps Engineer position at Expression?

To qualify for the Senior DevSecOps Engineer position at Expression, candidates should have proven experience in a senior DevSecOps or Site Reliability Engineering role, especially in a DoD or highly regulated environment. Required skills include proficiency in tools like GitLab, SonarQube, and OpenShift, excellent knowledge of Ansible, and strong problem-solving capabilities.

Join Rise to see the full answer
What tools and technologies will a Senior DevSecOps Engineer at Expression work with?

In the role of Senior DevSecOps Engineer at Expression, you will work with a suite of tools including GitLab, Fortify, SonarQube, Nexus Repo, and OpenShift. You'll also utilize Ansible for Infrastructure as Code, as well as monitoring tools like Prometheus and Grafana for reporting and tracking DORA metrics.

Join Rise to see the full answer
Is prior experience in government compliance frameworks necessary for a Senior DevSecOps Engineer at Expression?

Yes, prior experience with government compliance frameworks such as NIST, FISMA, or FedRAMP is highly preferred for the Senior DevSecOps Engineer position at Expression. This knowledge is critical to ensure adherence to strict security standards and practices within our projects.

Join Rise to see the full answer
What is the salary range for the Senior DevSecOps Engineer role at Expression?

The salary range for the Senior DevSecOps Engineer position at Expression is between $150,000 to $195,000 a year, reflecting the level of expertise and experience expected for this critical role.

Join Rise to see the full answer
Common Interview Questions for Sr DevSecOps Engineer
Can you explain what Infrastructure as Code (IaC) is and its importance in DevSecOps?

Infrastructure as Code (IaC) is a method of managing and provisioning computing infrastructure through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools. In DevSecOps, IaC plays a vital role as it enables automation, consistency, and speed in deploying and managing infrastructure, leading to more efficient development cycles and reduced errors.

Join Rise to see the full answer
How would you ensure compliance with government security standards while deploying applications?

To ensure compliance with government security standards while deploying applications, I would use secure coding practices, conduct regular security assessments, and implement tools that monitor compliance, such as automated scanning tools. Additionally, staying informed about the latest regulations and involving compliance teams early in the development process will help maintain adherence.

Join Rise to see the full answer
What experience do you have with GitLab and how have you utilized it in previous projects?

I have extensive experience using GitLab as a central platform for version control and CI/CD processes. I’ve utilized GitLab pipelines to automate testing, code coverage, and deployment processes, ensuring quick feedback loops and high-quality code delivery in previous projects.

Join Rise to see the full answer
Describe a challenging problem you faced while implementing CI/CD pipelines and how you resolved it.

In a previous position, I faced a challenge with pipeline failures due to inconsistent environment configurations across staging and production. To resolve this, I implemented Infrastructure as Code (IaC) with Ansible, ensuring that our environments were replicated accurately and creating a seamless process for deployments.

Join Rise to see the full answer
How do you approach monitoring and troubleshooting applications in a production environment?

Monitoring and troubleshooting in a production environment requires a proactive approach. I set up comprehensive logging and monitoring using tools like Prometheus and Grafana, allowing me to visualize performance metrics in real-time. When issues arise, I methodically investigate logs and metrics to identify root causes and deploy fixes while minimizing downtime.

Join Rise to see the full answer
What strategies do you use to integrate security best practices into DevSecOps workflows?

To integrate security best practices into DevSecOps workflows, I emphasize a 'shift left' approach where security assessments are included early in the development process. Implementing automated security scanning tools and conducting peer reviews helps identify vulnerabilities before they impact production.

Join Rise to see the full answer
Can you describe a successful project where you implemented DevSecOps principles?

In a recent project, I implemented DevSecOps by automating the CI/CD pipeline for a cloud-native application. This included integrating security tools from the start and leveraging IaC. The project was successful not only in meeting compliance standards but also in reducing deployment time by 40% and increasing overall application security.

Join Rise to see the full answer
How do you keep up with industry trends and advancements in DevSecOps?

I actively follow industry publications, participate in webinars, and engage in forums related to DevSecOps. Additionally, I network with other professionals and attend industry conferences, which helps me stay updated on new tools, practices, and emerging trends.

Join Rise to see the full answer
What is your experience with container orchestration platforms like OpenShift?

I have extensive experience working with OpenShift for container orchestration, allowing me to manage and deploy applications efficiently. I utilize OpenShift’s features for scaling, health monitoring, and automated rollbacks to ensure high availability and performance of applications in production.

Join Rise to see the full answer
How do you mentor junior team members in a DevSecOps environment?

I believe in hands-on mentorship for junior team members through pair programming, code reviews, and collaborative problem-solving sessions. I also encourage continuous learning by providing resources and guidance on best practices in both DevSecOps tools and methodologies.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 2 days ago
DoubleZero Remote No location specified
Posted 11 days ago
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
Continental Hybrid 4021 N 56th St, Lincoln, NE 68504, USA
Posted 5 days ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
Comcast Hybrid Elkins Park, PA
Posted 14 days ago
Photo of the Rise User
Posted 8 days ago
Mission Driven
Social Impact Driven
Passion for Exploration
Reward & Recognition

hatch I.T. connects local engineers, startups, investors, and corporate leaders who share a common vision of strengthening the startup & innovation landscape in the DMV region.

19 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 13, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!