DevSecOps Engineer
Job Description
<div class="content-intro"><h3>About Us</h3> <div> <div>AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.</div> </div></div><p>The <strong>DevSecOps Engineer</strong> provides security engineering expertise to Mission Partners, system owners, ISSMs/ISSOs, architects, and software development teams throughout the SDLC. The position integrates cybersecurity requirements and controls directly into Agile development and CI/CD processes, enabling development teams to identify and address security issues earlier in the lifecycle and securely move applications and capabilities from concept through production.</p> <p><strong>Essential Duties and Responsibilities:</strong></p> <ul> <li>Embed cybersecurity engineering into Agile software development and modernization activities.</li> <li>Integrate security requirements and controls throughout the SDLC and CI/CD pipelines.</li> <li>Apply DevSecOps and shift-left security principles to identify and remediate vulnerabilities earlier in development.</li> <li>Implement and support automated security testing within CI/CD workflows.</li> <li>Participate with development teams in requirements discussions, design activities, sprint planning, and other lifecycle events.</li> <li>Translate RMF, NIST SP 800-53, DoD cybersecurity policy, STIGs, SRGs, and related security requirements into actionable development and engineering tasks.</li> <li>Collaborate with developers, architects, system owners, ISSMs, and ISSOs to develop achievable technical security controls before formal assessment.</li> <li>Provide threat-informed security engineering guidance for legacy, modernized, and cloud-native applications.</li> <li>Support secure development involving APIs, microservices, containerized workloads, and other modern application architectures as applicable.</li> <li>Help development teams remediate security vulnerabilities while preserving mission functionality and delivery objectives.</li> <li>Provide engineering recommendations for technical controls such as authentication, encryption, network segmentation, and application security.</li> <li>Communicate security findings, technical risks, recommended remediation, and implementation approaches to technical and Government stakeholders.</li> <li>Manage security-engineering activities across multiple concurrent projects and development sprints.</li> </ul> <p><strong>Required Skills, Qualifications and Experience:</strong></p> <ul> <li>Bachelor’s degree and 10+ years of related experience.</li> <li>DoD 8140 Work Role 652 – Security Architect Certification requirement (must have at least one of the following): Security X/CASP+CE, CCSP, Cloud+, CISSP, CSSLP, CISM, CISSP-ISSAP, CISSP-ISSIP, CSSLP, and GSEC.</li> <li>Must have and maintain a current DoD Top Secret clearance.</li> <li>Must reside within a commutable distance of Fort Meade, MD or Chambersburg, PA in order to work a hybrid onsite schedule (4 days onsite weekly).</li> <li>Demonstrated experience integrating cybersecurity into Agile SDLC environments.</li> <li>Demonstrated hands-on experience with CI/CD pipelines.</li> <li>Practical experience implementing DevSecOps and shift-left security practices.</li> <li>Experience using automated security testing tools within software development processes.</li> &l