• At least 10 years of experience as a DevSecOps Engineer or similar role, with a focus on integrating security into the software development lifecycle.
• Experience building DevSecOps solutions at scale across multiple classification domains (IL5 to IL6+) simultaneously
• Expert understanding of DevOps practices, CI/CD pipelines, and automation tools (e.g., Jenkins, GitLab CI/CD, Artifactory, SonarQube, Selenium).
• Strong experience with infrastructure as code (IaC) tools such as Terraform, CloudFormation, or Ansible.
• Expert understanding of AWS and familiarity with other cloud platforms (e.g., Azure, GCP) and securing cloud-based applications and services.
• Solid understanding of containerization and orchestration technologies (e.g., Docker, Kubernetes, OpenShift, EKS) and securing containerized applications.
• Hands-on experience with security tools for static code analysis, dynamic application security testing (DAST), and vulnerability scanning, using tools such as Fortify, Acunetix, and Prisma Cloud
• Expert proficiency in scripting languages (e.g., Python, Bash) for automation and tool integration.
• Knowledge of security best practices, common vulnerabilities, and exposure to security frameworks (e.g., OWASP, NIST).
• Strong problem-solving skills and the ability to work effectively in a fast-paced, collaborative environment.
• Excellent communication skills, both written and verbal, with the ability to convey complex security concepts to technical and non-technical stakeholders.
• Active TS/SCI Clearance with CI poly
• Current certifications to meet 8140/8570 standards (e.g. Security+ or above)
• Cloud certifications such as AWS Solutions Architect Associate/Professional, AWS SysOps Administrator, AWS Developer, or AWS DevOps Engineer
• Experience with low-to-high development models and associated tooling
• Experience with Microsoft Azure or Google Cloud Platform (GCP).