- Momentum Engineering, Inc.
- Washington, DC
- Full-Time
- 73 days ago
ME00631-Senior DevSecOps Engineer Lead (Hybrid).
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
ME00631-Senior DevSecOps Engineer Lead (Hybrid): our view in 3 lines...
- The Role:This role is for a senior DevSecOps engineer lead supporting federal programs hosted on AWS GovCloud.
- The Person:The person will design and maintain AWS GovCloud environments, build CI/CD pipelines, automate infrastructure with Terraform, CloudFormation, and Ansible, and implement security, monitoring, and compliance controls.
- Requirements:The ideal candidate has 7+ years of hands-on experience in DevSecOps, Cloud Engineering, or Infrastructure Automation, plus Security+ Certification, US citizenship, and the ability to obtain a DoD Secret security clearance.
About the role
Job Summary
- Seeking a highly skilled Senior leveled DevSecOps Engineer to support federal programs hosted on AWS GovCloud
- This hybrid role requires expertise in DevSecOps best practices, cloud automation, security compliance, and continuous integration/continuous deployment (CI/CD) to enhance the security, scalability, and efficiency of mission-critical applications
Primary Responsibilities
- AWS GovCloud Architecture & Management: Design, implement, and maintain secure, scalable, and compliant AWS GovCloud environments for DoD and Civilian agency applications
- DevSecOps Pipeline Development: Build and optimize CI/CD pipelines using tools like GitLab CI/CD, Jenkins, AWS Code Pipeline, and Terraform to automate deployments and security compliance
- Security & Compliance: Ensure adherence to Federal cybersecurity frameworks (e.g., NIST 800-171, NIST 800-53, RMF, FedRAMP, Zero Trust). Implement STIGs, security baselines, and automated security scanning (SAST/DAST)
- Infrastructure as Code (IaC): Automate infrastructure provisioning and configuration management using Terraform, CloudFormation, and Ansible
- Containerization & Orchestration: Deploy and manage Docker containers and Kubernetes clusters in AWS GovCloud, leveraging services like Amazon EKS, ECS, and Fargate
- Monitoring & Incident Response: Implement AWS CloudWatch, AWS Security Hub, GuardDuty, Splunk, or ELK for proactive monitoring, logging, and compliance reporting
- Automation & Scripting: Develop automation scripts using Python, Bash, or PowerShell to improve deployment efficiency and security enforcement
- Collaboration & Knowledge Sharing: Work closely with software developers, cybersecurity teams, and cloud engineers to integrate security and automation into the software development lifecycle (SDLC)
Required Qualifications
- US citizenship with the ability to obtain a successful DoD Secret security clearance required
- Security+ Certification
- 7+ years of hands-on experience in DevSecOps, Cloud Engineering, or Infrastructure Automation roles
- Strong expertise in AWS GovCloud services, security configurations, and compliance frameworks
- Experience with CI/CD tools (GitLab CI/CD, Jenkins, AWS Code Pipeline, or similar)
- Hands-on experience with Infrastructure as Code (IaC) using Terraform, CloudFormation, and Ansible
- Proficiency in containerization and orchestration (Docker, Kubernetes, EKS, ECS, Fargate)
- Strong understanding of AWS security services (AWS IAM, GuardDuty, Security Hub,AWS KMS, AWS WAF, AWS Config, AWS Secrets Manager)
- Knowledge of federal cybersecurity frameworks (RMF, NIST 800-171/53, STIGs, ZeroTrust)
- Experience implementing automated security testing (SAST, DAST, vulnerability scanning, SBOM management)
- Proficiency in scripting (Python, Bash, PowerShell) for automation and security enforcement
Desired Qualifications
- No desired qualifications listed at this time
Exempt hourly position. 11 paid holidays, minimum of 3 weeks PTO, company sponsored group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is dependent upon the candidate’s experience and qualifications.

