MetroStar Systems, LLC
Sr. DevSecOps Engineer IV (5455)
MetroStar Systems, LLC, College Park, Maryland, us, 20741
As a
Sr.
DevSecOps Engineer IV , you'll play a critical role in designing, implementing, and maintaining secure and efficient software development and deployment pipelines. You will collaborate with cross-functional teams to integrate security practices seamlessly into the development and operations lifecycle, ensuring the delivery of high-quality, secure, and reliable software solutions. If you think you can see yourself delivering our mission and pursuing our goals with us, then check out the job description below! What you'll do: Collaborate with development, operations, and security teams to integrate security practices into the software development lifecycle. Design, implement, and maintain CI/CD pipelines that incorporate automated security testing, vulnerability scanning, and compliance checks. Develop and maintain infrastructure as code (IaC) templates and configurations, ensuring security best practices are applied to cloud resources and infrastructure components. Perform regular security assessments, code reviews, and penetration testing to identify and address vulnerabilities and weaknesses in applications, code, and infrastructure. Monitor and analyze system and application logs to detect and respond to security incidents. Implement and manage identity and access management (IAM) solutions, ensuring appropriate authentication and authorization mechanisms are in place. Collaborate with software engineers to provide guidance on secure coding practices and assist in remediation of security findings. Participate in incident response activities, helping to investigate and mitigate security incidents in a timely manner. Contribute to the development and maintenance of security policies, procedures, and documentation. What you'll need to succeed: Active TS/SCI Clearance with CI poly. At least 10 years of experience as a DevSecOps Engineer or similar role, with a focus on integrating security into the software development lifecycle. Expert experience with DevOps practices, CI/CD pipelines, and automation tools (e.g., Jenkins, GitLab CI/CD, Artifactory, SonarQube, Selenium, Fortify, Acunetix, and Prisma Cloud). Expert experience building DevSecOps solutions at scale across IL5 to IL6+ classification domains. Expert understanding of AWS and familiarity with other cloud platforms (e.g., Azure, GCP) and securing cloud-based applications and services. Strong experience with infrastructure as code (IaC) tools such as Terraform, CloudFormation, or Ansible. Strong experience in scripting languages (e.g., Python, Bash) for automation and tool integration. Hands-on experience with security tools for static code analysis, dynamic application security testing (DAST), and vulnerability scanning, using tools such as Fortify, Acunetix, and Prisma Cloud. Knowledge of security best practices, common vulnerabilities, and exposure to security frameworks (e.g., OWASP, NIST). MetroStar Systems is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. What we want you to know: In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
#J-18808-Ljbffr
Sr.
DevSecOps Engineer IV , you'll play a critical role in designing, implementing, and maintaining secure and efficient software development and deployment pipelines. You will collaborate with cross-functional teams to integrate security practices seamlessly into the development and operations lifecycle, ensuring the delivery of high-quality, secure, and reliable software solutions. If you think you can see yourself delivering our mission and pursuing our goals with us, then check out the job description below! What you'll do: Collaborate with development, operations, and security teams to integrate security practices into the software development lifecycle. Design, implement, and maintain CI/CD pipelines that incorporate automated security testing, vulnerability scanning, and compliance checks. Develop and maintain infrastructure as code (IaC) templates and configurations, ensuring security best practices are applied to cloud resources and infrastructure components. Perform regular security assessments, code reviews, and penetration testing to identify and address vulnerabilities and weaknesses in applications, code, and infrastructure. Monitor and analyze system and application logs to detect and respond to security incidents. Implement and manage identity and access management (IAM) solutions, ensuring appropriate authentication and authorization mechanisms are in place. Collaborate with software engineers to provide guidance on secure coding practices and assist in remediation of security findings. Participate in incident response activities, helping to investigate and mitigate security incidents in a timely manner. Contribute to the development and maintenance of security policies, procedures, and documentation. What you'll need to succeed: Active TS/SCI Clearance with CI poly. At least 10 years of experience as a DevSecOps Engineer or similar role, with a focus on integrating security into the software development lifecycle. Expert experience with DevOps practices, CI/CD pipelines, and automation tools (e.g., Jenkins, GitLab CI/CD, Artifactory, SonarQube, Selenium, Fortify, Acunetix, and Prisma Cloud). Expert experience building DevSecOps solutions at scale across IL5 to IL6+ classification domains. Expert understanding of AWS and familiarity with other cloud platforms (e.g., Azure, GCP) and securing cloud-based applications and services. Strong experience with infrastructure as code (IaC) tools such as Terraform, CloudFormation, or Ansible. Strong experience in scripting languages (e.g., Python, Bash) for automation and tool integration. Hands-on experience with security tools for static code analysis, dynamic application security testing (DAST), and vulnerability scanning, using tools such as Fortify, Acunetix, and Prisma Cloud. Knowledge of security best practices, common vulnerabilities, and exposure to security frameworks (e.g., OWASP, NIST). MetroStar Systems is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. What we want you to know: In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
#J-18808-Ljbffr