Our firm, Focused Management, Inc. (FMI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) and, Software Engineering Institute (SEI) – CMMI Maturity Level-3 Services Rated Company and we handle a wide range of government contracting opportunities. www.focusedmgmtinc.com
FMI is seeking a highly experienced DevSecOps Engineer to support the government hybrid cloud infrastructure environment supported by established DevSecOps practices, baselines, and federal compliance frameworks. To advance its modernization initiatives, the government seeks DevSecOps Engineering Services to augment existing engineering staff and expand upon established infrastructure automation, CI/CD pipeline capabilities, container orchestration, and security-hardened delivery practices. The objective is to extend and mature its existing infrastructure automation and secure software delivery capabilities.
POSITION: DevSecOps Engineer
LOCATION: Washington, DC
SUMMARY /GENERAL DESCRIPTION OF RESPONSIBILITIES:
The DevSecOps Engineer support shall be integrated seamlessly with the government’s engineering team,
build upon established procedures and guidelines, and contribute meaningfully across the following areas:
- Infrastructure as Code (IaC) using Terraform and OpenTofu
- Configuration as Code (CaC) using Ansible
- CI/CD pipeline development and maintenance using GitHub Actions
- Container build, management, and orchestration using Docker and Kubernetes
- Security integration and compliance hardening aligned with baselines and federal mandates. Support will not include design from scratch; rather, the engineer(s) will inherit existing
· patterns, adhere to established engineering standards, and incrementally enhance capabilities within an active production environment. The DevSecOps Engineer shall attend applicable stand-ups, sprint planning, and technical review sessions.
· The Contractor shall work within the government's established version control, change management, and peer review workflows. No changes shall be pushed to production environments without following the government’s change advisory process. Documentation standards for all deliverables must be followed
· and maintenance of clear records of changes made to shared codebases and pipelines.
· All security policies, including but not limited to, access control requirements, acceptable use policies, and data handling procedures must be adhered to.
The scope of work includes, but is not limited to, the following activities:
Infrastructure as Code (IaC) — Terraform / OpenTofu
The DevSecOps Engineer shall maintain, extend, and improve existing Terraform and OpenTofu codebases used to provision and manage government's cloud and hybrid infrastructure. This includes writing modular, reusable configurations; managing state files and remote backends; performing plan/apply workflows within approved change control processes; and refactoring legacy configurations to align with current engineering standards.
Work Products: Updated IaC modules, state management documentation, configuration change logs Configuration as Code (CaC) — Ansible
Develop and maintain Ansible playbooks and roles to automate system configuration, compliance enforcement, patch management, and application deployment across government server and network infrastructure. All playbooks shall adhere to the government's existing role structure, variable conventions,
and inventory management standards.
Work Products: Ansible playbooks/roles, inventory documentation, execution logs CI/CD Pipeline Development — GitHub Actions
Build, maintain, and improve GitHub Actions workflows to automate build, test, security scanning, and deployment processes for software and infrastructure pipelines. Pipelines shall incorporate security gates including static analysis (SAST), dependency scanning, secrets detection, and policy-as-code validation. All workflow changes shall be peer-reviewed and comply with the government's branching and approval standards.
Work Products: GitHub Actions workflow files, pipeline documentation, security gate integration report
Container Management — Docker and Kubernetes
Support containerized application delivery using Docker for image builds and Kubernetes for orchestration. Responsibilities include writing and maintaining Dockerfiles following image hardening best practices, managing Kubernetes manifests and Helm charts, supporting namespace and RBAC configuration, and assisting with cluster health monitoring and troubleshooting. All container images shall be scanned for vulnerabilities prior to deployment.
Work Products: Dockerfiles, Kubernetes manifests, Helm charts, image scan reports
Security Integration and Compliance Hardening
Integrate security practices throughout the software delivery lifecycle (Shift-Left security). This includes incorporating SAST/DAST scanning tools into pipelines, enforcing CIS benchmarks and security baselines on infrastructure and container configurations, supporting NIST SP 800-53 and FISMA compliance requirements, and producing documentation to support audit and assessment activities.
Work Products: Security scanning configuration, compliance alignment documentation, hardening
checklists
Mandatory Requirements:
- U.S. Citizenship
- Ability to obtain and successfully maintain an Active Public Trust Security Clearance
- Bachelor’s degree in computer science, Software Engineering, Information Systems, or related discipline.
- Infrastructure as Code: Hands-on experience with Terraform and OpenTofu, including module development, remote state management, and workspace management
- Configuration as Code: Proficiency with Ansible, including playbook and role development, dynamic inventories, and Ansible Vault for secrets management
- CI/CD: Demonstrated experience designing and maintaining GitHub Actions workflows, including reusable workflows, matrix builds, and security gate integration
- Containers: Working knowledge of Docker image authoring and hardening, Kubernetes manifest and Helm chart management, and container security scanning tools (e.g., Trivy, Grype, or equivalent)
- Security Integration: Familiarity with SAST tools (e.g., Semgrep, Checkov, tfsec), secrets scanning (e.g., Gitleaks, Detect-Secrets), and policy-as-code frameworks (e.g., OPA/Rego)
- Version Control: Proficiency with Git-based workflows including branching strategies, pull request reviews, and protected branch enforcement
Preferred Skills
- Experience in a federal or highly regulated environment
- Familiarity with NIST SP 800-53, FISMA, and FedRAMP compliance requirements
- Cloud platform experience (AWS)
- Experience with secrets management tools (e.g., HashiCorp Vault)
- Scripting proficiency in Python and Bash
Job Types: Full-time, Contract
Pay: $120,000.00 - $130,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Education:
Experience:
- DevSecOps: 4 years (Required)
- Terraform: 4 years (Required)
- OpenTofu: 4 years (Preferred)
- Ansible: 4 years (Required)
- GitHub: 4 years (Required)
- Kubernetes: 4 years (Required)
- FISMA: 4 years (Preferred)
- AWS: 3 years (Preferred)
- Federal Government IT support: 3 years (Preferred)
- Python scripting: 4 years (Preferred)
Security clearance:
Work Location: In person