Company Overview
Advanced Technological Solutions, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) specializing in delivering secure, reliable IT systems and network infrastructure solutions. We partner with clients to design, implement, and maintain cutting-edge technology environments that meet their unique business needs.
Overview
We are seeking a dynamic and highly skilled DevSecOps Engineer / Platform Application Subject Matter Expert (SME) to join our innovative team. Serves as the subject matter expert for securely deploying, integrating, and operating containerized applications and services on the platform. The role is not primarily responsible for building the underlying platform; rather, it ensures applications delivered by other teams can be securely onboarded, continuously integrated, deployed, monitored, and operated within the platform environment.
Applies DevSecOps principles throughout the application deployment lifecycle by integrating security controls, automated testing, vulnerability management, configuration management, and continuous compliance into CI/CD and GitOps workflows. May also function as a Platform Engineer and serves as a key liaison between application development, cybersecurity, and platform engineering teams.
Responsibilities
- Strong containerization skills using Docker, Podman, or equivalent technologies, including experience packaging applications for deployment using Helm charts, Kustomize, OpenShift Templates, or comparable technologies.
- Experience deploying and operating foundational network/platform services, such as authoritative DNS (e.g., PowerDNS), within a containerized environment.
- Ability to securely onboard applications built by other teams, such as an agentic coding suite or data mesh component, onto the shared platform, including troubleshooting application, dependency, integration, configuration, networking, and security issues.
- Strong working knowledge of CI/CD and GitOps pipelines for application build, test, security validation, deployment, and lifecycle management using technologies such as Jenkins, GitLab CI, Argo CD, or equivalent.
- Experience integrating automated security controls into CI/CD pipelines, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), dependency scanning, container image scanning, secrets detection, and infrastructure/configuration scanning.
- Experience supporting secure software supply-chain practices, including management and validation of trusted container images, software dependencies, artifact repositories, image registries, and software bills of materials (SBOMs).
- Working knowledge of container and Kubernetes/OpenShift security practices, including role-based access control (RBAC), secrets management, security contexts, network policies, image security, least-privilege principles, and secure configuration of application workloads.
- Ability to identify, assess, troubleshoot, and coordinate remediation of application and container vulnerabilities discovered during build, deployment, or operation.
- Familiarity with Infrastructure as Code (IaC) and configuration-as-code practices and the use of automated security and compliance checks to identify configuration drift or noncompliant application deployments.
- Scripting proficiency in Python, Bash, or similar languages to automate application deployment, security validation, configuration, monitoring, and troubleshooting tasks.
- Ability to work with cybersecurity, platform engineering, and application development teams to implement applicable DoD cybersecurity requirements and ensure application deployments align with established platform security controls and authorization requirements.
- Clear communication skills to translate application hosting, security, integration, and operational requirements between application development teams, cybersecurity personnel, and the platform engineering team.
- DoD 8570/8140-compliant certification appropriate to the assigned role.
Additional / Preferred Qualifications
- Certified Kubernetes Application Developer (CKAD), Certified Kubernetes Security Specialist (CKS), Red Hat OpenShift certification, or equivalent.
- Security-focused certification such as CompTIA Security+, CASP+/SecurityX, GIAC, or equivalent, as applicable to the position.
- Experience with service mesh technologies such as Istio or Linkerd, including implementation of secure service-to-service communications, traffic management, authentication, authorization, and observability.
- Familiarity with data mesh concepts and architecture to support integration of the data mesh workload.
- Prior experience as a DevSecOps Engineer, DevOps Engineer, Platform Engineer, or Site Reliability Engineer (SRE) bridging development, cybersecurity, and platform operations.
- Experience with Kubernetes/OpenShift security and policy enforcement technologies such as Open Policy Agent (OPA), Gatekeeper, Kyverno, or equivalent.
- Experience with container/image vulnerability scanning and software supply-chain security technologies such as Trivy, Anchore, Sonatype, JFrog, or equivalent.
- Familiarity with DoD Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs), continuous monitoring, and automated compliance validation within containerized or cloud-native environments.
Join us to be part of a forward-thinking team dedicated to delivering innovative IT solutions that empower our clients’ success!
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Life insurance
- Paid time off
- Vision insurance
Work Location: In person