Senior DevSecOps Engineer
| Verified Pay check_circle | Provided by the employer$140000 - $200000 per year |
|---|---|
| Hours | Full-time |
| Location | Reston, Virginia |
About this job
Job Description
Company Overview
Pantheon Data (a Kenific Holding company) is a private, small business based in the Washington, DC, area. Pantheon Data was founded in 2011, initially providing acquisition and supply chain management services to the US Coast Guard. Our service offerings have grown in the past ten years, including infrastructure resiliency, contact center operations, information technology, software engineering, program management, strategic communications, engineering, and cybersecurity. We have also grown our customer base to include commercial clients. The company has used this experience to expand our service offerings to other agencies within the Department of Homeland Security (DHS), the Department of Defense (DoD), and other Federal Civilian Agencies.
Position Overview
Pantheon Data is seeking a Senior DevSecOps Engineer to design, build, and operate secure, cloud-native platforms in AWS GovCloud supporting ML-enabled workloads and applications that process CUI, PII, and PHI. GitLab Ultimate is our DevSecOps platform: you will own our GitLab CI/CD architecture end to end - pipelines, runners, security scanning, policy enforcement, and compliance evidence - and lead the migration of existing repositories and pipelines onto it.
The role combines secure pipeline engineering with platform operations: hardened infrastructure as code, production Amazon EKS administered through GitOps, and gated security controls that satisfy NIST 800-53, FedRAMP, and DoD SRG requirements while keeping delivery fast. Successful candidates can walk through pipelines and platforms they have personally built - stage design, security gates, runner architecture, failure modes, and the compliance evidence they produced.
Responsibilities
- GitLab CI/CD Engineering: Design, implement, and operate enterprise-grade GitLab CI/CD pipelines, including multi-project/parent-child pipeline orchestration, environment promotion gates, protected branches and environments, and reusable pipeline templates and CI components.
- GitLab Ultimate Security Suite: Deploy, configure, and tune the full GitLab Ultimate security suite as required pipeline gates: Advanced SAST, DAST, secret detection (including push protection), dependency scanning, container scanning, IaC scanning, license compliance, and API security - with findings triaged through the vulnerability management dashboard and merge request security widgets.
- Policy-as-Code & Compliance Automation: Enforce security centrally using scan execution policies, merge request approval policies, compliance frameworks, and compliance pipelines so scanning is mandatory across all projects; maintain audit events and evidence packages that support ATO, POA&M, and continuous-monitoring activities.
- Software Supply Chain Security: Generate and manage SBOMs (CycloneDX), enforce dependency and license policies, sign and verify build artifacts and container images, and maintain a secure, traceable path from commit to production.
- Runners & Cloud Auth: Architect and operate GitLab Runner fleets in GovCloud (autoscaling, isolation, hardened images) and implement keyless OIDC authentication from GitLab to AWS IAM roles - no long-lived cloud credentials in CI.
- Secure Infrastructure: Design and maintain hardened AWS GovCloud environments with Terraform (modular design, remote state, multi-repo dependency ordering), aligned to NIST 800-53 and FedRAMP High baselines and DISA STIG/CIS benchmarks.
- Kubernetes & GitOps: Manage lifecycle, networking, and security for production Amazon EKS clusters; orchestrate deployments with Helm and GitOps tooling (Argo CD or Flux) for declarative state management; harden clusters, registries, and OCI image workflows.
- ML Workload Support: Deploy and scale containerized ML models and data pipelines; build observability (metrics, logging, alerting, tracing) for regulated, restricted-egress environments.
- Platform Migration: Lead the migration of repositories, pipelines, and integrations from GitHub/GitHub Actions to GitLab, including translation of workflows, secrets strategy, branch protection parity, and developer enablement.
- Team Enablement: Mentor engineers on secure delivery practices, author runbooks and pipeline documentation, and partner with security and compliance teams on control implementation and assessment support.
Required Skills and Experience
- Bachelor's degree in Computer Science, Information Technology, Information Systems, Engineering, or a related technical field, from an ABET accredited university.
- 5+ years in DevSecOps/DevOps engineering with responsibility for production AWS environments. Plus an additional 5 years of experience in a related technical field.
- Deep, hands-on GitLab expertise: GitLab CI/CD pipeline design at scale, GitLab Ultimate security and compliance features (SAST/DAST/secret detection/dependency/container/IaC scanning, scan execution and approval policies, security dashboards), and GitLab Runner administration.
- Experience implementing gated DevSecOps controls in CI/CD - pipelines that block on security findings, enforce approvals, and produce auditable evidence.
- Deep hands-on expertise with Amazon EKS: cluster hardening, OCI-compliant image management, Helm, and GitOps deployment patterns (Argo CD or Flux).
- Proficiency in Terraform for complex networking and security stacks: modular design, state management, and multi-environment promotion.
- Practical understanding of NIST SP 800-53, FedRAMP, and DoD RMF/SRG, and their application to technical configurations in AWS GovCloud (STIGs, CIS benchmarks, boundary controls, audit logging).
- Scripting proficiency in Python or Bash for operational automation and security tooling.
- Current AWS Certified DevOps Engineer – Professional or AWS Certified Security – Specialty.
- Ability to work effectively in remote, cross-functional teams; meet deadlines; and produce quality work with clear written communication.
- Proficient in Microsoft Suite software including Outlook, Word, Excel, SharePoint, and PowerPoint.
Preferred Skills and Experience