DevSecOps Engineer (TS/SCI)

External job listingat Vantor

Vantor is forging the new frontier of spatial intelligence, helping decision makers and operators navigate what’s happening now and shape what’s coming next. Vantor is a place for problem...

External source - not verified1 hour agoOpen until: Dec 29, 2026

Salary

Not provided

Location

Herndon, United States

Employment type

Not provided

Workplace

Not provided

DevSecOps Engineer (TS/SCI)

Herndon, United States

Job description

Vantor is forging the new frontier of spatial intelligence, helping decision makers and operators navigate what’s happening now and shape what’s coming next. Vantor is a place for problem solvers, changemakers, and go-getters—where people are working together to help our customers see the world differently, and in doing so, be seen differently. Come be part of a mission, not just a job, where you can: Shape your own future, build the next big thing, and change the world. To be eligible for this position, you must be a U.S. Citizen. This position requires an active U.S. Government security clearance, applicants who do not currently hold the required clearance will not be eligible for consideration. Employment for cleared roles is contingent upon verification of clearance status. Export Control/ITAR: Certain roles may be subject to U.S. export control laws, requiring U.S. person status as defined by 8 U.S.C. 1324b(a)(3). Please review the job details below. Vantor is seeking a Mid-Level DevSecOps Engineer located in Herndon, VA, to support the development, integration, and cybersecurity compliance of intelligence capabilities in Development and Production environments. This is a software engineering-focused DevSecOps role. The primary focus is designing, coding, testing, and maintaining software and automation tools that streamline Cyber Security workflows and improve the reliability of our platforms. We are looking for a candidate with a software development background who can build scalable, reliable systems and developer tools, and contribute to DevSecOps pipelines that integrate and deploy components across multiple networks into private cloud infrastructures hosted for our government customer. As a Vantor team member, you will closely support our mission partners, and your work will have direct mission impact. You will work with DevSecOps engineers, software developers, infrastructure technicians, and cybersecurity professionals to use open-source technology to create and maintain the full stack of a High-Performance Computing (HPC) system that hosts applications for thousands of users. About Us: We are a multi-faceted technical team with expertise spanning the full stack of cloud computing technologies including systems administration, DevOps, cybersecurity, software development, and systems engineering that builds and maintains software applications backed by a self-managed cloud infrastructure with a true big-data footprint (over 10 petabytes) Our diverse background of experience in mission support and technology development and operations serves as a catalyst to solve unique and challenging intelligence problems in support of special operations analysts and their on-going activities. Prototyping and frequent, iterative feedback are core to our delivery approach, anchored by a need to work quickly in support of our missions. Principal Responsibilities Software Engineering and Automation Build and maintain custom command-line tools, APIs, and dashboards that reduce manual effort and streamline Cyber Security and developer workflows. Design, write, test, and maintain clean, production-quality code (e.g., Python, Go, Java, or similar) to automate Cyber Security workflows. Convert manual Cyber Security, compliance, infrastructure, and developer workflows into automated, repeatable software workflows. Build automation for security analysis, vulnerability correlation, compliance tracking, remediation workflows, and security exception processes. Develop custom dashboards and reporting applications that aggregate data from multiple systems and provides actionable visibility into security, compliance, infrastructure, and software delivery. Participate in code reviews. Troubleshoot complex application and automation failures by analyzing source code, logs, APIs, infrastructure, and system behavior. DevSecOps and Software Delivery Deploy and manage highly available applications to ensure system reliability and scalability. Implement and maintain HashiCorp Nomad and Kubernetes clusters for workload orchestration. Execute DNS configuration, management, and performance tuning for enterprise-grade systems. Develop and implement Infrastructure-as-Code (IaC) solutions using tools like Terraform, Ansible, or similar. Build and manage multiple CI/CD pipelines with GitLab or equivalent tools to automate deployments and streamline development workflows for rapid development and integration Perform system monitoring, logging, and troubleshooting to proactively identify and resolve issues. Automate security testing and monitoring within the DevOps workflows using ACAS and Trivy. Analyze cybersecurity scan findings and work with the cybersecurity team to identify false positives. Assist the cybersecurity team in assembling the required Body of Evidence for False Positive exceptions. Assist the cybersecurity team in assembling the required Body of Evidence to submit containerized and non-containerized software packages for enterprise software approval. Integrate static code analysis tools such as GitLab SAST, Fortify, or SonarQube and other security mechanisms into CI/CD pipelines. Build and maintain software tools that automate cybersecurity analysis and correlation workflows as compliance requirements evolve. Perform cybersecurity remediation on DevSecOps-managed virtual machines, including OS patching, OS STIG implementation, and software package updates. Build, maintain, and monitor configuration management of release products. Troubleshoot and resolve issues in networks, automation pipelines, and infrastructure. Minimum Requirements Must have an active TS/SCI clearance and be willing and able to pass a CI polygraph. Must be able and willing to work 40 hours per week in a SCIF in Herndon, Virginia. At least 3 years of industry experience in software development or software engineering. At least 5 years of industry experience in DevSecOps, with a bachelor’s degree in Computer Science, Information Systems, or a related field; or a master’s degree and at least 3 years of relevant experience. Demonstrated professional software development experience is required. Candidates must be able to design, write, test, debug, and maintain software using at least one language such as Python, Go, Java, C#, or similar. Experience building automation tools, APIs, or applications is central to this role. Strong expertise in cloud environments, including deployment, optimization, and troubleshooting. Proven track record in building and operating Cloud Native Applications using tools like Kubernetes and Docker. In-depth experience with IaC tools such as Terraform, Ansible, or equivalent. Solid experience in creating and managing CI/CD build pipelines using GitLab or similar tools (e.g., Jenkins, Azure DevOps). Strong software automation skills using Python, Bash, or equivalent languages; Python or comparable application development experience is required. Excellent problem-solving skills with attention to detail and the ability to thrive in a fast-paced environment. Experience applying security best practices in DevSecOps pipelines (e.g., Trivy, Grype, GitLab SAST, or SonarQube). Familiarity with monitoring tools like Prometheus, Grafana, or ELK Stack. Strong knowledge of networking and load balancing technologies. Experience with source control tools such as Git, including collaborative development workflows. Experience with automated deployment technologies such as Cloud Formation, Ansible, Puppet or Chef. Experience deploying and maintaining open-source and custom applications. Moderate Linux system administration experience (Red Hat, Rocky Linux, AlmaLinux, or similar). Working knowledge of Linux and Windows operating systems, web services, and SQL databases. Experience working in an Agile environment. Desired Skills Security+ or comparable certification for privileged user access. Experience with distributed processing methods and tools, such as REST APIs, microservices, IaaS/PaaS services. Experience developing and deploying web services. Experience in implementing Docker STIGs Experience with CONMON cybersecurity remediation. RHCSA/LPIC 1/2, CKA, or Docker Certified Associate certification. #cjpost Pay Transparency: To support pay transparency, Vantor includes salary ranges in all U.S. job postings. Starting pay for this role will fall within the listed range and will be based on factors such as experience, qualifications, skills, location, and market conditions. Candidates who meet the minimum requirements for the role should not expect to receive compensation at the top of the range. The listed range reflects the expected pay for this position, and final offers will be determined based on each candidate’s experience, expertise, and alignment with the role. The base pay for this position within the Washington, DC metropolitan area is: $116,000.00 - $154,000.00 - $169,400.00 annually. For all other states, we use geographic cost of labor as an input to develop market-driven ranges for our roles, and as such, each location where we hire may have a different range. Benefits: Vantor offers a competitive total rewards package that goes beyond the standard, including a robust 401(k) with company match, mental health resources, and unique perks like student loan repayment assistance, adoption reimbursement and pet insurance to support all aspects of your life. You can find more information on our benefits. The application window is three days from the date the job is posted and will remain posted until a qualified candidate has been identified for hire. If the job is reposted regardless of reason, it will remain posted three days from the date the job is reposted and will remain reposted until a qualified candidate has been identified for hire. The date of posting can be found on Vantor's Career page at the top of each job posting. To apply, submit your application via Vantor's Career page. EEO Policy: Vantor is an equal opportunity employer committed to an inclusive workplace. We believe in fostering an environment where all team members feel respected, valued, and encouraged to share their ideas. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender identity, sexual orientation, disability, protected veteran status, age, or any other characteristic protected by law.

Is this your job posting?

Claim it for free and receive video applications on CazVid.

Similar jobs