Defense Unicorns is seeking a senior DevSecOps Engineer to embed with a government team and its technology partners building an emerging AI-powered engineering ecosystem. This role sits at the intersection of platform engineering, cybersecurity, compliance, and software delivery. The engineer will help establish secure, automated, and repeatable pipelines that allow software, AI models, and agentic capabilities to move rapidly from development into operational environments while identifying cybersecurity and compliance risks early—before formal security testing.
🏢 About Defense Unicorns
Defense Unicorns delivers mission value by streamlining software delivery so our customers can focus on the most important challenges. We share a vision of freedom and security for the advancement of progress and innovation. Our commitment to this vision, and to our mission-driven customers, means a commitment to speed, user experience and optionality, without compromising security. Our team is composed of innovators, software engineers, and veterans with decades of experience delivering technology programs across the federal market.
🎯 The Role
This role sits at the intersection of platform engineering, cybersecurity, compliance, and software delivery. The engineer will help establish secure, automated, and repeatable pipelines that allow software, AI models, and agentic capabilities to move rapidly from development into operational environments while identifying cybersecurity and compliance risks early—before formal security testing. The ideal candidate is a hands-on DevSecOps engineer with deep experience in Kubernetes, cloud infrastructure, CI/CD, NIST 800-53, and the RMF/ATO process.
✅ Key Responsibilities
Design, implement, and continuously improve secure CI/CD and GitOps pipelines for cloud-native software, AI models, and agentic applications.
Work hands-on with Kubernetes and Red Hat OpenShift/OpenShift AI environments to automate secure build, test, promotion, deployment, and lifecycle workflows.
Translate NIST SP 800-53 controls and RMF requirements into practical engineering controls, policies, pipeline checks, and automated evidence collection.
Identify cybersecurity, compliance, configuration, and supply-chain risks early in the development lifecycle—before formal security testing or authorization activities.
Support the end-to-end ATO/RMF lifecycle, including control implementation, technical evidence generation, security artifacts, remediation tracking, and preparation for assessment.
Build and maintain automated security checks across source code, dependencies, container images, infrastructure, configurations, and deployment pipelines.
Implement software supply-chain security practices including SBOM generation, provenance, artifact signing, vulnerability scanning, policy enforcement, and controlled artifact promotion.
Develop Infrastructure as Code using Terraform, Pulumi, Ansible, or similar technologies to make environments consistent, auditable, and repeatable.
Configure and improve GitLab CI/CD pipelines, runners, registries, and automated workflows across multiple environments.
Integrate identity, secrets management, policy enforcement, logging, monitoring, and security tooling into the broader engineering platform.
Collaborate with platform, data, AI/agent, and architecture engineers to ensure security and compliance requirements are designed into the system rather than bolted on later.
Work directly with commercial technology partners to resolve cross-platform security, deployment, identity, networking, and integration issues.
Help establish repeatable approaches for promoting software and AI capabilities across security domains and into classified operational environments.
Develop security automation and compliance-as-code patterns that reduce manual effort and accelerate authorization decisions.
Create and maintain architecture decision records, security documentation, technical standards, runbooks, and implementation guidance.
Continuously identify recurring security and compliance work that can be standardized, automated, or productized rather than solved manually for each environment.
Operate effectively in a fast-moving, ambiguous environment where requirements and architecture will continue to evolve.
📌 Required Qualifications
Active TS/SCI clearance.
Must reside in or be local to the National Capital Region with the ability to work onsite in Springfield, VA as required.
Deep hands-on experience with Kubernetes and containerized application environments.
Experience deploying and operating workloads on Red Hat OpenShift and/or enterprise Kubernetes platforms.
Strong experience with GitLab CI/CD or comparable software delivery platforms.
Strong working knowledge of NIST SP 800-53 and the Risk Management Framework (RMF).
Practical understanding of the government ATO process, including control implementation, security evidence, POA&M/remediation, assessment, and authorization activities.
Experience identifying and remediating security risks in software and infrastructure before formal security testing.
Experience developing and managing Infrastructure as Code using Terraform, Pulumi, Ansible, or similar technologies.
Strong experience with Helm, Kubernetes manifests, GitOps, and declarative configuration management.
Experience with cloud environments such as AWS, including networking, IAM, compute, storage, and Kubernetes services.
Strong Linux systems knowledge and ability to troubleshoot across application, container, Kubernetes, network, and infrastructure layers.
Experience with container security, vulnerability management, artifact repositories/registries, and software supply-chain controls.
Strong scripting or programming ability using Python, Go, Bash, or similar languages.
Ability to work directly with government personnel and multiple technology vendors to diagnose and resolve complex technical and security issues.
Ability to operate with significant autonomy and turn loosely defined mission objectives into working technical solutions.
⭐ Desirable Experience
Experience supporting production systems at Secret or TS/SCI classification levels.
Experience implementing NIST 800-53 controls in Kubernetes or cloud-native environments.
Experience with continuous authorization / continuous ATO (cATO) approaches and automated compliance evidence.
Experience with Red Hat OpenShift AI or similar enterprise AI platforms.
Experience with AI/ML infrastructure, model serving, GPU-enabled environments, MLOps, or agentic AI systems.
Experience securing AI/agent workloads, including model provenance, tool access, data access, guardrails, and policy enforcement.
Experience with GitOps tooling such as Flux or Argo CD.
Experience with security and compliance tools such as Kyverno, OPA/Gatekeeper, SonarQube, Trivy, Snyk, Anchore, or comparable technologies.
Experience with SBOM, SLSA/provenance, artifact signing, and software supply-chain security frameworks.
Experience with identity and access management platforms such as Keycloak or comparable enterprise IAM technologies.
Experience with observability and telemetry tooling such as Prometheus, Grafana, OpenTelemetry, ELK, or similar platforms.
Experience moving software, images, or artifacts across multiple security domains or into disconnected/air-gapped environments.
Familiarity with UDS, Zarf, Pepr, Iron Bank, or similar secure software delivery technologies.
Department of Defense or Intelligence Community experience working on an operational ATO’d system.
Experience working on multidisciplinary teams consisting of government engineers, FDEs, OEM professional services teams, and multiple technology vendors.
Demonstrated ability to turn security and compliance requirements into automated engineering patterns that can be reused across environments.
🎁 Benefits
Full compensation packages are based on candidate experience. Compensation ranges are established using national benchmarking data and apply across all geographic locations within the United States.
Remote - USA
$148,750 — $201,250 USD
Health: Medical/Dental/Vision Premiums are 100% Company Paid Health Savings Account Life Insurance Disability Insurance
Financial: 401k Retirement Plan Company Stock Options Home Office Budget
Leave: We offer all full-time Unicorns Flexible Time Off (FTO) plus all Federal Holidays, one week for Thanksgiving, and two weeks for Christmas and New Year's Paid Parental Leave
Learning: Reimbursement for approved trainings/subscriptions Conferences (travel, lodging, and fees)
🛂 Visa & Eligibility
EMPLOYER IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AND AN ACTIVE TOP SECRET CLEARANCE.
Please let Defense Unicorns know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.