MetroStar logo

Sr. DevSecOps Engineer II (6736)

MetroStar

Herndon, VAJob$170–190K/yrTracked 4w agoSeen in employer's feed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$170–190K/yr
Location
Herndon, VA
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

IAT Level 2 CertificationCompTIA Security+GSECSSCPTS/SCI clearance

Job overview

MetroStar is hiring a Sr. DevSecOps Engineer II (6736). The Sr. DevSecOps Engineer II will design, implement, and maintain secure and efficient software development and deployment pipelines. This role involves collaborating with cross-functional teams to integrate security practices into the development and operations lifecycle, ensuring the delivery of high-quality, secure, and reliable software solutions. The engineer will work independently or as part of a team to address complex technical requirements.

Key focus areas include Collaborate with customers and internal teams to design and implement automatic technical solutions across multiple classification environments., Develop CI/CD pipelines from scratch in GitLab CI and Jenkins with integrated security scanning and STIG compliance validation., and Provide expert guidance to development teams on pipeline troubleshooting and implementing DevSecOps best practices..

Successful candidates bring Active TS/SCI Clearance With CI Poly, 7+ Years DevSecOps Engineer Experience, and IAT Level 2 Certification. Important skills include GitLab CI, Jenkins, STIG Compliance Validation, DevSecOps Best Practices, AWS CloudFormation, and AWS GovCloud.

Skills & qualifications

RequiredNice to have

Skills

GitLab CIJenkinsSTIG Compliance ValidationDevSecOps Best PracticesAWS CloudFormationAWS GovCloudAWS C2SAWS TC2SLinux Command-Line ToolsRoot Cause AnalysisSecure Coding PracticesVulnerability RemediationATO EffortsDocker ImagesOpenShiftPrisma SecurityContainer OrchestrationCode ReviewsTechnical DocumentationDevOps PracticesCI/CD PipelinesContainerizationArtifactorySonarQubePrisma CloudPythonBashLinux EnvironmentRHELOracle LinuxTerraformAnsibleTier 1-3 Customer SupportGitLab Service DeskServiceNowDevSecOps Services Across Classified DomainsAWS CapabilitiesAmazon EC2Amazon S3IAMAmazon RDSArchitecting Secure Cloud-Based InfrastructureConfiguring Applications and Systems to Comply With STIGSecurity Requirements Guide (SRG)Security Best PracticesCommon VulnerabilitiesOWASPNISTOpenSCAPWork Independently

Qualifications

Active TS/SCI Clearance With CI Poly7+ Years DevSecOps Engineer ExperienceIAT Level 2 CertificationCompTIA Security+GSECSSCPUS Government/Intelligence Community Experience

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Paid Time Off
Parental Leave

Full job description

As a Sr. DevSecOps Engineer II , you’ll play a critical role in designing, implementing, and maintaining secure and efficient software development and deployment pipelines. You will collaborate with cross-functional teams to integrate security practice seamlessly into the development and operations lifecycle, ensuring the delivery of high-quality, secure, and reliable software solutions.

We know that you can’t have great technology services (https://www.metrostar.com/) without amazing people. At MetroStar, we are obsessed with our people and have led a two-decade legacy of building the best and brightest teams. Because we know our future relies on our deep understanding and relentless focus on our people, we live by our mission: A passion for our people. Value for our customers.

If you think you can see yourself delivering our mission and pursuing our goals with us, then check out the job description below!

What you’ll do:

  • Collaborate with customers and internal teams to design and implement automatic technical solutions across multiple classification environments, working independently or as part of the team to address complex technical requirements.

  • Develop CI/CD pipelines from scratch in GitLab CI and Jenkins with integrated security scanning and STIG compliance validation, providing expert guidance to development teams on pipeline troubleshooting and implementing DevSecOps best practices.

  • Create and maintain Infrastructure as Code (IaC) templates primarily using CloudFormation to architect highly available, resilient, and secure DevSecOps tool infrastructure across AWS environments (GovCloud, C2S, TC2S) while ensuring STIG compliance and guiding junior engineers on IaC best practices.

  • Lead advanced troubleshooting efforts by analyzing system and application logs using Linux command-line tools, conducting root cause analysis for complex issues, and developing mitigation strategies for service degradation.

  • Provide expert security guidance to development teams on secure coding practices, STIG compliance, vulnerability remediation, and other best practices in support of their ATO efforts.

  • Architect and build secure containerized solutions by designing Docker images with security best practices, implementing and optimizing OpenShift deployments and configurations, remediating Prisma security findings, and providing guidance to development teams on container orchestration and best practices.

  • Perform code reviews and knowledge sharing while maintaining technical documentation, promoting best practices, and fostering continuous team improvement.

What you’ll need to succeed:

  • Active TS/SCI Clearance with CI poly.

  • 7+ years of experience as a DevSecOps Engineer or similar role, with a strong focus on infrastructure automation, scalability, and reliability across the software development lifecycle.

  • Expert experience with DevOps practices, CI/CD pipelines, containerization, and other automation tools (e.g., Jenkins, GitLab CI/CD, Artifactory, SonarQube, and Prisma Cloud).

  • Strong experience with scripting languages (e.g., Python, Bash), in a Linux environment (RHEL, Oracle Linux, or similar)

  • Strong experience with infrastructure as code (IaC) tools such as Terraform, CloudFormation, or Ansible.

  • Experience with Tier 1- 3 customer support and ticketing systems such as GitLab Service Desk and ServiceNow

  • Expert experience delivering DevSecOps services across multiple classified domains

  • Expert understanding of AWS capabilities (EC2, S3, IAM, RDS, etc) and architecting secure cloud-based infrastructure and services. (familiarity with other cloud platforms a plus)

  • Hands-on experience configuring applications and systems to comply with Secure Technical Implementation Guides (STIG), Security Requirements Guide (SRG) by implementing security best practices.

  • Knowledge of security best practices, common vulnerabilities, and exposure to security frameworks (e.g., OWASP, NIST, OpenSCAP)

  • Ability to work independently and communicate with stakeholders across a global enterprise and cross-functional teams to drive project completion.

  • Experience within the US Government/Intelligence Community a plus.

  • Minimum IAT Level 2 Certification (CompTIA Security+, GSEC, SSCP, ETC.)

SALARY RANGE: $170,000 - $190,000

The salary range for this position is determined based on qualifications, skills, and relevant experience. The final salary offered will be determined based on several factors including:

  • The candidate's professional background and relevant work experience

  • The specific responsibilities of the role and organizational needs

  • Internal equity and alignment with current team compensation

  • This role is also eligible for additional compensation, subject to the terms and policies of MetroStar, which may include:

  • Performance-based bonuses

  • Company-paid training and/or certifications

  • Referral bonuses

To apply for this position, please submit your resume via the form below or through our careers page: https://www.metrostar.com/jobs/

Application Deadline: Applications will be accepted on a rolling basis until the position is filled; candidates are encouraged to apply as early as possible for full consideration.

Additional Compensation : This role may also be eligible for bonuses and/or additional incentives based on individual and company performance.

Benefits : All full-time employees are eligible to participate in our benefits programs:

  • Health, dental, and vision insurance

  • 401(k) retirement plan with company match

  • Paid time off (PTO) and holidays

  • Parental Leave and dependent care

  • Flexible work arrangements

  • Professional development opportunities

  • Employee assistance and wellness programs

Like we said, we are big fans of our people. That’s why we offer a generous benefits package, professional growth, and valuable time to recharge. Learn more about our company culture code (https://www.metrostar.com/wp-content/uploads/2025/02/MetroStar-CultureGuide-2025.pdf) and benefits (https://www.metrostar.com/join-us/) . Plus, check out our accolades. (https://blog.metrostar.com/news/tag/awards)

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment based on merit and without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.

What we want you to know:

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

Not ready to apply now?

Sign up to join our newsletter here (https://www.metrostar.com/news-events/) .

You've read the whole posting — now see how you match it.