Search

Junior DevSecOps Engineer

PublishedPublished: 6/14/2022
Engineering

Job Description

Job Description

VIATEQ Corporation is looking for a Junior DevSecOps Engineer to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved.


The ideal candidate is an early-career software or cybersecurity professional with foundational knowledge of secure software development principles, DevSecOps practices, and application security concepts who is eager to build deep technical expertise in a complex, mission-driven federal IT environment. This individual must be a technically curious self-starter with strong analytical skills, a foundational understanding of software development and security integration practices, and the ability to contribute effectively to cross-functional engineering and security teams under the guidance of senior cybersecurity engineers and program leadership.


This role sits within the Information Security Division (ISD) and provides foundational DevSecOps engineering support, security integration assistance, and application security services in support of the agency's secure software development lifecycle (SDLC), continuous integration and continuous delivery (CI/CD) pipeline security, and enterprise cybersecurity architecture and engineering program.


The Junior DevSecOps Engineer provides foundational engineering support across a range of DevSecOps integration, application security testing, security tool management, and continuous monitoring activities under the direction of senior cybersecurity engineers, the cybersecurity architecture and engineering team, and program leadership. This individual assists in the integration of security requirements into the software development lifecycle, supports CI/CD pipeline security tooling, contributes to application security testing activities including static and dynamic code analysis and API security testing, and helps ensure that security is embedded throughout the development-to-delivery pipeline for agency IT systems and applications.


This role offers significant professional development opportunities for an early-career DevSecOps or cybersecurity professional seeking to build expertise in secure SDLC integration, application security testing, cloud security, Zero Trust Architecture implementation, and enterprise cybersecurity engineering within a dynamic and mission-critical federal environment.


Responsibilities:

DevSecOps Integration Support

  • Assist senior engineers with the assessment of current DevSecOps practices and the integration of security tooling and processes into the agency's development-to-delivery pipeline under established guidance and direction.
  • Support the implementation of security controls and automated security checks within CI/CD pipelines, including code scanning, dependency analysis, and vulnerability detection at the build and deployment stages.
  • Assist with the integration of enterprise and security tools and practices into the development pipeline, supporting DevSecOps integration activities across agency IT Services and Business Technology Solutions projects as directed.
  • Contribute to the development and documentation of DevSecOps methods of procedures (MOPs), governance structures, standard operating procedures, and operational runbooks under senior staff direction.
  • Support the configuration, maintenance, and troubleshooting of DevSecOps tooling integrated into the agency's Azure DevOps environment, including pipeline configurations, security scan integrations, and automated testing frameworks.
  • Assist with the development of recommendations for DevSecOps governance structures and workforce development plans, contributing research, analysis, and draft documentation under senior engineer direction.
  • Support the automation and orchestration of CI/CD pipelines with ongoing security enhancements, assisting senior engineers in identifying and implementing improvements to pipeline security posture.



Application Security Testing Support

  • Assist with the execution of static code analysis (SAST) activities, supporting the configuration of static analysis tools, interpretation of scan results, and preparation of findings reports under senior staff direction.
  • Support dynamic code analysis (DAST) activities, including test environment setup coordination, scan execution assistance, and results documentation for review by senior engineers.
  • Assist with API security testing activities, supporting the execution of API scans against the OWASP API Top Ten criteria, organizing test results, and preparing formatted findings reports for senior staff review and stakeholder out-briefs.
  • Contribute to sprint-based penetration and API testing activities, supporting test coordination, results documentation, and remediation tracking under senior engineer direction.
  • Assist with the validation of remediation activities for identified application security findings, supporting re-testing execution and documentation of remediation verification results.
  • Research and document common application security vulnerabilities, attack vectors, and remediation strategies to support the development of senior engineer recommendations and findings reports.



Vulnerability Management Support

  • Assist with the scheduling and execution of vulnerability scans across the enterprise IT environment using Tenable Security Center, supporting scan configuration, results export, and preliminary findings review under senior staff direction.
  • Support the preparation of weekly vulnerability debrief slides and reports, compiling scan data, formatting outputs, and organizing findings for senior staff review and stakeholder distribution.
  • Assist with the review of vulnerability reports from Microsoft Threat and Vulnerability Management (TVM) to support the confirmation of CVE impact and applicability to the enterprise environment.
  • Contribute to the tracking and reporting of zero-day vulnerabilities, assisting senior staff with status tracking, closure documentation, and ad hoc reporting activities.
  • Support the management of scanning infrastructure, assisting with monitoring scanner operational status, performing basic troubleshooting under senior guidance, and escalating issues requiring advanced resolution.
  • Assist with compliance scans of newly provisioned servers and newly created OS baseline images, supporting scan execution and results documentation in accordance with established procedures.



Security Tools Management Support

  • Assist senior engineers with the administration, configuration, and maintenance of enterprise cybersecurity tools across the agency's security tool stack, including endpoint protection, SIEM, vulnerability management, and application security platforms.
  • Support the development and maintenance of tools inventory documentation, standard operating procedures (SOPs), and tools procedures documentation, ensuring all materials are current, accurately formatted, and uploaded to the designated SharePoint repository.
  • Assist with the identification of misconfigurations in security tools and capabilities for agency-operated systems, documenting findings and supporting remediation coordination under senior staff direction.
  • Contribute to the design, development, integration, and testing of automated security testing tools and scripts in support of Assessment and Authorization (A&A) activities.
  • Support the development and maintenance of compliance content leveraging the agency's Continuous Diagnostics and Mitigation (CDM) toolset, assisting senior engineers with content configuration and alignment to approved Security Configuration Specifications.
  • Research and document emerging cybersecurity tools, technologies, and capabilities, supporting senior engineer assessments of potential additions or enhancements to the agency's security tool stack.



Cybersecurity Architecture & Engineering Support

  • Assist senior security architects and engineers with the development and maintenance of cybersecurity architecture documentation, including architecture diagrams, data flow diagrams, topology maps, and recommendation documents under senior staff direction.
  • Support the development of Security Configuration Baselines (SCBs), assisting with research, documentation, and alignment to DISA STIGs, CIS Benchmarks, and agency-approved hardening standards.
  • Contribute to security design reviews for new technologies and services by researching security considerations, documenting relevant standards and requirements, and preparing supporting materials for senior engineer review.
  • Assist with the development of Zero Trust Architecture (ZTA) documentation and implementation support materials, contributing research, diagram drafts, and supporting content under senior architect direction in alignment with NIST SP 800-207 and applicable federal ZTA guidance.
  • Support configuration management activities, assisting senior engineers with the maintenance of the Configuration Management Database (CMDB) and contributing to the development of configuration management process documentation.
  • Assist with tracking and documenting new, revised, or emerging applicable federal policies and regulations, supporting senior architects in assessing impacts to the agency's cybersecurity architecture and engineering posture.



Cloud Security Support

  • Assist senior engineers with security engineering activities for cloud-hosted systems and services across AWS and Microsoft Azure Government environments, supporting configuration review, security assessment, and documentation activities under established guidance.
  • Support the monitoring and review of cloud security posture management outputs from AWS Security Hub, Amazon GuardDuty, Microsoft Defender for Cloud, and related cloud security tools, assisting with findings documentation and escalation to senior engineers.
  • Contribute to the development and maintenance of cloud security architecture documentation, assisting senior engineers with diagram preparation, findings write-ups, and recommendation documentation.
  • Assist with ensuring that FedRAMP JAB Provisional ATO or Agency ATO requirements are considered in cloud solution implementations, supporting senior engineers with documentation and compliance verification activities.



Automation & Scripting Support

  • Assist senior engineers with the development, testing, and maintenance of automation scripts and tools supporting security operations, vulnerability management, compliance monitoring, and DevSecOps pipeline integration activities.
  • Support the development of PowerShell, Python, or equivalent scripts for automating routine security administration, compliance data collection, and reporting tasks under senior engineer direction.
  • Assist with the development and maintenance of Extract-Transform-Load (ETL) processes and data normalization routines supporting security dashboards and visualization outputs.
  • Contribute to the testing and validation of automation tools and scripts prior to production deployment, supporting quality assurance activities under senior engineer guidance.



Documentation & Reporting

  • Assist with the preparation and maintenance of technical documentation, project plans, recommendation documents, hardware/software review reports, procedure documents, and system diagrams in support of cybersecurity engineering activities.
  • Prepare and maintain weekly and monthly status reports, enterprise ticketing system reports, and other recurring reporting deliverables in accordance with established formats and submission schedules.
  • Ensure all documentation is peer-reviewed for accuracy, grammar, and formatting consistency prior to submission, and that all deliverables are uploaded to the designated SharePoint or GRC repository.
  • Respond to documentation requests and ad hoc reporting requirements within established timelines as directed by senior staff and program leadership.



Security & Compliance

  • Complete all required annual cybersecurity awareness training within established deadlines and maintain all required certifications as current and unexpired throughout the period of performance.
  • Ensure all work products are Section 508 accessibility compliant where required, government-owned, and free of proprietary or company-specific markings or restrictions.
  • Adhere to all applicable Federal security, privacy, and compliance requirements, including FISMA, NIST SP 800-53, NIST SP 800-160, OMB Circular A-130, and agency-specific cybersecurity policies, in the performance of all assigned duties.


Required Education and Experience:

  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
  • Minimum of 1–2 years of experience in software development, DevOps, DevSecOps, application security, or a closely related technical field, including internship, academic project, or entry-level professional experience in a federal government IT environment or federal contractor setting.
  • Demonstrated foundational knowledge of secure software development lifecycle (SDLC) principles, CI/CD pipeline concepts, and application security testing methodologies obtained through coursework, certification study, or practical work experience.
  • Basic hands-on experience with at least one scripting or programming language (e.g., Python, PowerShell, Bash, JavaScript) used for automation, security tooling, or application development purposes.
  • Abil
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...