Source Job

$125,000–$135,000/yr
US

  • Conduct code and container vulnerability assessments using DoD scanning tools, DISA STIGs, and SRGs.
  • Apply SAST and DAST methodologies and integrate security controls into CI/CD pipelines.
  • Serve as GitLab security reviewer and coordinate remediation of security findings across teams.

DevSecOps GitLab Vulnerability Assessment Risk Management Framework

20 jobs similar to Cybersecurity Engineer – DevSecOps

Jobs ranked by similarity.

US

  • Design, build, and maintain CI/CD pipelines for application and infrastructure delivery.
  • Automate infrastructure provisioning and configuration using Terraform and Ansible.
  • Integrate security scanning, vulnerability detection, and automated testing into software delivery pipelines.

This company delivers secure, reliable technology for critical federal acquisition systems. They offer a remote work environment and support mission-critical government technology initiatives.

$140,000–$160,000/yr
US Unlimited PTO

  • Support DoD cybersecurity requirements by integrating security controls, automation, and compliance into DevSecOps pipelines, tooling, and configurations.
  • Design, implement, and maintain automated security controls for CI/CD pipelines, including SAST, DAST, SCA, container scanning, and vulnerability management.
  • Collaborate with engineering teams to ensure secure software supply chain practices, including SBOMs, artifact signing, and automated compliance evidence collection.

Raft is a customer-obsessed non-traditional defense tech company dedicated to empowering U.S. military and government agencies with cutting-edge AI/ML and data solutions. We are a hyper-collaborative team that values innovation, diversity, and a culture of Ubuntu, where each member adds unique value.

$100,000–$166,000/yr
US

  • Design, build, and maintain CI/CD pipelines for secure application delivery.
  • Automate infrastructure provisioning and deploy cloud services using AWS and Terraform.
  • Integrate security controls and enforce cybersecurity standards in development and deployment.

LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed. Headquartered in Tysons, Virginia, LMI serves the defense, space, healthcare, and energy sectors, helping agencies navigate complexity.

$98,135–$125,000/yr
United States

  • Design and implement secure CI/CD pipelines and DevSecOps processes for the VA COSE program.
  • Integrate security controls and automated testing throughout the software development lifecycle.
  • Collaborate with cybersecurity and development teams to ensure secure, compliant, and repeatable deployments.

9th Way Insignia is a service-disabled, veteran-owned small business that brings transformative technology to government customers. The company specializes in cybersecurity, cloud modernization, software development, and data analytics, and fosters a culture of innovation and mission-driven work.

North America Unlimited PTO

  • Lead the design and implementation of secure enterprise solutions for Professional Services clients across AMER.
  • Assess complex security architectures and guide migrations to GitLab security capabilities, including CI/CD and compliance frameworks.
  • Provide technical leadership throughout the engagement lifecycle, from pre-sales scoping to delivery and enablement.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security risk. With more than 50 million registered users and 50% of the Fortune 100 as customers, GitLab fosters a high-performance, all-remote culture driven by values and continuous learning.

$120,000–$155,000/yr
US Unlimited PTO

  • Deploy and automate CI/CD pipelines and establish IaC using modern DevSecOps techniques including serverless and Zero Trust patterns.
  • Own the POAM process end to end, develop plans of action with target dates, track progress, and close findings proactively.
  • Conduct Security Impact Analyses (SIAs) to achieve and maintain ATO, and maintain a live dashboard for all security findings.

Oddball brings quality software to the federal space, aiming to improve the daily lives of millions. It is a small company that values learning, growth, and making a big impact.

$185,000–$260,000/yr
US

  • Lead the end-to-end vulnerability management lifecycle across the technology stack.
  • Harden base operating system images and secure the software supply chain.
  • Integrate security controls into CI/CD pipelines and establish secure-development practices.

Partner company is a technology organization focused on application security and cloud-native environments. They foster a collaborative, remote-first culture with a focus on continuous improvement and employee wellbeing.

$150,000–$155,000/yr
US

  • Conduct application and cloud security assessments to identify risks and vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the SDLC.
  • Support vulnerability management, incident response, and security awareness education.

Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.

$180,000–$200,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • You will own end-to-end data protection: architecting security infrastructure, managing PCI/SOC2 programs, and setting the security roadmap.
  • You will integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and harden containerized and cloud-native environments.
  • You will configure IAM and SSO platforms, manage EDR/DLP/SIEM tooling, and run security awareness training.

Campminder builds software for summer camps, enabling meaningful experiences for kids. With over 100 employees, they are stable, profitable, and have a values-led culture committed to work/life balance.

$104,300–$193,700/yr
US

  • Collaborate with DevOps and engineering teams to embed security throughout the software development lifecycle.
  • Implement automated security testing, including SAST, DAST, SCA, and container security, and strengthen cloud-native security controls.
  • Support compliance with PCI-DSS, GDPR, CCPA, and SOC 2, and evaluate secure adoption of AI-assisted coding tools.

Our partner is a technology company in the travel and hospitality industry. They have a collaborative remote culture and value employee development and diversity.

$149,469–$184,000/yr
US

  • Develop and implement cybersecurity strategies and architectures aligned with organizational objectives and regulatory requirements.
  • Lead RMF activities for large distributed systems to obtain and maintain Authority to Operate.
  • Collaborate with government stakeholders and cross-functional teams to integrate security across systems and networks.

The company specializes in cybersecurity architecture and Zero Trust solutions for U.S. Department of Defense clients. It offers a fully remote work environment with a focus on work-life balance and professional development opportunities.

US

  • Design, build, and optimize secure CI/CD pipelines within GitLab, enforcing DevSecOps principles through automated vulnerability scanning and compliance gates.
  • Manage and scale AWS infrastructure, optimizing workloads on EKS, EC2, S3, and RDS.
  • Establish comprehensive monitoring, logging, and alerting systems across EKS and EC2 nodes to ensure maximum uptime.

LMI is a digital solutions provider that accelerates government impact with innovation and speed, offering commercial-grade platforms and mission-ready AI to federal agencies. Headquartered in Tysons, Virginia, the company serves defense, space, healthcare, and energy sectors, focusing on agility and collaboration.

Europe

  • Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
  • Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
  • Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk.

The partner company operates a large-scale digital platform and a globally distributed technology ecosystem connected to gaming and esports communities. They maintain a flexible, distributed, and inclusive work environment focused on equal opportunity and technical ownership.

US

  • Provide technical leadership for deploying real-time asset tracking solutions supporting U.S. Army operations.
  • Engage with Army and DoD stakeholders to translate mission requirements into effective technical solutions.
  • Oversee RMF and ATO compliance activities, including system architecture documentation and security control management.

US Security & IT provides IT and security solutions for U.S. Army missions, focusing on real-time asset tracking with RFID, IoT, and cloud infrastructure. The company values innovation and collaboration in a multi-disciplinary environment.

$98,000–$116,000/yr
US

  • Integrate AppSec tools into CI/CD pipelines and manage application security vulnerabilities.
  • Monitor and respond to security incidents, tuning WAF policies and security rulesets.
  • Collaborate with IT partners to perform security reviews and remediate findings across cloud platforms.

EMCOR Group, Inc. is a Fortune 500 leader in mechanical and electrical construction, industrial and energy infrastructure, and building services. As a large company with a diverse portfolio, it emphasizes a culture of security and collaboration.

Global

  • Apply your cybersecurity expertise to train next-generation AI systems with real-world input.
  • Analyze, debug, and resolve software bugs and vulnerabilities across diverse codebases.
  • Perform security audits, penetration testing, and contribute to backend development.

Our client is a venture-backed AI company developing intelligent systems via human expertise and machine learning. They are rapidly growing with over $40 million in funding and a global network of experts.

$154,000–$207,000/yr
US 3w PTO

  • Design and implement cybersecurity controls for satellite software, ground systems, and mission infrastructure.
  • Develop secure software practices including threat modeling, code reviews, and vulnerability management.
  • Monitor networks for cyber threats, lead incident response, and support compliance with NIST 800-171 and CMMC.

Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company is based in Silicon Valley and offers a comprehensive benefits package including equity, medical, dental, vision, 401k, paid vacation, and parental leave.

$110,095–$156,603/yr
US

  • Design and oversee cloud computing strategy, including adoption plans, application architecture, and system management.
  • Lead cloud implementation projects on IaaS and PaaS, collaborating with Cloud Service Providers like CloudOne and DAF CloudWorks.
  • Optimize cloud performance, enforce security compliance, and serve as a customer liaison for technical requirements.

Defense technology platform delivering high-impact technologies, technology-enabled services, and advanced manufacturing to U.S. national security customers. Backed by Falfurrias Management Partners, it combines deep domain expertise across military programs into a scalable aerospace and defense enterprise.

$115,000–$186,000/yr
US

  • Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
  • Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
  • Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.

Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.

$150,000–$182,400/yr
US 4w PTO

  • Design, develop, and maintain scalable, secure software services with an emphasis on backend systems, microservices, and APIs. - Implement DevSecOps practices including CI/CD pipelines, Infrastructure as Code, and containerization. - Collaborate with cross-functional teams to improve security, reliability, and delivery of healthcare technology solutions.

Bellese is a mission-driven digital services company pioneering innovative technology solutions in civic healthcare. They foster a collaborative, remote-first culture with a focus on learning and making a meaningful impact on public health outcomes.