Key Responsibilities:
- Work with Pipeline Architect and Software Engineering SMEs to ensure DoD IA and cybersecurity thresholds are met and built directly into pipeline tooling, configurations, and workflows.
- Translate DoD cybersecurity, RMF, and DevSecOps requirements into actionable technical requirements for engineering teams.
- Design, implement, configure, and maintain automated security controls within CI/CD pipelines.
Security Tooling and Integration:
- Integrate and maintain security tooling for SAST, DAST, software composition analysis (SCA), container scanning, secrets detection, dependency scanning, and vulnerability management.
- Establish and enforce security gates and thresholds within GitLab CI/CD pipelines to prevent noncompliant or vulnerable software artifacts from progressing.
- Support secure software supply chain practices, including artifact integrity, SBOM generation, vulnerability scanning, signing, provenance, and software attestations.
Collaboration and Compliance:
- Work with engineering teams to integrate tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, Cosign/Sigstore, and similar security capabilities into automated workflows.
- Review Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for security vulnerabilities and configuration weaknesses.
- Support compliance with the DoD DevSecOps Reference Design, NIST RMF, NIST 800-53 controls, and applicable DoD cybersecurity requirements.