Engineering Roles

DevSecOps Engineer

In this role, you’ll build the pipelines that move robust software into the field quickly. You’ll automate build, test, security, and deployment so new capability reaches operators in days rather than months, with security built in from the start instead of bolted on at the end. This is software engineering practiced at velocity: the faster the mission needs to move, the more your pipeline matters.

The Work
Your job is to collapse the distance between a code change and a fielded capability without relaxing security or destabilizing operations. You’ll work in small teams on rapid deployment problems, working with mission teams to remove the friction between them and the field. You’ll create continuous integration (CI) pipelines backed by extensive test automation to scale agile development to large teams. You’ll augment CI with continuous deployment (CD) to create end-to-end pipelines that compile, test, scan, and deploy across classification levels, wiring in automated security tests so that vulnerabilities surface in the pipeline, not in production. These pipelines will also automatically collate the evidence needed to ensure continuous authority to operate. You’ll maintain configuration management across product lines with multiple applications, shared services, and customers. When an operator needs a fix downrange, you’re part of the reason it can ship in less than a day.

You’ll also own the platform underneath the pipeline: creating environments using infrastructure as code, running Kubernetes on accredited cloud and on-premises infrastructure where telemetry cannot simply phone home to a SaaS, and building the observability that tells you a deployment is healthy.

This is campaigning in code: providing continuous updates to systems and tooling that enable mission-critical capabilities.

Who You Work With
You’ll collaborate with the software and analytics engineers whose code your pipelines carry to the field, with the information security team whose controls you automate into the delivery path, and with forward-deployed mission engineers and program teams who need capability fast without trading away security. You’ll also interact with classified IT, which sets the standards for cleared infrastructure, and research teams that need to move at speed within security constraints. You’ll work across STR’s classified infrastructure—100+ secure labs, accredited cloud environments, and on-premises networks—for teams that ship on a fast cadence. Your work enables that speed.
What We Look For
Strong experience with CI/CD tools (Gitlab) and pipeline automation, Cloud platforms (such as AWS, Azure, or Google Cloud), automated provisioning tools (such as Ansible or Chef), Containerization technologies (such as Docker and Podman), Kubernetes management solutions (such as EKS and Rancher). Experience deploying, and monitoring Kubernetes clusters and pod configurations. Knowledge of Python and Linux Shell, and Cyber Security fundamentals. Basic knowledge of Linux System Administration. Demonstrated experience as an effective communicator to both technical and non-technical audiences. Familiarity with NIST controls, RMF, infrastructure-as-code, and running platforms in cleared or constrained environments is valued. GitOps and infrastructure-as-code tools such as ArgoCD, Flux, and Terraform a plus. Experience leading teams in an Agile/SCRUM software development processes a plus.

Open Positions

Ready to find your place?

Browse every open position for this role across all capability areas and all U.S. locations.