Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Leidos

DevSecOps Engineer

Leidos

. Build and operate automated security controls embedded in L-CAP’s delivery pipeline .

Posted 9/22/2026full-timeUnited StatesMid-LevelSenior💰 $87,100 - $157,450 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in implementing and maintaining security controls within CI/CD pipelines, particularly focusing on SAST, DAST, and container security. Proficient in Kubernetes security practices and vulnerability remediation, with a strong understanding of policy-as-code and infrastructure guardrails.

Highest-signal resume keywords
SAST IntegrationKubernetes SecurityVulnerability ScanningSecrets ManagementPolicy-as-Code

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
SASTDASTContainer ScanningKubernetesVulnerability RemediationSecrets ManagementPythonBashGitOpsInfrastructure-as-Code
Tools & Technologies
NessusTrivyGrypeQualysGitLab CIGitHub ActionsJenkinsOPA/RegoKyvernoService Mesh
Certifications & Qualifications
Security+ CECySA+Certified Kubernetes Administrator (CKA)Certified Kubernetes Security Specialist (CKS)
Industry Keywords
NIST 800-53AWS SecurityAzure SecuritySAFeAgileCVE TriagePublic TrustFAA RequirementsSoftware Supply Chain SecuritySafety-Critical Environments

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityFluxJenkinsKubernetesLinuxOpenShiftPythonVaultGo

About the role

Key responsibilities & impact
  • Build and operate automated security controls embedded in L-CAP’s delivery pipeline
  • Implement and maintain SAST, DAST, software composition analysis, container scanning, and infrastructure-as-code scanning in CI/CD pipelines
  • Enforce security gates, artifact signing, provenance verification, and CycloneDX/SPDX SBOMs
  • Drive container vulnerability remediation and hardening, including hardened minimal base images and elimination of critical/high findings
  • Implement Kubernetes security controls, including pod security, network policies, RBAC, admission controls, and security context constraints
  • Secure workloads through secrets management, mutual TLS, service mesh policies, and Linux/container hardening
  • Build and maintain policy-as-code and infrastructure guardrails using OPA/Rego, Kyverno, or equivalent tools
  • Produce security evidence supporting authorization and continuous monitoring requirements
  • Partner with platform and application teams to triage vulnerabilities, remediate findings, and support security incident response and root cause analysis
  • Leverage AI-assisted development, automation, and modern engineering practices to improve security, code quality, productivity, and delivery speed
  • Operate within a SAFe/Agile framework as part of an Agile Release Train delivering iterative value across the program

Requirements

What you’ll need
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience
  • Additional experience, education and training may be considered in lieu of degree
  • Hands-on experience integrating SAST, DAST, software composition analysis, and container scanning into CI/CD pipelines
  • Experience securing Kubernetes and container environments, including pod security, network policies, RBAC, admission controls, and hardened/minimal base images
  • Experience with vulnerability scanning and remediation using Nessus, Trivy, Grype, or Qualys, including CVE triage and tracking
  • Experience with secrets management such as HashiCorp Vault and security automation using Python, Bash, or Go
  • Experience with Git-based workflows and CI/CD tooling such as GitLab CI, GitHub Actions, or Jenkins
  • Working knowledge of NIST 800-53, automated security evidence, and AWS or Azure cloud security
  • Understanding of network security, including segmentation and default-deny policies
  • U.S. citizenship required
  • Ability to obtain and maintain a favorable Public Trust investigation
  • Must meet FAA facility and information system access requirements
  • Continuous U.S. residency for at least 3 of the prior 5 years
  • Preferred: Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification
  • Preferred: Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS)
  • Preferred: Knowledge of software supply chain security, including SLSA, Sigstore/cosign, in-toto, and FIPS 140-3
  • Preferred: Experience with policy-as-code and infrastructure-as-code security scanning
  • Preferred: Experience securing Kubernetes/OpenShift environments and service mesh security
  • Preferred: Experience with GitOps deployment using ArgoCD, Flux, or equivalent
  • Preferred: Experience in aviation, FAA, or other safety-critical environments
  • Preferred: Experience with SAFe or large-scale Agile delivery

Benefits

Comp & perks
  • Hybrid work arrangement: 3 days onsite and 2 days working from home when within commuting distance
  • 100% remote consideration when not within commuting distance
  • Opportunity to work on mission-critical air traffic management systems
  • AI-assisted development, automation, and modern engineering practices