Devsecops Engineer Jobs
Devsecops engineer jobs are open across financial services, healthcare, government contracting, and technology, from mid-level to staff and principal, with specializations in cloud security automation, container security, and CI/CD pipeline hardening. Find a role that fits from the openings below and apply directly.
Find Devsecops Engineer JobsLooking for remote work? View remote devsecops engineer jobs →Overview
Showing 5 of 325+ Devsecops Engineer jobs









Title:
DevSecOps EngineerBelong. Connect. Grow. with KBR!
KBR provides innovative and cost-effective services and solutions to national security and industry customers. We are leading the way for national security and commercial space integration, developing innovative solutions to tomorrow's challenges today. This position supports the Strategic and Long-Range Communications Group at MIT Lincoln Laboratory.
We are seeking a DevSecOps Engineer to contribute to the design, development, implementation, and testing of software for a series of large-scale communications system demonstrations. Work will be performed in a disciplined collaborative environment, employing modern programming practices. A hybrid work location possible for this position. These services shall be provided in support of several Laboratory and Government test sites.
Why Join Us?
- Innovative Projects: Enable critically important communications over vast distances by being the team member to innovate and overcome technical challenges as we spearhead new solutions through advanced prototyping.
- Collaborative Environment: Come join a team of enthusiastic engineers engaged in creating the next generation of cutting-edge laser communication systems technology.
- Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense and/or defense.
Key Responsibilities:
- Serve as the DevSecOps subject-matter expert and architectural authority
- Define standards, reference architectures, and best practices used across teams
- Design and implement secure, scalable, and highly available cloud and hybrid platforms
- Embed security controls directly into:
- CI/CD pipelines
- Infrastructure‑as‑code
- Container platforms and deployment workflows
- Evaluate, select, and integrate DevSecOps tooling, including
- SAST, DAST, SCA
- Secrets management, encryption, and identity integration
- Container security
- Lead implementation of containerized platforms (Docker, Kubernetes, OpenShift, etc.)
- Integrate identity access management, secrets management, and encryption into pipelines and platforms
- Troubleshoot complex system, pipeline, and security issues across environments
- Act as a trusted technical advisor to engineering, security, and platform teams
- Mentor engineers and elevate DevSecOps maturity across the organization
- Lead technical reviews, architecture discussions, and root cause analyses
- Communicate risk, tradeoffs, and recommendations clearly to technical and non-technical leadership
- Actively maintain security vulnerability assessment databases for third-party application dependency scans and operating system level scans
- Actively monitor GitLab Security Dashboards for new vulnerabilities detected in software products and work with developers to remediate
- Maintain and enforce compliance frameworks across projects
- Maintain the software release pipeline
- Ensure base container images are regularly updated to include latest security patches and updates
Work Environment:
- Location: On-site at MIT LL in Lexington, MA. Hybrid possible.
- Travel Requirements: Willing and able to travel (up to 10%, typically CONUS)
- Working Hours: Standard
Required Qualifications:
- Security Clearance: Secret
- Education: Bachelors in Computer Science, Computer Engineering, Electrical Engineering, or related field
- Work Experience: 5 to 10 years of experience in software development, systems engineering, platform engineering, or DevOps roles
- Containerization Technologies: Expert level experience building container images with Podman, Docker, Kaniko, Skopeo. Familiarization with Universal Base Images (UBI). Familiarization with k3s and k8s desired.
- GitLab CI/CD: Expert-level experience building and optimizing build pipelines. To include use of CI templates or CI components.
- Security Integration: Proficiency in implementing security scan execution policies and pipeline security scans. Familiar with Trivy, Semgrep, and Gemnasium (or other SBOM based dependency scans).
- Software Proficiency: Expert-level experience with package managers for Java, Python and Node.
- Operating Systems: Proficient with Red Hat Enterprise Linux 8.10 or higher.
Basic Compensation:
For MA only, the salary range is approximately $126,900 - $190,400 USD annually. The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity.
Ready to Make a Difference?
If you’re excited about making a significant impact in the field of space defense and working on projects that matter, we encourage you to apply and join our team at KBR. Let's shape the future together.
Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together.
KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.
Devsecops Engineer Jobs by Experience Level
See All 325+ Devsecops Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Devsecops Engineer JobsDevsecops Engineer Job Market
Who's Hiring
- Leidos14

- SAIC9

- Lockheed Martin8

- CACI International8

- Booz Allen Hamilton7

Top Industries Hiring
- Technology & Software
- Consulting & Professional Services
- Healthcare & Medical Services
- Aerospace & Defense
- Airlines
What Employers Look For
The qualifications that appear most often in devsecops engineer jobs.
- Experience securing CI/CD pipelines using tools such as Jenkins, GitHub Actions, or GitLab CI
- Proficiency with infrastructure-as-code tools including Terraform, Ansible, or CloudFormation
- Hands-on knowledge of container security in Kubernetes or Docker environments
- Familiarity with cloud security controls across AWS, Azure, or Google Cloud Platform
- Experience with SAST, DAST, or SCA tooling integrated into development workflows
- Bachelor's degree in computer science, cybersecurity, or a related technical field
Tips for Your Devsecops Engineer Job Search
Tailor your resume to the stack
Hiring managers scan for specific tools before reading anything else. List the exact platforms you've worked with, such as Terraform, Kubernetes, Vault, or Falco, in a dedicated skills section so your resume clears automated filters quickly.
Certify before you apply to federal roles
Government and defense contractors almost always require a DoD 8570 or 8140 baseline certification like Security+ or CISSP. If you're targeting those postings, confirm your certification is active and list it prominently near the top of your resume.
Apply early to roles that fit
Migrate Mate lists devsecops engineer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Show pipeline ownership, not participation
Recruiters distinguish candidates who built and owned secure CI/CD pipelines from those who contributed to them. Describe the scope of what you owned, the threat model you addressed, and the measurable outcome, rather than listing tools you touched.
Prepare for a live threat-modeling exercise
Many devsecops engineer interviews include a whiteboard or collaborative threat-modeling session rather than a purely algorithmic coding round. Practice walking through an architecture diagram, naming attack surfaces, and proposing controls out loud before your first technical screen.
Negotiate on scope before salary
Devsecops roles vary widely in actual authority. Before discussing compensation, clarify whether the role has enforcement power over developers or is purely advisory. That distinction changes the job's day-to-day demands and your leverage in the offer conversation.
Devsecops Engineer Jobs: Frequently Asked Questions
Which companies are hiring the most devsecops engineers?
The companies hiring the most devsecops engineers right now include Leidos, SAIC, and Lockheed Martin, with the largest share of openings in Virginia, Alabama, and Maryland, based on current listings on Migrate Mate as of September 2026. Demand is concentrated in technology, defense contracting, and financial services.
How many devsecops engineer jobs are remote?
About 62% of devsecops engineer openings are fully remote or hybrid as of September 2026, making it one of the more distributed roles in the security field. Cloud-focused and platform engineering sub-areas tend to offer the most remote flexibility, while roles involving classified systems or on-premises infrastructure typically require in-office presence.
How do you become a devsecops engineer?
Start with a foundation in either software development or systems administration, then layer in security fundamentals through a certification like Security+ or Certified Kubernetes Security Specialist. Build practical experience by hardening CI/CD pipelines in personal or open-source projects, then move into a security engineering or platform engineering role where you can take on devsecops responsibilities directly.
Can you get hired as a devsecops engineer without direct experience?
Yes, candidates with strong software engineering or cloud infrastructure backgrounds can transition into devsecops engineer roles by demonstrating security depth through certifications and hands-on projects. Contributing to open-source security tooling, publishing a pipeline-hardening write-up, or earning a cloud security specialty credential signals practical readiness to hiring managers who are evaluating non-traditional backgrounds.
What does the devsecops engineer interview process look like?
Most devsecops engineer interviews include an initial recruiter screen, a technical phone interview covering CI/CD and security tooling, and a practical round that often involves a threat-modeling exercise or a live pipeline review. Final rounds typically include a system design conversation focused on secure architecture and a behavioral interview with engineering leadership assessing cross-functional collaboration.
Where can I find and apply to devsecops engineer jobs?
You can find and apply to devsecops engineer jobs on Migrate Mate, which lists current openings from across the United States. Find roles that match your experience and specialization, then apply directly to each listing from the page.
See All 325+ Devsecops Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Devsecops Engineer Jobs