Devsecops Engineer Jobs in District of Columbia
Devsecops engineer jobs in District of Columbia are concentrated in federal government contracting, defense, and cybersecurity, making the District one of the most active markets for this role anywhere in the country. Most hiring is in and around Washington DC and the Northern Virginia corridor, where major employers like Booz Allen Hamilton, Leidos, and General Dynamics Information Technology maintain large workforces. The most in-demand specialties are container security, CI/CD pipeline hardening, and FedRAMP compliance engineering. Find a role that fits below and apply directly.
Find Devsecops Engineer JobsOverview
Showing 5 of 24+ Devsecops Engineer jobs




DevSecOps Engineer
Department of Veterans Affairs Office of Information Security COSE Support
Position: Full-Time / Remote from Contractor Facility
Primary Work Location: Contractor facility within the United States; occasional coordinated support at VA Central Office, 811 Vermont Street NW, Washington, D.C.
JOIN OUR TEAM!
Caladwich is seeking a highly motivated, detail-oriented DevSecOps Engineer to support the Department of Veterans Affairs Office of Information Security Cybersecurity Operations and Security Engineering (COSE) program. The selected professional will integrate security into VA software delivery, cloud-native engineering, and operational workflows. This role builds automated security controls and testing into CI/CD pipelines while supporting secure, reliable, and compliant releases.
This position offers the opportunity to contribute directly to repeatable delivery of secure software and infrastructure with earlier detection and remediation of risk. The DevSecOps Engineer helps VA teams automate compliance, strengthen supply-chain security, and improve development speed without weakening controls.
WHO WE ARE:
Caladwich is a U.S.-based Service-Disabled Veteran-Owned Small Business (SDVOSB) and SBA 8(a) certified company providing professional services and mission support solutions to federal agencies worldwide. Our capabilities include Acquisition Support, Program Management, Logistics Support Services, Process Improvement, Asset Management, and Operational Support Services for DoD, DHS, VA, and GSA customers.
As a Veteran-owned company, our mission remains steadfast: Integrity. Solutions. Results.
Core Responsibilities
- Design, implement, and improve secure CI/CD pipelines for application, infrastructure, and cloud-native delivery environments.
- Integrate automated security testing, vulnerability scanning, policy enforcement, compliance checks, and evidence generation into DevOps workflows.
- Engineer hardened security controls using deployment scripts, infrastructure-as-code, configuration-management frameworks, and approved automation tools.
- Support container, orchestration, artifact repository, code repository, and cloud-native platform security.
- Perform or support security assessments, vulnerability management, remediation validation, incident response, and secure release readiness.
- Apply secure software development practices, code review, version control, branch protection, dependency management, and software supply-chain controls.
- Collaborate with developers, architects, security teams, and platform engineers to address threats, control gaps, and operational constraints.
- Develop pipeline patterns, reusable controls, metrics, technical documentation, and implementation guidance aligned with VA and Federal requirements.
Operational Support
- Coordinate with VA stakeholders, technical teams, system owners, and other contractors to resolve issues and keep work aligned with VA priorities.
- Develop, maintain, and submit accurate technical documentation, status information, and contract deliverables within required timeframes.
- Apply VA security, privacy, accessibility, records-management, and configuration-management requirements to all work products.
- Support risk, issue, dependency, schedule, and quality management activities, including corrective actions and continuous improvement.
- Protect VA information and systems, use approved collaboration and remote-access methods, and promptly report security or privacy concerns.
- Participate in meetings, reviews, briefings, and occasional travel as directed and approved under the task order.
- Monitor pipeline security results, prioritize findings, troubleshoot failed security gates, and support timely remediation.
- Evaluate and implement automation opportunities that reduce manual effort, review cycle time, and rework while preserving security and quality.
Required Qualifications
- Minimum 10 years of DevSecOps experience, including at least five years of Cybersecurity and Cloud Security experience at a large Government agency similar in size and scope to GSA, IRS, DoD, or VA.
- Expertise in DevSecOps or related fields, including CI/CD pipelines, containerization, cloud-native environments, software development, Git or comparable repositories, and version control.
- Cybersecurity experience that includes security assessments, vulnerability management, and incident response.
- Expertise integrating security tools into DevOps pipelines and automating security testing and compliance.
- Bachelor's degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or a related field.
- Certification in one or more of the following: IAT III, IAM III, or IASAE III.
- PWS substitution: IAT III, IAM III, or IASAE III certification may substitute for a relevant Bachelor's degree or four years of relevant experience.
Other Requirements
- Must be able to read, write, speak, and understand the English language.
- Must successfully complete and maintain the VA personnel vetting and background investigation requirements applicable to assigned work; PWS Tasks 5.1 through 5.9 are designated Tier 4 / High Risk.
- Must complete required fingerprinting, personnel security forms, security and privacy training, and Rules of Behavior acknowledgments within Government-established timelines.
- Must qualify for and properly safeguard any required VA Personal Identity Verification (PIV) credential and Government-furnished equipment.
- Must be available and responsive during core hours of 8:00 a.m. to 5:00 p.m. Eastern Time on normal Federal Government workdays.
- Must be able to work from a Contractor-provided facility and travel occasionally to VA Central Office in Washington, D.C., or other approved locations when coordinated in advance.
- Remote access to VA systems must occur only through VA-approved methods and from locations permitted by VA policy.
See All 24 Devsecops Engineer Jobs in District of Columbia
Find roles in District of Columbia that match your experience and apply in just a few clicks.
Find Devsecops Engineer JobsDevsecops Engineer Jobs by City in District of Columbia
Where District of Columbia roles are concentrated, by current openings.
Devsecops Engineer Job Market in District of Columbia
A snapshot from current District of Columbia openings, updated as new roles post.
Who's Hiring


Top Industries Hiring
- Government & Public Sector
What District of Columbia Employers Look For
The qualifications that appear most often in devsecops engineer jobs across District of Columbia.
- Active DoD security clearance, typically Secret or Top Secret with SCI eligibility
- Experience integrating security tooling into CI/CD pipelines using Jenkins or GitLab
- Proficiency with container security platforms such as Kubernetes, Docker, and Aqua Security
- Relevant certification such as CompTIA Security+, CISSP, or Certified DevSecOps Professional
- Hands-on experience with FedRAMP, NIST 800-53, or CMMC compliance frameworks
- Scripting and automation skills in Python, Bash, or Go for pipeline and infrastructure work
Devsecops Engineer Jobs in District of Columbia: Frequently Asked Questions
How do you become a devsecops engineer in District of Columbia?
Most devsecops engineer roles in District of Columbia require a bachelor's degree in computer science, information systems, or a related field combined with hands-on experience in both software development and security operations. The District has no state-issued license for this role, but federal contractors in DC require candidates to hold or be eligible for a DoD security clearance, which involves a background investigation process managed through the Defense Counterintelligence and Security Agency. Certifications like CompTIA Security+ or CISSP significantly strengthen candidacy with DC-area federal contractors.
How much do devsecops engineers make in District of Columbia?
Devsecops engineers in District of Columbia earn a median of about $136,880 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $85,140 for the lowest 10% to over $197,000 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire devsecops engineers in District of Columbia?
District of Columbia devsecops engineer roles are posted by Sciata, E Logic, and Rackner and others right now, based on current listings on Migrate Mate as of September 2026. The DC market skews heavily toward large federal contractors and defense agencies, so cleared candidates and those with FedRAMP or NIST framework experience tend to see the broadest range of active openings.
Which District of Columbia cities have the most devsecops engineer jobs?
The cities with the most devsecops engineer openings in District of Columbia are Washington. Washington DC anchors the market as the seat of federal agencies and the headquarters of major defense contractors, while neighboring areas in the Northern Virginia corridor draw significant hiring from the dense concentration of cleared contractor offices, intelligence community facilities, and cloud infrastructure operations tied to government contracts.
Are there remote devsecops engineer jobs in District of Columbia?
Yes, and more than many technical roles, since devsecops work is largely code and pipeline driven. About 79% of devsecops engineer openings tied to District of Columbia are remote or hybrid as of September 2026, though positions requiring access to classified systems or government facilities remain largely on-site. Pipeline automation, vulnerability scanning, and security tooling integration tasks are the parts of the role most likely to be performed fully remotely.
How can I get hired as a devsecops engineer in District of Columbia with little or no experience?
The most realistic entry path is moving laterally from a software development or systems administration role into a junior devsecops position at a mid-size federal contractor, where employers like SAIC or Peraton regularly bring on associate-level engineers and provide on-the-job security training. Earning CompTIA Security+ before applying immediately broadens eligibility, since many DC-area contractor roles require it at the entry level. Internship programs at federal agencies such as NSA and CISA also provide a direct pipeline into cleared devsecops work for early-career candidates.
Where can I find and apply to devsecops engineer jobs in District of Columbia?
You can find and apply to devsecops engineer jobs in District of Columbia on Migrate Mate, which lists current openings across the District. Search the listings, find roles that match your experience and clearance level, and apply directly to the ones that fit.
See All 24 Devsecops Engineer Jobs in District of Columbia
Find roles in District of Columbia that match your experience and apply in just a few clicks.
Find Devsecops Engineer Jobs