Remote Devsecops Engineer Jobs
Remote Devsecops Engineer jobs are open across cybersecurity, cloud infrastructure, fintech, and enterprise software at remote-first companies and distributed engineering teams, from entry-level security automation roles to senior platform engineering positions. Employers hiring remotely right now include CVS Health, Entarian, and Connected Logistics. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 41+ Remote Devsecops Engineer jobs









Since 2004, Millennium has operated at the forefront of cybersecurity. Our elite team of over 300 professionals brings an unmatched record of performance across Red Team Operations, Defensive Cyber Operations, Software Engineering, and Technical Engineering. As home to the largest contingent of contracted Red Team operators supporting the Department of Defense, Millennium delivers unparalleled threat intelligence and battle-tested expertise to both DoD and federal civilian customers.
Millennium Corporation is seeking a Cybersecurity Engineer – DevSecOps to support cybersecurity, software assurance, and security engineering activities within a DoD/DoN environment. This position is 100% remote and will focus on integrating cybersecurity throughout the software development and delivery lifecycle, with an emphasis on application security, CI/CD pipeline security, container security, vulnerability management, and DoD cybersecurity compliance.
Candidates located in or near major U.S. Navy installations are preferred, with priority given to candidates in the New Orleans, Orlando, and Washington, DC metropolitan areas. Candidates located near other major Navy facilities may also be considered.
Key Responsibilities
- Conduct code and container vulnerability assessments using approved DoD vulnerability scanning tools, DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and other DoD/DoN software assurance tools.
- Implement and assess operating system security configurations in accordance with applicable DISA STIGs and SRGs.
- Perform cybersecurity assessments, security audits, and risk analyses to identify vulnerabilities and compliance gaps.
- Apply security testing methodologies, including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), throughout the software development lifecycle.
- Review and implement cybersecurity policies and security controls within CI/CD pipelines to support secure software delivery and DoD/DoN requirements.
- Serve as a GitLab security reviewer and approver for merge requests, reviewing security scan results and verifying that identified findings are remediated or appropriately documented through the approved risk-management process prior to release.
- Review GitLab SAST, dependency, secret detection, and container scanning results; coordinate remediation activities with development teams and track findings through closure.
- Review changes to GitLab security policies, pipeline controls, and protected branch settings to ensure required security checks and approvals remain properly enforced.
- Provide cybersecurity oversight for containerized workloads using NeuVector, including review of vulnerability findings, admission control decisions, and runtime security alerts.
- Collaborate with application and platform teams to investigate NeuVector findings, tune security policies, and document remediation actions or accepted risks.
- Ensure security-related provisions within system acquisition and program documentation address identified cybersecurity requirements.
- Provide cybersecurity guidance and assist with developing mitigation strategies for DoD information systems.
- Prepare Risk Management Framework (RMF) artifacts and Memoranda of Agreement (MoAs) with system owners supporting interface and networking implementations.
- Identify and evaluate Common Criteria and National Information Assurance Partnership (NIAP) certified technologies when applicable.
- Evaluate cybersecurity products and technologies used by programs to validate compliance with applicable DoD/DoN requirements.
- Support cybersecurity activities across the software lifecycle and collaborate with engineering, development, platform, and program teams to address security requirements and risks.
Qualifications:
- Active Secret clearance.
- Bachelor's degree with 8 years of relevant experience, or a high school diploma/equivalent with 13 years of relevant experience.
- Experience working within the DoD Risk Management Framework (RMF) and familiarity with DoDI 8510.01.
-
An Information Assurance Manager (IAM) Level II certification in accordance with DoD 8570.01-M, such as:
- CISSP
- GSLC
- CISM
- Experience with DoD cybersecurity requirements, including DISA STIGs and SRGs.
- Experience with software security testing methodologies, including SAST and DAST.
- Experience supporting cybersecurity within CI/CD or DevSecOps environments.
- Experience with GitLab security tools and processes, including reviewing security scan results and supporting vulnerability remediation.
- Candidates should be located in or near a major U.S. Navy installation. Preferred locations include New Orleans, LA; Orlando, FL; and the Washington, DC metropolitan area. Candidates near other major Navy facilities may also be considered.
Preferred Qualifications
- Proficiency with GitLab, NeuVector, and Sonatype.
- Experience with container security and vulnerability management.
- Experience supporting cybersecurity within a DoD or Department of the Navy (DoN) environment.
- Experience with the Navy's Rapid Assess and Incorporate Software Engineering (RAISE) methodology.
- Experience with the RAISE Platform of Choice (RPOC).
- Experience evaluating Common Criteria and NIAP-certified technologies.
- Experience developing or supporting RMF artifacts, security documentation, and cybersecurity mitigation strategies.
- Must be comfortable with prolonged periods of sitting at a desk and working on a computer.
- Must be able to lift up to 10-15 pounds at a time.
$125,000- $135,000
The salary range provided for this position is intended as a general guideline and does not guarantee a specific salary or compensation amount. Final compensation will be determined based on a variety of factors, including, relevant education, experience, knowledge, skills, and abilities
See All 41 Remote Devsecops Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Devsecops Engineer Job Market
Who's Hiring


Top Industries Hiring
- Insurance
- Healthcare & Medical Services
What Employers Look For
The qualifications that appear most often in remote devsecops engineer jobs.
- Experience securing CI/CD pipelines using tools such as Jenkins, GitHub Actions, or GitLab CI
- Proficiency with infrastructure-as-code tools including Terraform, Ansible, or CloudFormation
- Hands-on knowledge of container security in Kubernetes or Docker environments
- Familiarity with cloud security controls across AWS, Azure, or Google Cloud Platform
- Experience with SAST, DAST, or SCA tooling integrated into development workflows
- Bachelor's degree in computer science, cybersecurity, or a related technical field
Tips for Your Remote Devsecops Engineer Job Search
Apply early to remote roles that fit
Migrate Mate lists remote devsecops engineer openings from across the U.S. in one place, so you can find roles that match your stack and security focus and apply directly without sorting through mixed location listings.
Build a public security automation portfolio
Remote hiring managers can't watch you work, so your GitHub needs to do it for them. Publish IaC modules, SAST pipeline configurations, or container hardening scripts that show you own the full security automation cycle, not just individual tools.
Write your resume for async security teams
Remote devsecops teams communicate in Jira, Confluence, and Slack threads, not standups. Your resume should name the documentation and incident communication tools you've used and show outcomes you shipped without close supervision, like reducing pipeline vulnerability findings or cutting deployment risk metrics.
Prepare for remote technical screens on live infrastructure
Remote devsecops interviews often include live coding or architecture sessions over video where you configure a pipeline, review a Terraform plan, or walk through a threat model. Practice narrating your reasoning clearly while working, since remote teams screen for communication as much as technical ability.
Remote Devsecops Engineer Jobs: Frequently Asked Questions
How do I get a remote devsecops engineer job?
Remote devsecops engineer roles go to candidates who can demonstrate self-direction and communicate clearly in writing without relying on in-person context. Remote-first companies and distributed security teams screen for fluency with infrastructure-as-code tools like Terraform and Ansible, CI/CD pipeline ownership, and cloud security frameworks across AWS, Azure, or GCP. Showing async work habits, documented runbooks, and a GitHub history of security tooling gives you a concrete edge over equally skilled candidates.
Which companies hire remote devsecops engineers?
Companies hiring remote devsecops engineers right now include CVS Health, Entarian, and Connected Logistics, based on current remote listings on Migrate Mate as of September 2026. Remote devsecops roles concentrate at remote-first software companies, cloud-native startups, fintech platforms, and large enterprises running distributed security and infrastructure teams.
Can you get a remote devsecops engineer job with no experience?
Yes, but remote entry-level devsecops roles are harder to land because employers expect you to troubleshoot independently without tapping someone on the shoulder. Cloud-native startups and remote-first SaaS companies are the most likely to hire early-career candidates. A portfolio of personal or open-source projects showing CI/CD pipelines, security scanning automation, or IaC configurations gives hiring managers something concrete to evaluate in place of a work history.
Do you need a degree for remote devsecops engineer jobs?
Not always. Remote employers in devsecops weigh certifications like AWS Security Specialty, Certified Kubernetes Security Specialist, or CompTIA Security Plus heavily alongside a demonstrated portfolio of real work. Distributed teams care most about whether you can own a pipeline, ship secure infrastructure, and communicate findings clearly in writing. A degree helps in regulated industries, but it rarely outweighs hands-on skill evidence for remote devsecops roles.
Which industries hire the most remote devsecops engineers?
The sectors hiring the most remote devsecops engineers are Insurance and Healthcare & Medical Services, based on current remote listings on Migrate Mate as of September 2026. These sectors rely on distributed engineering teams running continuous delivery pipelines and cloud infrastructure at scale, making fully remote devsecops work a natural operational fit.
See All 41 Remote Devsecops Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs