DevSecOps Engineer

Description
DevSecOps Engineer
Department of Veterans Affairs Office of Information Security COSE Support
Position: Full-Time / Remote from Contractor Facility
Primary Work Location: Contractor facility within the United States; occasional coordinated support at VA Central Office, 811 Vermont Street NW, Washington, D.C.
JOIN OUR TEAM!
Caladwich is seeking a highly motivated, detail-oriented DevSecOps Engineer to support the Department of Veterans Affairs Office of Information Security Cybersecurity Operations and Security Engineering (COSE) program. The selected professional will integrate security into VA software delivery, cloud-native engineering, and operational workflows. This role builds automated security controls and testing into CI/CD pipelines while supporting secure, reliable, and compliant releases.
This position offers the opportunity to contribute directly to repeatable delivery of secure software and infrastructure with earlier detection and remediation of risk. The DevSecOps Engineer helps VA teams automate compliance, strengthen supply-chain security, and improve development speed without weakening controls.
WHO WE ARE:
Caladwich is a U.S.-based Service-Disabled Veteran-Owned Small Business (SDVOSB) and SBA 8(a) certified company providing professional services and mission support solutions to federal agencies worldwide. Our capabilities include Acquisition Support, Program Management, Logistics Support Services, Process Improvement, Asset Management, and Operational Support Services for DoD, DHS, VA, and GSA customers.
As a Veteran-owned company, our mission remains steadfast: Integrity. Solutions. Results.
Core Responsibilities
· Design, implement, and improve secure CI/CD pipelines for application, infrastructure, and cloud-native delivery environments.
· Integrate automated security testing, vulnerability scanning, policy enforcement, compliance checks, and evidence generation into DevOps workflows.
· Engineer hardened security controls using deployment scripts, infrastructure-as-code, configuration-management frameworks, and approved automation tools.
· Support container, orchestration, artifact repository, code repository, and cloud-native platform security.
· Perform or support security assessments, vulnerability management, remediation validation, incident response, and secure release readiness.
· Apply secure software development practices, code review, version control, branch protection, dependency management, and software supply-chain controls.
· Collaborate with developers, architects, security teams, and platform engineers to address threats, control gaps, and operational constraints.
· Develop pipeline patterns, reusable controls, metrics, technical documentation, and implementation guidance aligned with VA and Federal requirements.
Operational Support
· Coordinate with VA stakeholders, technical teams, system owners, and other contractors to resolve issues and keep work aligned with VA priorities.
· Develop, maintain, and submit accurate technical documentation, status information, and contract deliverables within required timeframes.
· Apply VA security, privacy, accessibility, records-management, and configuration-management requirements to all work products.
· Support risk, issue, dependency, schedule, and quality management activities, including corrective actions and continuous improvement.
· Protect VA information and systems, use approved collaboration and remote-access methods, and promptly report security or privacy concerns.
· Participate in meetings, reviews, briefings, and occasional travel as directed and approved under the task order.
· Monitor pipeline security results, prioritize findings, troubleshoot failed security gates, and support timely remediation.
· Evaluate and implement automation opportunities that reduce manual effort, review cycle time, and rework while preserving security and quality.
Requirements
Required Qualifications
· Minimum 10 years of DevSecOps experience, including at least five years of Cybersecurity and Cloud Security experience at a large Government agency similar in size and scope to GSA, IRS, DoD, or VA.
· Expertise in DevSecOps or related fields, including CI/CD pipelines, containerization, cloud-native environments, software development, Git or comparable repositories, and version control.
· Cybersecurity experience that includes security assessments, vulnerability management, and incident response.
· Expertise integrating security tools into DevOps pipelines and automating security testing and compliance.
· Bachelor's degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or a related field.
· Certification in one or more of the following: IAT III, IAM III, or IASAE III.
· PWS substitution: IAT III, IAM III, or IASAE III certification may substitute for a relevant Bachelor's degree or four years of relevant experience.
Other Requirements
· Must be able to read, write, speak, and understand the English language.
· Must successfully complete and maintain the VA personnel vetting and background investigation requirements applicable to assigned work; PWS Tasks 5.1 through 5.9 are designated Tier 4 / High Risk.
· Must complete required fingerprinting, personnel security forms, security and privacy training, and Rules of Behavior acknowledgments within Government-established timelines.
· Must qualify for and properly safeguard any required VA Personal Identity Verification (PIV) credential and Government-furnished equipment.
· Must be available and responsive during core hours of 8:00 a.m. to 5:00 p.m. Eastern Time on normal Federal Government workdays.
· Must be able to work from a Contractor-provided facility and travel occasionally to VA Central Office in Washington, D.C., or other approved locations when coordinated in advance.
· Remote access to VA systems must occur only through VA-approved methods and from locations permitted by VA policy.
You'll be redirected to
the company's application page