DevSecOps Security Engineer

Leidos

Confirmed live today High trust
Remote

Quick summary

Work type
Remote
Location
Gaithersburg, MDEagan, MNEgg Harbor Township, NJ
Salary
$87,100–$157,450 / yr
Employment
Full-time
Posted
1 day ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $162k
This role $122k
$74k most similar roles pay here $211k

This role pays less than 86% of similar roles. Most pay $126,800–$197,618 — the shaded band above. At the midpoint, this role pays about $122k versus about $162k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 350 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 299 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · DevSecOps Security Engineer

The DevSecOps Security Engineer joins the Air Traffic Business Area to support the development of the Leidos Common Automation Platform. This role focuses on building and operating automated security controls within a hybrid cloud data mesh architecture to enable next-generation air traffic management capabilities. You will implement and maintain SAST, DAST, software composition analysis, and container scanning in CI/CD pipelines while enforcing security gates, artifact signing, and SBOMs. Key responsibilities include hardening container images, managing Kubernetes security policies like RBAC and network policies, and implementing policy-as-code using OPA or Kyverno. You will utilize tools such as HashiCorp Vault, Nessus, Trivy, and Grype while leveraging Python, Bash, or Go for automation. The role addresses the challenge of maintaining a high security posture in mission-critical infrastructure through continuous monitoring and automated evidence production.

What you'll do

  • Implement and maintain automated security controls like SAST, DAST, and container scanning within CI/CD pipelines.
  • Enforce security gates, artifact signing, provenance verification, and SBOM generation to prevent unauthorized deployments.
  • Drive the hardening of container images and remediate critical or high-severity vulnerabilities.
  • Configure Kubernetes security controls including network policies, RBAC, admission controls, and security context constraints.
  • Secure workloads using secrets management, mutual TLS (mTLS), and service mesh policies.
  • Develop policy-as-code and infrastructure guardrails using tools like OPA/Rego or Kyverno.
  • Produce security evidence to support platform authorization and continuous monitoring requirements.
  • Triage vulnerabilities and perform root cause analysis for security incidents in partnership with application teams.

What we're looking for

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (additional experience/training may be considered in lieu of degree).
  • 4+ years of relevant experience.
  • Hands-on experience integrating SAST, DAST, software composition analysis, and container scanning into CI/CD pipelines.
  • Experience securing Kubernetes and container environments, including pod security, network policies, RBAC, admission controls, and hardened base images.
  • Experience with vulnerability scanning and remediation using tools such as Nessus, Trivy, Grype, or Qualys.
  • Experience with secrets management (HashiCorp Vault or equivalent) and security automation using Python, Bash, or Go.
  • Working knowledge of NIST 800-53, automated security evidence, and AWS or Azure cloud security.
  • U.S. citizenship required, with the ability to obtain a Public Trust and meet continuous U.S. residency requirements for at least 3 of the prior 5 years.
  • Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification (preferred).
  • Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS) (preferred).
  • Knowledge of software supply chain security, policy-as-code, and infrastructure-as-code security scanning (preferred).
  • Experience in aviation, FAA, or other safety-critical environments; experience with SAFe or large-scale Agile delivery (preferred).

More like this

Similar roles

DevSecOps Engineer

Booz Allen Hamilton

Fayetteville, NC 58 days ago
Kubernetes CI/CD Infrastructure as Code Ansible Terraform Python Bash AWS Azure Google Cloud Linux RHEL Ubuntu Prometheus Grafana ELK OpenSearch Istio ArgoCD Flux Harbor Nautobot NetBox Agile Scrum SAFe
5+ yrs exp

DevSecOps Engineer

Booz Allen Hamilton

Peterson AFB, CO 44 days ago $99,000–$225,000
Kubernetes Docker ArgoCD AWS EC2 EKS IAM Lambda SQS SNS RDS GitLab CI/CD Bash Python Prometheus Grafana Helm SBOM
10+ yrs exp

DevSecOps Engineer, Intelligent Platforms & Agents

Leidos

Remote 8 days ago $107,900–$195,050
DevSecOps Kubernetes CI/CD Terraform GitLab CI Python Bash Helm RKE2 K3S Infrastructure as Code GitOps Prometheus Grafana Vault SBOM CVE Scanning Linux RHEL Rocky Linux Security+
8+ yrs exp Remote

Mid-Level DevSecOps Engineer

Leidos

Gaithersburg, MD +3 35 days ago $87,100–$157,450
DevSecOps CI/CD Docker Kubernetes Terraform AWS Azure Python Bash PowerShell OpenShift CloudFormation GitLab CI GitHub Actions Jenkins AWS CDK ECS Zero Trust Architecture RMF STIGs
4+ yrs exp

DevSecOps Platform Engineer

Booz Allen Hamilton

Fayetteville, NC 63 days ago $77,500–$176,000
Kubernetes CI/CD Infrastructure-as-Code Ansible Terraform Python Bash Linux AWS Azure Google Cloud Prometheus Grafana ELK OpenSearch Istio ArgoCD Flux Harbor Nautobot NetBox RAG LLM Agile Scrum SAFe
8+ yrs exp

DevSecOps Engineer

Booz Allen Hamilton

Washington, DC 46 days ago $77,600–$176,000
DevSecOps CI/CD AWS Azure GCP Terraform CloudFormation CDK Docker Kubernetes Python Bash Go GitLab CI GitHub Actions PostgreSQL MySQL MongoDB Oracle Ansible Prometheus Grafana ELK Helmfile Flux Argo CD IaC SAST SCA
8+ yrs exp