Peraton is seeking a Senior DevSecOps Engineer to serve as the technical lead for DevSecOps and cloud transformation across a large AWS enterprise environment spanning both commercial and GovCloud. This role will help modernize software delivery by building secure, automated, and repeatable development and deployment processes with security built in from the start.
Location: Remote
Shift Schedule: 8am – 5pm Eastern Standard Time (EST)
What you will do:
DevSecOps Pipelines and Security Automation
- Design and manage GitLab CI/CD pipelines using reusable templates, shared runners, feature flags, environment gates, and DORA metrics.
- Automate SAST, DAST, SCA, and secrets scanning as required pipeline stages, with policy-based gates that prevent insecure builds from promotion.
- Integrate container scanning, registry admission controls, and runtime protection using Aqua Security to enforce Kubernetes and CIS benchmarks.
- Scan Terraform and Kubernetes configurations for security issues and remediate findings before deployment.
- Lead Jenkins-to-GitLab CI/CD migrations and establish standardized pipeline patterns for application teams
Container Platforms and Cloud Infrastructure
- Operate containerized workloads on OpenShift (ROSA) and Amazon EKS across AWS Commercial and GovCloud, including Spring Boot and other microservices.
- Automate AWS and Kubernetes infrastructure with Terraform and use Ansible/Ansible Tower for configuration management, hardening, and patching.
- Engineer AWS services including EC2, VPC, IAM, S3, EBS, ELB/ALB/NLB, Route 53, and CloudWatch, using least-privilege IAM as the baseline.
- Implement GitOps workflows so infrastructure, application, and cluster configurations are version-controlled, reviewable, and reproducible.
App Enablement and Developer Self-Service
- Build reusable Terraform modules and GitLab templates that allow application teams to provision namespaces, environments, and supporting AWS resources without platform-team tickets.
- Design self-service onboarding workflows covering repository creation, CI/CD setup, RBAC and quotas, and security-gate enrollment.
Publish standardized GitLab pipeline templates and golden-path patterns so security, compliance, and observability are built in automatically. - Maintain onboarding documentation and module catalogs, and use adoption and onboarding metrics to identify and remove friction.
Security, Compliance, and Identity
- Implement and enforce STIG, CIS, and organizational security requirements across pipelines, platforms, and workloads.
- Design and manage AWS and Kubernetes IAM, including RBAC, admission controls, pod security, network policies, and secrets management using AWS KMS and Secrets Manager.
- Support vulnerability management, ATO and accreditation activities, audits, and continuous compliance reporting across FedRAMP and DoD environments.
Observability, Incident Response, and Reliability
- Operate observability platforms including Datadog, Dynatrace, Splunk, OpenTelemetry, CloudWatch, and OpenSearch for metrics, logs, traces, dashboards, and alerting.
- Lead critical incident response, including real-time diagnostics, stakeholder and executive communication, root-cause analysis, and corrective actions through resolution.
- Facilitate cross-team root-cause reviews and drive resulting reliability improvements through implementation.
Leadership and Delivery
- Lead transformation initiatives across AI, advanced analytics, and emerging technologies, translating strategy into actionable engineering roadmaps and technical responses to RFIs.
- Establish engineering standards, review architecture, and mentor engineers across DevSecOps, cloud, security, and automation.
- Identify and improve inefficient processes and actively participate in Agile delivery to evolve business processes and technology.