Skip to main content
Concept Plus

DevSecOps Lead

RemoteUnited States only
Published
Role
DevOps
Experience
Senior
Employment
Full-time
Company size
Mid-size
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Experienced DevSecOps Lead needed for secure CI/CD pipelines, automated testing, and IaC for Oracle eBusiness applications on OCI. Requires 5+ years of hands-on DevSecOps experience, proficiency with YAML, Ansible, Git, Jenkins, Terraform, and Kubernetes. Must have an active Secret clearance and DoD 8140/8570 IAT-II or higher certification.

Core skills

DevSecOpsCI/CDInfrastructure as Code

Required skills

YAMLAnsibleGitJenkinsGitLab CI/CDTerraformKubernetesSASTDASTsoftware composition analysiscontainer image scanningunit testingintegration testingregression testingperformance testingDoD RMFOCI DevOps servicesOCI Artifact RegistryOCI Vault

Optional skills

FlexDeployOracle eBSOracle Fusion MiddlewareSOA SuiteWebLogicDISA-managedCloud OneIL4/IL5 authorization

Required languages

English

What you'll do

  • Design, implement, and maintain secure CI/CD pipelines using Jenkins, GitLab CI/CD, or comparable enterprise tooling to automate build, test, and deployment workflows for all common services on OCI
  • Develop and maintain Infrastructure as Code (IaC) using Ansible, YAML, and Terraform to automate environment provisioning, configuration management, and compliance enforcement across OCI environments
  • Architect, deploy, and manage containerized workloads using Kubernetes (K8s) or OCI Container Engine (OKE), including cluster configuration, workload scheduling, secrets management, and runtime security controls
  • Integrate SAST, DAST, software composition analysis (SCA), and container image scanning tools into all CI/CD pipelines to enforce security-left practices throughout the development lifecycle
  • Establish and maintain a comprehensive automated test framework — including unit, integration, regression, and performance testing — in support of the Government's Test Automation objectives
  • Enforce code quality, branching strategies, and version control governance across all development teams using Git (GitHub, GitLab, or equivalent)
  • Embed DoD RMF controls and security compliance checks into CI/CD workflows to support continuous ATO and audit readiness
  • Collaborate with the Cybersecurity Lead/ISSO to ensure all pipeline artifacts, container images, and deployed services meet required security scanning thresholds and DoD 8140/8570 compliance baselines
  • Lead DevSecOps toolchain onboarding, training, and standards adoption across all integrated team members
  • Monitor pipeline performance, test coverage metrics, and deployment frequency; report results to the Program Manager and Government stakeholders as part of recurring performance reporting
  • Support the Technical Lead in aligning DevSecOps practices with the OCI platform architecture, including OCI DevOps services, OCI Artifact Registry, and OCI Vault
  • Develop and maintain automated patching, configuration compliance, and vulnerability remediation workflows to support 24/7/365 operational sustainment requirements
  • Contribute to AI/ML integration efforts by implementing automated pipelines for model training, validation, and deployment within the authorized OCI environment
  • Support transition-in activities by assessing the incumbent's existing pipeline tooling, identifying gaps, and migrating to the team's DevSecOps toolchain with no disruption to operations

What they require

  • US Citizen
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related technical field
  • 5+ years of hands-on DevSecOps, platform engineering, or software delivery engineering experience
  • Proficiency with YAML for configuration, pipeline, and IaC definition
  • Hands-on experience with Ansible for configuration management and automated provisioning
  • Proficiency with Git-based version control (GitHub, GitLab, Bitbucket, or equivalent) and branching/merge strategies
  • Hands-on experience designing and maintaining CI/CD pipelines using Jenkins, GitLab CI/CD, or comparable enterprise pipeline tooling
  • Demonstrated experience implementing Infrastructure as Code (IaC) using Terraform, including state management, module design, and automated compliance enforcement
  • Demonstrated experience deploying and managing containerized applications using Kubernetes (K8s), including cluster administration, Helm charts, namespace management, and workload security
  • Experience integrating SAST, DAST, and security scanning tools into automated pipelines (e.g., SonarQube, Fortify, Checkmarx, Twistlock/Prisma Cloud, or equivalent)
  • Experience building and maintaining automated test frameworks for web services, APIs, or enterprise applications
  • Familiarity with DoD RMF, ATO processes, and embedding security compliance into development and deployment pipelines
  • Active DoD Secret clearance required to start; must be maintainable for the duration of the program
  • Active DoD 8140/8570 IAT-II or higher certification required at time of hire (qualifying certifications include CompTIA Security+ CE, CompTIA CySA+, GSEC, SSCP, GICSP, CND, or any IAT-III equivalent such as CASP+ CE, CISSP, CISA, CCNP Security, GCED, or GCIH)
  • Active Top Secret (TS) security clearance; candidates holding an active TS clearance will be given strong preference as the program's operational scope and data sensitivity may require TS access
  • Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.

Benefits

  • competitive pay
  • comprehensive health, dental, and vision insurance
  • paid life insurance
  • paid time off
  • 11 paid holidays
  • performance bonuses
  • tuition reimbursement
  • unlimited training
  • the opportunity to thrive in a collaborative, flexible, and innovative environment

Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm. Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.

🇺🇸 United StatesFintechMid-size

Details

Visa sponsorshipNo
Salary not disclosed