DevSecOps Project Lead (Sr DevSecOps Engineer)

DEFCON AI

Apply Now
United States
$175,000 - $215,000 / year
full-time
senior
Posted August 5, 2026
via himalayas

About This Role

ABOUT DEFCON AI RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems. In today s dynamically changing world, DEFCON AI s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions. About the Role As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy. This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer's security and accreditation staff. We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government's timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required. Key Responsibilities First Deliverable: Platform Into the Government Environment • Own the initial platform deployment into the government IL-5 environment, which is the program's first contract deliverable and lands early. • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build. • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them. • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy. Platform and Pipeline Ownership • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production. • Establish and operate development, test, and production environments in AWS GovCloud at IL-5. • Build the platform so it is reusable across programs rather than rebuilt for each one. Cloud and Infrastructure Architecture • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images. • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer's cloud and security staff. • Design for zero-downtime deployment and rehearsed rollback. • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them. • Integrate CAC / PIV authentication and role-based access control. Security Engineering and Authorization Support • Implement security controls from week one and produce the control evidence continuously from the pipeline. • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions. • Serve as the engineering counterpart to the customer's security and accreditation staff, and support the authorization decision on their timeline. • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand. • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows. Release Management and Delivery Performance • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines. • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service. • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real...

Ready to Apply?

Click the button below to visit the company's application page.

Apply for this Position