Base Career helps you apply smarter for this job.
Key skills for this role
The Lead DevSecOps & Compliance Engineer is a senior technical leader responsible for embedding security, auditability, and compliance automation across the full software delivery lifecycle. This role ensures the platform is secure by design, continuously compliant, and aligned with Zero Trust principles. Working at the intersection of cybersecurity, DevOps, and compliance engineering, this engineer defines and enforces platform-wide security policies, hardens build and deployment processes, and maintains traceability of technical controls to federal mandates such as FIAR, NDAA, FedRAMP, and Zero Trust Architecture.
This role operates as a core member of the technical leadership team, collaborating with cloud platform engineers, backend developers, AI/ML teams, and project leadership to safeguard every layer of the stack—from infrastructure to middleware to deployment artifacts. The ideal candidate brings deep hands-on experience implementing and maintaining Azure infrastructure (especially AKS and Mission Landing Zones), security automation, policy-as-code, and compliance in a federal environment.
U.S. Citizenship is required and the candidate must be able to obtain and maintain a U.S. Secret security clearance. This is a hybrid, full-time position with an onsite requirement of 3 days a week at our Crystal City HQ.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Arlington, USA
Arlington, USA
Arlington, USA
Arlington, USA
Arlington, USA
Arlington, USA
Arlington, USA
Arlington, USA
Arlington, USA
Critical Skills (Must-Have)
Demonstrated experience implementing and maintaining Azure infrastructure in production, including AKS and Mission Landing Zones (MLZs).
Strong AKS operations experience: upgrades, node pools, ingress, RBAC/Entra ID, policy enforcement, and observability.
MLZ/landing zone governance: management groups, Azure Policy, hub-and-spoke networking, identity integration, and private networking patterns.
Experience securing and operating Azure Database for PostgreSQL Flexible Server (networking/private access, backups/restore, HA, and hardening).
Experience deploying and securing RabbitMQ (TLS, access control, monitoring/alerting, and operational maintenance).
Professional Experience & Qualifications
7+ years of experience in DevSecOps , cloud security, infrastructure security, or platform security for production systems.
Hands-on experience with CI/CD pipeline security (e.g., GitHub Actions, GitLab CI/CD, Bitbucket Pipelines) and automated security testing (SAST/DAST/SCA/SBOM).
Hands-on experience with Azure security foundations, including: Entra ID, VNets /NSGs, Private Link, Key Vault, and Azure Monitor/Log Analytics.
Proven experience mapping technical controls to federal compliance frameworks (e.g., NIST 800-53, FedRAMP; plus FIAR/NDAA where applicable).
Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or a related technical field.
CISSP, CISM, or equivalent senior-level cybersecurity certification.
Security Engineering & Compliance Tooling
Policy-as-code frameworks and admission controls (OPA/Gatekeeper, Azure Policy for Kubernetes, Sentinel).
Secure software supply chain tooling (e.g.,Sigstore/Cosign, in-toto, provenance/attestation).
Cloud-native security tooling and posture management: Azure: Defender for Cloud, Azure Policy, Azure Monitor AWS (desired): AWS Config, GuardDuty, Inspector
Azure: Defender for Cloud, Azure Policy, Azure Monitor
AWS (desired): AWS Config, GuardDuty, Inspector
Observability & Operations
Observability platforms and practices: OpenTelemetry, Prometheus, ELK/Splunk, alerting and SLOs.
AWS Experience
Experience operating secure AWS infrastructure and workloads, including: ECS, CloudWatch, IAM, VPC, Secrets Manager (and related security controls/patterns)
ECS, CloudWatch, IAM, VPC, Secrets Manager (and related security controls/patterns)
Familiarity with multi-cloud governance approaches and translating controls across Azure and AWS.
Platform/Delivery Engineering
Infrastructure-as-code beyond Terraform (Azure Bicep) and secure module patterns.
Azure networking fundamentals (NSGs, route tables, hub-and-spoke, firewall/egress/ingress patterns).
Domain/Advanced Areas
Experience with AI/ML security practices or secure metadata handling for model pipelines.
Strong understanding of Zero Trust architectures and service-to-service identity enforcement.
Service-disabled veteran-owned management consulting and custom software firm serving federal acquisition organizations.
Visit company websiteJobs and hiring trendsFull-time
Senior · 7+ years experience
Hybrid
Apply faster on company sites with our extension.