Standard Job Description
We are seeking an experienced and motivated Stf DevSecOps Engineer. The DevSecOps Engineer will be responsible for new and existing HPC production and development environments. Deployment of new tools, infrastructure security, monitoring, auto-recovery, performance tuning and installation/configuration of applications. The DevSecOps Engineer plays a pivotal role in establishing secure workflows and patterns for end-to-end application lifecycle management. The ideal candidate for this position has worked in agile software development environments, taking ownership of their tasks/stories, and contributing to various products. At times, they may need to work closely with the architects and process owners who have designed the solutions to firm up requirements or perform testing. Other responsibilities include: • Act as Kubernetes team lead, building and training talent on Kubernetes and container automation. • Containerization and automation of existing and new applications in airgap environments. • Identifying and resolving technical challenges through innovative software solutions. • Working with software developers and engineers to create secure repeatable DevSecOps workflows and patterns. • Ensure the success of complex security requirements and compliance for container environments, CI/CD, DevOps, Infrastructure, and Kubernetes initiatives in classified environments. • Documenting infrastructure configurations, processes, and procedures. • Automating repetitive tasks to increase efficiency and reduce errors in the image hardening process. • Developing best practices to increase the velocity of secure image updates and patch management. • Implementing and managing automated compliance scanning tools (SAST/DAST/Fuzzing) within the build pipeline. • Implementing Infrastructure as Code (IaC) using Terraform or similar tools to stand up secure environments. |
Performs tech planning, design, devel, integ, v&v for total syst life cycle. Analyses performed at all levels of syst product incl. concept, design, fabrication, test, instl, operation, maintenance & disposal, incorp design methods & stds for Cyber Security, SW & HW infrastructure. Designs, devels, docs, tests & debugs SW that contains logical & math solutions to business/mission problems/questions in computer language. Ensures the logical & syst conversion of customer/product reqs into total syst solutions that ack tech, sched, cost constraints & align to SW & HW deployment pipelines & factories. Performs func & timeline analysis, detail trade & reqs allocation & interface defs studies to translate customer reqs into HW & SW feature defs & acceptance criteria. Applies stds, processes, procedures & tools throughout the devel life cycle. Applies HW & SW knowledge, cyber security stds in business/mission apps, & feedback from users to develop SW. Corrects program errors, prepares operating instructions, compiles doc of program devel & analyzes syst capabilities to resolve program problems, output/input data acq, programming tech & controls. Ensures SW stds are met. Validates incorp of features & use cases into implemented designs
Basic Qualifications
• Current US DoD TOP SECRET clearance or the ability to obtain one.
• Proficiency with git and version control systems (Github, GitLab) in a team setting.
• Experience with containerization (Podman, Docker, Kubernetes) and container security.
• Experience designing infrastructure as code solutions using Terraform and Ansible.
• Experience with CI/CD tooling (GitHub Actions, GitLab CI, Jenkins, ArgoCD, FluxCD, or similar).
• Experience with Linux (RHEL, RockyOS) administration and hardening.
• Knowledge of DevSecOps processes and software supply chain security (SBOMs, signing, verification)
• Knowledge of software development lifecycle and SDLC promotion strategies.
• Knowledge of secrets management platforms and software ( HashiCorp Vault, SOPS, HSM ).
• Knowledge of virtualization technologies ( VMWare ).
Desired Skills
• Experience using Helm, FluxCD, ArgoCD, Version Control, and Harness for deploying and managing kubernetes clusters in airgap environments using GitOps best practices to manage cluster state and bootstrap new clusters. • Experience deploying and managing HashiCorp Vault and Vault Secrets Operator. • Experience with Elasticsearch or equivalent applications for monitoring and alerting such as Prometheus and Grafana or Splunk. • Some experience containerizing Node.js and Go based applications. |
Pay Information
Full-Time Salary Range: $120600.00 - $224000.00
At Lockheed Martin, we know mission success starts with taking care of our people. Our Total Rewards program is designed to attract top talent, support your well-being, and help you grow—both professionally and personally.
The salary range for this position is as listed on the requisition. Please note that the salary information listed is a general guideline only. Lockheed Martin considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/ training, key skills as well as market(work location) and business considerations when extending an offer.
Benefits offered: Medical, Dental, Vision, Flexible work arrangements and schedules (e.g., 4x10), 401(k) match, Paid time off, Holidays, Parental Leave, EAP, Flexible Spending Accounts, Education Assistance, Life Insurance, Short-Term Disability, and Long-Term Disability.
- Annual short-term and/or long-term incentive compensation programs may be offered depending on the position. Payments under these annual programs are not guaranteed and can vary from year to year and are tied to a range of performance metrics.
- For (Washington state applicants only) Non-represented full-time employees: accrue at least 10 hours per month of Paid Time Off (PTO) to be used for incidental absences and other reasons; receive at least 90 hours for holidays. Represented full time employees accrue 6.67 hours of Vacation per month; accrue up to 52 hours of sick leave annually; receive at least 96 hours for holidays. PTO, Vacation, sick leave, and holiday hours are prorated based on start date during the calendar year.