About this role
Position Overview: Our client is seeking a skilled DevSecOps Engineer to play a pivotal role in the implementation and integration of security tooling within a DevSecOps program. This hands-on position involves deploying and operating DefectDojo Pro in a FedRAMP-authorized AWS environment, ensuring it serves as the single source of truth for vulnerability findings. The engineer will integrate multiple detection sources while modernizing legacy processes, taking ownership of integration code, CI/CD wiring, and automation for efficient vulnerability management.
Key Responsibilities:
- Deploy and operate DefectDojo Pro within a FedRAMP-authorized AWS environment, including IdP/SSO integration and compliance configuration.
- Build and maintain scanner integrations, including API connectors and CI jobs that aggregate findings from various detection sources.
- Integrate container scanning into GitHub CI pipelines and ECR workflows, implementing runtime scanning for EKS/ECS workloads.
- Create a reconciliation loop to match scanned container images with deployed workloads.
- Implement KEV/EPSS enrichment and tagging for internet reachability.
- Develop FedRAMP JSON export services adhering to VDT/AVI/MRH schemas.
- Implement a bidirectional Jira sync to maintain vulnerability metadata within ATO boundaries.
- Set up PagerDuty alerting for emergency patch scenarios with defined SLAs.
- Decommission legacy workflows while ensuring audit continuity during migration.
- Write infrastructure-as-code and operational documentation for all components developed.
Required Skills:
- 6+ years in DevOps/DevSecOps or platform engineering roles with a focus on security tooling.
- Strong experience with AWS services including EKS/ECS, EC2, and IAM.
- Proficiency in building API integrations and data pipelines using Python or similar languages.
- Hands-on experience with CI/CD processes, particularly GitHub Actions.
- Familiarity with Kubernetes operational practices and security tooling.
- Experience with infrastructure-as-code, preferably using Terraform.
Preferred (Bonus) Skills:
- Direct experience with DefectDojo or similar vulnerability aggregation platforms.
- Familiarity with security tools such as Trivy, AWS Inspector, and Semgrep.
- Experience working within a FedRAMP boundary or other regulated environments.
- Understanding of ATO scope and change control processes.
- Knowledge of SBOM formats and VEX, KEV/EPSS data sources.
What we offer: Our client provides a dynamic work environment with opportunities for professional growth, a collaborative team culture, and the chance to work on impactful projects in the security domain.