DevSecOps Engineer
Job Description
EY is seeking a DevSecOps Engineer to support government and infrastructure cybersecurity engagements, with a focus on strengthening application security and delivery practices. In this role, you will evaluate delivery toolchains, modernize secure CI/CD workflows, and connect security verification to authorization and compliance traceability for continuous cATO.
What you’ll do
- Review each application’s delivery toolchain and practices, including source control, build and release automation (for example, Jenkins and Bitbucket), artifact management (Artifactory), code quality (SonarQube), Infrastructure-as-Code and configuration management (Terraform, Ansible), and monitoring (Datadog), identifying manual release steps and gaps.
- Assess application security posture to support rationalization efforts, including open vulnerabilities, outdated or vulnerable dependencies, SBOM availability, secrets handling, authentication patterns, and open POA&Ms.
- Design, build, and maintain secure CI/CD pipelines for the modernization factory, integrating SAST/DAST, software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection, and quality gates.
- Apply policy-as-code and automated evidence collection to support continuous Authorization to Operate (cATO) and NIST SP 800-53 control traceability.
- Harden container images and environments against applicable security configuration benchmarks such as DISA STIGs or CIS Benchmarks.
- Support governance gates for AI-assisted development, including provenance, human review, and traceability of AI-generated code.
- Define reference DevSecOps patterns and reusable pipeline templates for future modernization waves, and report delivery and security metrics, including DORA metrics and vulnerability aging.
- Assist with vulnerability triage and remediation guidance, collaborating with client cybersecurity and authorization stakeholders.
What you bring
- Bachelor’s degree in computer science, software engineering, information systems, computer engineering, or a related field, or equivalent practical experience.
- 2+ years of experience in DevOps, software engineering, or security engineering.
- Hands-on CI/CD pipeline engineering experience with Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
- Experience with at least one application security scanning tool, such as Fortify, Checkmarx, SonarQube, Snyk, Trivy, or OWASP ZAP.
- Working knowledge of containers and Infrastructure-as-Code.
- Scripting experience in Python, PowerShell, or Bash.
- Knowledge of the NIST Risk Management Framework, NIST SP 800-53, and secure software development lifecycle practices.
- Ability to obtain and maintain a secret level clearance.
- Comfort working in-person as needed in the Washington, DC area.
Technologies you may work with
- Jenkins, Bitbucket, Artifactory, SonarQube
- Terraform, Ansible, Datadog
- SAST, DAST, software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection, policy-as-code
- NIST SP 800-53, DISA STIGs, CIS Benchmarks, OPA/Gatekeeper, Azure Policy
- CycloneDX, SPDX
- Python, PowerShell, Bash, GitHub Actions, GitLab CI, Azure DevOps
- Fortify, Checkmarx, Snyk, Trivy, OWASP ZAP
- NIST Risk Management Framework, DORA metrics
Benefits
- Comprehensive compensation and benefits package, including medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Flexible vacation policy, including EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence.
Location: McLean, onsite (Primary Location Only). Work may be required at client, EY, and/or contractor sites, with an assignment approach focused on commutable distances; travel may be required beyond your work location based on client and project needs, and candidates should be willing to travel 20–30% or more.
Salary: USD 82,500 - 148,500 per yearly. Individual salaries within the overall range are determined by factors including education, experience, knowledge, skills, and geography.
Requisition ID: 1749118
Date: Oct 2, 2026