CybersecurityJobs.io
← Back to all jobs

Job Description

EY is hiring a Senior DevSecOps Engineer to support its Government & Infrastructure cybersecurity team in McLean, VA. In this role, you will evaluate how applications are delivered and how mature their security practices are, then help modernize software delivery by designing secure CI/CD pipelines and automated evidence for authorization activities. The work focuses on ensuring security is embedded into the software lifecycle and mapped to authorization and control traceability requirements.

This position will be based onsite in the Washington, DC area as needed, with responsibilities spanning application delivery toolchain assessment, security posture evaluation, and governance-driven automation for continuous Authorization to Operate (cATO) and NIST SP 800-53.

Responsibilities

  • Assess each application’s delivery toolchain and practices, including source control, build and release automation (for example, Jenkins and Bitbucket), artifact management (Artifactory), code quality (SonarQube), Infrastructure-as-Code and configuration management (Terraform, Ansible), and monitoring (Datadog), and identify manual release steps and gaps.
  • Assess application security posture as an input to rationalization, including open vulnerabilities, outdated or vulnerable dependencies, SBOM availability, secrets handling, authentication patterns, and POA&Ms.
  • Design, build, and maintain secure CI/CD pipelines for the modernization factory with integrated SAST/DAST, software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection, and quality gates.
  • Implement policy-as-code and automated evidence collection to support continuous cATO and NIST SP 800-53 control traceability.
  • Harden container images and environments against applicable security configuration benchmarks such as DISA STIGs or CIS Benchmarks.
  • Integrate governance gates for AI-assisted development, covering provenance, human review, and traceability for AI-generated code.
  • Define reference DevSecOps patterns and reusable pipeline templates for future modernization waves, and report delivery and security metrics such as DORA metrics and vulnerability aging.
  • Support vulnerability triage and remediation guidance and collaborate with client cybersecurity and authorization stakeholders.
  • Own the team’s DevSecOps architecture and toolchain standards.
  • Lead the security-posture assessment methodology and ensure findings are scored consistently across the portfolio.
  • Serve as the primary security engineering contact for client cybersecurity stakeholders and prepare artifacts for authorization reviews.
  • Mentor the Staff DevSecOps engineer and promote secure engineering practices across the team.

Requirements

  • Bachelor’s degree in computer science, software engineering, information systems, computer engineering, or a related field, or equivalent practical experience.
  • 3-6+ years of experience in DevOps, software engineering, or security engineering.
  • Hands-on CI/CD pipeline engineering with tools such as Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
  • Experience with at least one application security scanning tool, for example Fortify, Checkmarx, SonarQube, Snyk, Trivy, or OWASP ZAP.
  • Working knowledge of containers and Infrastructure-as-Code.
  • Scripting skills in Python, PowerShell, or Bash.
  • Understanding of the NIST Risk Management Framework, NIST SP 800-53, and secure software development lifecycle practices.
  • Must be able to obtain and maintain a secret level clearance.
  • Comfort with working in-person as needed in the Washington, DC area.

Technologies

  • Jenkins, Bitbucket, Artifactory, SonarQube
  • Terraform, Ansible, Datadog
  • SAST, DAST, software composition analysis, container image scanning, Infrastructure-as-Code scanning, secrets detection
  • Policy-as-code, cATO, NIST SP 800-53, DISA STIGs, CIS Benchmarks
  • AI-assisted development, DORA metrics
  • GitHub Actions, GitLab CI, Azure DevOps
  • Fortify, Checkmarx, Snyk, Trivy, OWASP ZAP
  • NIST Risk Management Framework, Python, PowerShell, Bash
  • Kubernetes security and policy engines (OPA/Gatekeeper, Azure Policy)
  • CycloneDX, SPDX, SBOM, SBOM tooling

Benefits

  • Comprehensive compensation and benefits package
  • Medical and dental coverage
  • Pension and 401(k) plans
  • Paid time off options, including a flexible vacation policy
  • Time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence

Location: McLean (onsite). Salary range: USD 104,800 - 209,700 per year. Date: Oct 2, 2026. Requisition ID: 1749123.

Due to the nature of government and public sector work, completion may be required at client, EY, and/or contractor sites, and travel of 20-30% or more may be required based on client and project needs. Assignments may be within a commutable distance of the office.

Ideally, You’ll Also Have

  • Experience supporting continuous ATO or FedRAMP authorizations and managing POA&Ms.
  • Kubernetes security and policy engines (OPA/Gatekeeper, Azure Policy).
  • SBOM tooling and standards (CycloneDX, SPDX).
  • Certifications such as CompTIA Security+, CISSP, CCSP, Certified Kubernetes Security Specialist (CKS), or relevant GIAC certifications.

Similar Jobs