Position: DevSecOps Engineer — Tooling Implementation & Integration
Engagement Mode: Not specified
Location: Not specified
Position Overview:
This is a hands-on build role at the center of a DevSecOps program. The
engineer will deploy and operate
DefectDojo Pro inside a FedRAMP-authorized AWS environment as the single
source of truth for
vulnerability findings. The role involves integrating seven detection sources
— Trivy, Semgrep, Qualys,
Tenable, AWS Inspector, CrowdStrike, and Dependabot — while retiring a legacy
multi-hop pipeline (GHAS
→ Splunk → email → Jira). The engineer will own all integration code, CI/CD
wiring, and automation that
moves findings from detection through evaluation to ticketing and reporting.
This position requires deep AWS
expertise, strong Python development skills, Kubernetes operational fluency,
and experience with security
tooling in regulated environments.
Key Responsibilities:
• Deploy and operate DefectDojo Pro within a FedRAMP-authorized AWS
environment, including IdP/SSO
integration, hardening, and boundary-compliant configuration
Build and maintain scanner integrations: API connectors, webhook pipelines,
and CI jobs feeding findings
from all detection sources into the aggregation platform
• Integrate container scanning into GitHub CI pipelines and ECR registry
workflows (Trivy), and implement
runtime container scanning for EKS/ECS workloads
• Build a runtime reconciliation loop matching scanned images to
actually-deployed workloads
• Implement KEV/EPSS enrichment and internet-reachability tagging
• Build FedRAMP JSON export services (VDT/AVI/MRH schemas)
• Implement link-only bidirectional Jira sync that keeps vulnerability
metadata inside the ATO boundary
• Wire PagerDuty alerting for emergency-patch scenarios (12h–2d SLAs for
highest-severity, exploitable,
internet-reachable findings)
• Decommission the legacy GHAS/Splunk/email findings chain and migrate active
workflows without losing
audit continuity
• Write infrastructure-as-code, deployment automation, and operational
documentation for all built
components
Required Skills:
• 6+ years in DevOps/DevSecOps or platform engineering roles with significant
security tooling exposure
• Strong AWS experience: EKS/ECS, ECR, EC2, Lambda, IAM, VPC networking
• Proficiency building API integrations and data pipelines in Python or
similar language
• Experience with REST APIs, webhooks, and JSON schema work
Hands-on CI/CD experience with GitHub Actions
• Experience embedding security scanning into build and registry workflows
• Kubernetes operational fluency: deployments, admission concepts, workload
visibility, runtime security
tooling
• Infrastructure-as-code (Terraform preferred)
Preferred (Bonus) Skills:
• Direct experience with DefectDojo (especially DefectDojo Pro) or comparable
vulnerability
aggregation/ASPM platforms
• Experience with Trivy, Grype, AWS Inspector, CrowdStrike Falcon Cloud
Security, Semgrep, Qualys, or
Tenable APIs
• Experience operating tooling inside a FedRAMP boundary or other regulated
environment
• Understanding of ATO scope, hardening baselines, and change control
• Familiarity with SBOM formats (CycloneDX)
• Familiarity with VEX, KEV/EPSS data source
Apply through whichever channel suits you best.