Back to all jobs

About the role
<div class="content-intro"><h3><span style="font-family: arial, helvetica, sans-serif;"><strong><span data-ccp-props="{"201341983":0,"335551550":1,"335551620":1,"335559739":160,"335559740":259}">About Metron</span></strong></span></h3>
<p><span style="font-family: arial, helvetica, sans-serif;" data-ccp-props="{"201341983":0,"335551550":1,"335551620":1,"335559739":160,"335559740":259}">Metron is an employee-owned company dedicated to delivering innovative solutions for the most challenging national security problems. For over 40 years, our principled approach to problem-solving has yielded creative solutions at the intersection of advanced mathematics, computer science, physics, and engineering. Our people are leaders in their technical fields and are passionate about solving challenging problems. We look for individuals who share this same passion and can apply their experience in real-world settings. </span></p>
<p> </p></div><p> </p>
<p><strong><span data-contrast="auto">Job Description:</span></strong><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<p><span data-contrast="auto">Our Reston, VA office is seeking a </span><strong><span data-contrast="auto">DevSecOps Engineer</span></strong><span data-contrast="auto"> to help secure and improve software delivery across the enterprise. This role focuses on embedding security, quality, compliance, and software supply-chain controls into CI/CD workflows while partnering with software development, cybersecurity, platform engineering, systems engineering, and program teams.</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<p><span data-contrast="auto">This is an engineering role, not a pure governance or vulnerability-management position. The DevSecOps Engineer will work across Azure DevOps Server, Nexus, SonarQube, Kubernetes/K3s deployment workflows, artifact controls, and secure release patterns to help teams deliver software securely and reliably.</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<p><span data-contrast="auto">Occasional after-hours/weekend maintenance and emergency response may be required.</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<p><strong><span data-contrast="auto">Key Responsibilities:</span></strong><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<p><strong><span data-contrast="auto">Secure CI/CD & Release Workflows</span></strong><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="auto">Design, implement, and improve secure CI/CD patterns in Azure DevOps, including reusable YAML templates, quality gates, artifact controls, and release safeguards</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Support secure release workflows across development, test, integration, staging, and production environments</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Troubleshoot pipeline failures, permissions issues, dependency problems, scan failures, and release blockers</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Software Supply Chain & Security Controls</span></strong><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="auto">Integrate security and quality checks into build and release workflows, including SAST, SCA, dependency scanning, secrets scanning, code-quality gates, container scanning, and artifact validation</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Support tools such as Nexus, SonarQube, Azure DevOps artifacts, and related code-quality or artifact-management platforms</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Partner with cybersecurity to align CI/CD controls with SSP, RMF, NIST, CMMC, STIG, Zero Trust, audit, and program requirements</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Kubernetes Guardrails & Developer Enablement</span></strong><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="auto">Partner with platform engineering on secure Kubernetes/K3s deployment standards, including namespaces, RBAC, ServiceAccounts, Helm, ingress, TLS, storage, quotas, and workload security</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Create documentation, examples, runbooks, and onboarding materials for secure pipeline and deployment workflows</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Track recurring developer pain points, pipeline health, scan outcomes, release blockers, and control gaps; turn findings into automation, templates, documentation, or improved guardrails</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Required Qualifications:</span></strong><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="auto">5+ years of experience in DevOps, DevSecOps, platform engineering, software delivery, systems engineering, or a closely related technical role</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Hands-on experience with Azure DevOps pipelines, YAML, build/release workflows, repositories, artifacts, permissions, or agent-based builds</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience implementing security, quality, or compliance controls in CI/CD workflows</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience with secure software delivery practices such as SAST, SCA, dependency scanning, secrets handling, code-quality gates, artifact controls, or container scanning</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience troubleshooting CI/CD failures, build issues, deployment problems, permissions issues, or dependency-related errors</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience with Kubernetes, K3s, containers, Helm, or similar deployment technologies</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience with scripting or automation using PowerShell, Bash, Python, or similar languages</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Ability to write clear technical documentation, runbooks, onboarding guides, and troubleshooting procedures</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Eligible to obtain and maintain a U.S. security clearance</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Willing and able to work in regulated, secure, or compliance-bounded environments</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Preferred Qualifications:</span></strong><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="auto">Active U.S. security clearance</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience with Azure DevOps Server</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience integrating or administering Nexus, SonarQube, or similar artifact and code-quality platforms</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience with SBOM generation, SCA, container scanning, artifact signing, provenance, or software supply-chain security</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience with policy-as-code, OPA/Gatekeeper, Kubernetes admission controls, or secure workload policies</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience with Infrastructure-as-Code or Configuration-as-Code practices using Terraform, Ansible, Bicep, CloudFormation, or similar tools</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience with Prometheus, Grafana, Loki, or similar observability platforms</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
<li><span data-contrast="auto">Experience in defense contracting, government programs, CMMC, NIST 800-171, RMF, STIGs, or other compliance-driven environments</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></li>
</ul>
<p><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span><span data-contrast="auto">Position Location: Reston, VA (the selected individual will be expected to work onsite in the Reston, VA office)</span><span data-ccp-props="{"134233117":false,"201341983":0,"335559738":0,"335559739":0,"335559740":240}"> </span></p>
<h3><strong><span data-contrast="auto">Perks and Benefits</span></strong><span data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span></h3>
<ul>
<li><span data-contrast="auto">Medical, Dental and Vision Insurance </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Accompanying FSA and HSA options </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Additional Voluntary Benefits </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Paid Time Off </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">9 Observed Holidays and 2 Floating Holidays </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Paid Parental Leave </span></li>
<li><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}">Military Leave </span></li>
<li><span data-contrast="auto">Tuition Reimbursement</span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Professional Development Reimbursement </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Annual Salary Reviews </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Profit Sharing </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">401(k) Traditional and Roth Options </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Gym and Fitness Reimbursement </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Employee Assistance Program </span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
<li><span data-contrast="auto">Employee Referral Program</span><span data-ccp-props="{"134233279":true,"201341983":0,"335559739":160,"335559740":259}"> </span></li>
</ul>
<p> </p><div class="content-conclusion"><p> </p>
<p><span style="font-family: arial, helvetica, sans-serif;"><strong><span data-contrast="none">Metron is an Equal </span></strong><strong><span data-contrast="none">Employment </span></strong><strong><span data-contrast="none">Opportunity (EEO) employer. It is the policy of the company to provide equal employment opportunities to all qualified applicants without regard to race, color, religious, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.</span></strong></span></p>
<p><span style="font-family: arial, helvetica, sans-serif;"><strong><span data-contrast="none">VEVRAA Federal Contractor</span></strong><span data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span></span></p>
<p> </p></div>
Perks & benefits
- 401k
- Vision Insurance
- Paid Time Off
- Company Retreats
- Free Gym Membership
- Profit Sharing
741,000+ hidden jobs like this
metron and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.
Everything Pro unlocks:
- Unlimited applications — free stops at 5
- Track every application in one place
- Apply straight to the source, one click
- Save & organize roles you love
- Roles pulled from company boards before the big sites