Job Closed
This listing is no longer active.
Building simple, effective government services. Want to contribute? We're hiring!
Senior Software Engineer – DevSecOps Architect
Location
Alabama + 29 moreAll locations: Alabama | Arizona | California | Colorado | District of Columbia | Florida | Illinois | Louisiana | Maine | Nevada | New Jersey | New York | North Carolina | Ohio | Oklahoma | Oregon | Maryland | Massachusetts | Michigan | Minnesota | Missouri | Pennsylvania | Rhode Island | South Carolina | Tennessee | Texas | Utah | Virginia | Washington | Wisconsin
Posted
172 days ago
Salary
$153K - $171K / year
Seniority
Senior
Job Description
Senior Software Engineer – DevSecOps Architect
Nava
• Design, implement, and maintain the organization’s security architecture in alignment with federal security standards (e.g., FISMA, NIST SP 800-53, 800-171) and contract requirements • Lead security planning and risk assessments for government systems hosted in AWS • Serve as the primary security point of contact for government programs, overseeing incident response, vulnerability management, and system hardening activities • Develop and maintain security documentation required for system authorization, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and Continuous Monitoring strategies • Support the Authority to Operate (ATO) process across multiple projects, working closely with compliance teams, federal partners, and internal stakeholders • Architect, oversee and support implementation of security controls across AWS services (e.g., IAM, KMS, Security Hub, GuardDuty, CloudTrail, Config, WAF, etc.) • Perform regular audits, security assessments, and continuous monitoring to ensure compliance with government standards and internal policies • Collaborate with engineering teams to integrate security into SDLC/DevOps pipelines, using tools such as SonarQube, Snyk, Tenable, and Jenkins • Lead incident response efforts for government systems, including containment, eradication, and recovery, while maintaining proper documentation and communication protocols • Research and recommend emerging AWS security services and technologies to improve security posture and maintain compliance • Mentor junior DevSecOps team members and foster a culture of security-first thinking across the organization • Interface with federal agency stakeholders, auditors, and security assessors to represent the organization’s security practices and compliance efforts • Participate in proposal development and pre-award planning by advising on security architecture and compliance strategies for new federal opportunities
Job Requirements
- Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field
- 5+ years of experience in information security, with at least 2 years supporting federal government contracts and managing system compliance efforts
- Deep understanding of federal security frameworks, including FISMA, NIST 800-53, 800-171, and FedRAMP
- Hands-on experience managing security for AWS cloud environments, including services such as: IAM, KMS, CloudTrail, Security Hub, GuardDuty, Config, VPC, EC2, Lambda, S3, RDS, DynamoDB, WAF, Shield, Inspector, Secrets Manager
- Experience leading or supporting the ATO process, including documentation, control implementation, security testing, and coordination with third-party assessors or agency officials
- Proficiency in modern DevSecOps toolchains and methodologies (e.g., Terraform, Jenkins, GitHub, New Relic, SonarQube, Snyk, Tenable Nessus)
- Solid understanding of secure software development principles across languages and frameworks such as Java, Spring Boot, Python, Go, JavaScript/TypeScript, and Angular
- Demonstrated ability to communicate security concepts to technical and non-technical stakeholders
- Strong leadership, analytical, and problem-solving skills
Benefits
- Health coverage — comprehensive medical, dental, and vision plans to support your overall health needs
- Insurance coverage — Nava provides disability, life, and accidental death insurance at no cost
- Time off — vacation, holidays (including Juneteenth), and floating holidays to rest and recharge
- Company holidays — enjoy 12 paid federal holidays each year on top of your regular PTO
- Annual bonus — when Nava meets its goals, eligible employees receive a performance-based annual bonus
- Parental leave — paid time off for new parents, plus weekly meals delivered to your home
- Wellness program — full platform offering physical, mental, & emotional health resources & support tools
- Virtual care — see doctors online with no copay through UnitedHealthcare’s virtual visit program
- Sabbatical leave — earn extended unpaid leave after continuous service for personal growth or rest
- 401(k) match — Nava matches 4% of your salary to support your retirement savings plan
- Flexible work — remote-first environment with flexibility built around your schedule and responsibilities
- Home office setup — company laptop & setup assistance provided via Staples for remote work needs
- Utility support — monthly reimbursement to help offset eligible home office utility expenses
- Learning opportunities — internal training programs and resources to help grow your professional skills
- Development opportunities — LinkedIn Learning access & an annual allowance for courses, tuition, & certs
- Referral bonus — get rewarded when you refer great people who join the Nava team
- Commuter benefits — pre-tax commuter programs to support in-office travel when applicable
- Supportive culture — A collaborative and remote-friendly team environment where people genuinely care
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
Senior Site Reliability Engineer – SRE
Xenon SevenHuman Experts Implementing Artificial Intelligence #AI #ArtificialIntelligence #HumanIntelligence
• Design and architect highly available and scalable OpenShift/Kubernetes infrastructure for banking applications on on-premise servers • Lead and implement comprehensive monitoring and observability strategy using Prometheus and Grafana • Design and oversee centralized logging infrastructure using ELK Stack (Elasticsearch, Logstash, Kibana) • Lead SRE best practices implementation and adoption of production support standards across teams • Mentor and coach junior SRE and DevOps engineers on OpenShift, Kubernetes, monitoring, and production support • Define and implement Service Level Indicators (SLIs), Objectives (SLOs), and Agreements (SLAs) with measurable metrics • Lead incident response strategy, post-incident reviews, and drive continuous improvement in production stability • Architect and implement advanced alerting, monitoring dashboards, and visualization strategies using Prometheus and Grafana • Design automation frameworks and tools to reduce operational toil and improve production efficiency • Lead OpenShift/Kubernetes cluster upgrades, security patches, and infrastructure modernization on-premise • Establish production support procedures, on-call rotation policies, and escalation frameworks • Optimize system performance, cost, and resource utilization across containerized on-premise infrastructure • Conduct capacity planning, performance optimization, and infrastructure scaling initiatives • Lead technical architecture reviews and infrastructure design decisions for banking applications • Manage on-premise data center resources and infrastructure planning • Participate in 24/7 on-call rotation and escalation for critical production incidents • Ensure compliance, security hardening, and disaster recovery procedures for financial systems
DevOps Business Analyst
GXABuilding Stronger Businesses & Communities. Providing Managed IT Services in the Dallas-Fort Worth Area since 2008.
• Act as the client-facing bridge between business stakeholders and the Dev/Ops engineering team. • Gather and document business requirements, mapping workflows, identifying integration or automation opportunities. • Translate needs into clear, actionable specifications for the Dev/Ops Engineer. • Ensure proposed solutions align with client goals, are technically feasible, and operationally robust. • Lead structured discovery sessions with clients and internal stakeholders. • Document business processes, pain points, data flows, and desired outcomes. • Identify opportunities for integrations, automation, or custom development. • Translate business requirements into functional specifications, user stories, wireframes, and acceptance criteria. • Map system interactions, including API usage, data movement, and workflow triggers. • Validate requirements with the Dev/Ops Engineer to ensure technical feasibility. • Define project scope, success criteria, timelines, and dependencies. • Serve as the primary contact for status updates and requirement clarifications. • Ensure clients understand trade-offs, risks, and set realistic expectations. • Analyze existing business processes and recommend improvements. • Identify automation opportunities, such as ETL, API-based workflows, and SQL-driven tasks. • Produce detailed documentation, diagrams, decision logs, and training materials. • Facilitate handovers to operations, support, and engineering teams.
DevOps AppSec, Security Engineer
GXABuilding Stronger Businesses & Communities. Providing Managed IT Services in the Dallas-Fort Worth Area since 2008.
• Guide developers and engineers on secure coding standards and practices. • Perform code reviews and static/dynamic analysis to identify vulnerabilities. • Integrate security tools into CI/CD pipelines for automated scanning and compliance. • Design and implement authentication, authorization, and encryption for APIs and applications. • Assess and remediate risks in REST/SOAP integrations, data pipelines, and custom applications. • Collaborate with the vISM and Security Team to manage vulnerability identification, tracking, and remediation across applications and infrastructure. • Coordinate and support penetration testing activities, including scoping, execution, and remediation of findings. • Conduct security assessments for new and existing systems, documenting risks and recommending mitigation strategies. • Develop and maintain threat models for applications and infrastructure. • Respond to security incidents, perform root-cause analysis, and document lessons learned. • Support compliance initiatives (e.g., GDPR, HIPAA, PCI-DSS) and assist with audit preparation and evidence collection. • Build and maintain security automation scripts and workflows (e.g., for vulnerability scanning, alerting, and compliance checks). • Integrate security monitoring into Azure Pipelines, Data Factory, and related services. • Maintain comprehensive security documentation, diagrams, and operational procedures. • Work with Business Analysts to translate security requirements into actionable specifications. • Educate stakeholders on security risks, trade-offs, and mitigation strategies. • Participate in client meetings to address security concerns and present solutions.
AWS DevOps Engineer, Associate
MactoresMactores is a trusted leader among businesses in providing modern data platform solutions.
• Manage large customer deployments including Linux and Windows Administration • Help migrate remaining dedicated hardware infrastructure to the cloud • Automate operational and server provisioning workflows using AWS CFT on AWS • Share responsibility for deploying releases and conducting other operations maintenance • Enhance operations infrastructures such as Jenkins clusters, Bitbucket, monitoring tools (Consul), and metrics tools such as Graphite and Grafana • Establish and maintain operational best practices • Design team strategy in collaboration with founders • Participate in hiring culturally fit engineers • Train and guide the team in DevOps practices • Implement monitoring for automated system health checks • Build CI pipeline



