Full-Time

Sr. Devsecops Engineer III

Posted on 7/9/2024

MetroStar

MetroStar

201-500 employees

Technology solutions for government agencies

Government & Public Sector
Enterprise Software

Expert

Washington, DC, USA

US Top Secret Clearance Required

Category
DevOps & Infrastructure
Site Reliability Engineering
DevOps Engineering
Required Skills
Bash
Microsoft Azure
Python
Git
AWS
Jenkins
Terraform
Ansible
Development Operations (DevOps)
Google Cloud Platform
Requirements
  • Active TS/SCI Clearance with CI poly.
  • At least 10 years of experience as a DevSecOps Engineer or similar role, with a focus on integrating security into the software development lifecycle.
  • Expert experience with DevOps practices, CI/CD pipelines, and automation tools (e.g., Jenkins, GitLab CI/CD, Artifactory, SonarQube, Selenium, Fortify, Acunetix, and Prisma Cloud).
  • Expert experience building DevSecOps solutions at scale across IL5 to IL6+ classification domains.
  • Expert understanding of AWS and familiarity with other cloud platforms (e.g., Azure, GCP) and securing cloud-based applications and services.
  • Strong experience with infrastructure as code (IaC) tools such as Terraform, CloudFormation, or Ansible.
  • Strong experience in scripting languages (e.g., Python, Bash) for automation and tool integration.
  • Hands-on experience with security tools for static code analysis, dynamic application security testing (DAST), and vulnerability scanning, using tools such as Fortify, Acunetix, and Prisma Cloud.
  • Knowledge of security best practices, common vulnerabilities, and exposure to security frameworks (e.g., OWASP, NIST).
Responsibilities
  • Collaborate with development, operations, and security teams to integrate security practices into the software development lifecycle.
  • Design, implement, and maintain CI/CD pipelines that incorporate automated security testing, vulnerability scanning, and compliance checks.
  • Develop and maintain infrastructure as code (IaC) templates and configurations, ensuring security best practices are applied to cloud resources and infrastructure components.
  • Perform regular security assessments, code reviews, and penetration testing to identify and address vulnerabilities and weaknesses in applications, code, and infrastructure.
  • Monitor and analyze system and application logs to detect and respond to security incidents.
  • Implement and manage identity and access management (IAM) solutions, ensuring appropriate authentication and authorization mechanisms are in place.
  • Collaborate with software engineers to provide guidance on secure coding practices and assist in remediation of security findings.
  • Participate in incident response activities, helping to investigate and mitigate security incidents in a timely manner.
  • Contribute to the development and maintenance of security policies, procedures, and documentation.

MetroStar creates technology solutions to improve digital experiences for government agencies. They modernize IT infrastructure and develop digital tools, such as a pandemic relief eligibility tool for farmers and virtual training platforms for law enforcement. MetroStar stands out by tailoring its services specifically to government needs, generating revenue through contracts and partnerships. The company's goal is to enhance efficiency and innovation in public sector operations.

Company Stage

N/A

Total Funding

$4.4M

Headquarters

Reston, Virginia

Founded

1999

Simplify Jobs

Simplify's Take

What believers are saying

  • MetroStar's Comet design system aligns with the growing trend of DesignOps in government.
  • Their DEI focus matches the public sector's increasing emphasis on diversity and inclusion.
  • Partnerships for broadband access meet rising demand in rural areas, enhancing connectivity.

What critics are saying

  • Competition from companies like NTT Data could limit MetroStar's large-scale contract opportunities.
  • Reliance on USWDS and React may lead to inefficiencies in design system projects.
  • New initiatives like Comet may require time and resources to prove their value.

What makes MetroStar unique

  • MetroStar specializes in digital services for government agencies, focusing on IT modernization.
  • The company excels in creating user-centric digital experiences for public sector innovation.
  • MetroStar's virtual training platforms have saved $16 million in travel expenses for law enforcement.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Paid Vacation

Paid Sick Leave

Paid Holidays

Professional Development Budget

Wellness Program

INACTIVE