Software Engineer-DevSecOps
About the role
Be Challenged and Make a Difference
In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.
Description of Task to be Performed:
AnaVation is seeking a Software Engineer-DevSecOps to support one of our cybersecurity programs in our San Antonio office. In this position, the right candidate will develop and manage the CI/CD pipelines of mission applications across value streams. Considered a strong generalist on CI/CD and security requirements, the role automates security control implementation and evidence collection and advances inheritance and automation aligned with the Government’s Cyber Assessment Roadmap to sustain IATT, ATO, and cATO readiness.
Position Responsibilities: This position establishes the automation standard for secure software delivery, ensuring security is built into pipelines, and control evidence is generated continuously.
Responsibilities include:
Build and maintain CI/CD pipelines (e.g., GitLab CI, Jenkins) for an enterprise consisting of many applications
Develop, test, and maintain containerized applications; work with source version control and build/release tooling
Develop Infrastructure as Code (IaC) and Configuration as Code (CaC) using Packer, Terraform, and Ansible
Automate security control implementation, validation, and evidence collection supporting RMF, ATO, and cATO
Integrate and tune pipeline security tooling: SAST, DAST, SCA, container scanning, secrets detection, and policy gates
Support security-relevant changes (SRCs), Security Impact Assessments (SIAs), and control validation for embedded value streams
Support application/container vulnerability management, whitelisting decisions, and CTF/pipeline compliance so changes do not invalidate the ATO
Collaborate with ISSEs, software developers, Value Stream engineers, COT, CPT, and Government stakeholders across sprint cadences
Architect logging, monitoring, and telemetry to support continuous monitoring
Maintain a strong security-first mindset and support Zero Trust and secure software supply chain practices
Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness
Develop automated security policies in CI/CD (e.g., GitLab Policies) to flag End-of-Life images, remediate pipeline vulnerabilities, prevent unauthorized deployments, and quarantine compromised artifacts
Required Qualifications:
Clearance: U.S. Citizen; TS/SCI
Education: Bachelor's degree in Computer Science, Cybersecurity, IT, Software Engineering, or related field
Certification: DoD 8140/8570 IAT Level II e.g., Security+ CE or equivalent
Location: Full-time on-site in San Antonio, TX
Experience and Knowledge:
Senior level comprehensive knowledge across key tasks and high-impact assignments; plans and leads major technology assignments; functions as a technical expert across the team; may lead others
Deep understanding of Agile and DevSecOps methodologies; DevSecOps implementation using Jenkins, GitLab, or similar
Skillset to build and maintain CI/CD pipelines for a large enterprise (hundreds of applications)
Experience developing IaC/CaC with Packer, Terraform, and Ansible; development experience with Kubernetes, Docker, and Helm
Experience with cloud systems and architectures (AWS, Google Cloud, or Azure); Linux and scripting (Bash, Python)
Working knowledge of source version control, build/release tools, and CI/CD; strong security-first mindset
Minimum years of experience - 4 years of relevant experience
Preferred Qualifications:
Clearance: Active TS/SCI
Education: Advanced degree in a related technical field
Certification: CKS, CKA, AWS certifications, CCSP, or GitLab certifications
Experience and Knowledge:
Experience developing software with Java/Spring, Python, JavaScript/node.js, or Angular; microservice architectures (REST, JMS, AMQP)
Experience with Istio; experience supporting Government software factory environments
Experience supporting Continuous Authority to Operate (cATO)
Experience with secure software supply chain (SBOM, artifact signing)
Experience supporting IL4, IL5, or IL6 cloud environments; COT, CPT, or Security Control Assessors
Experience with GitLab security policies, Twistlock, Anchore, Defect Dojo, container signing (e.g., cosign/sigstore), and End-of-Life image detection
Benefits
Generous cost sharing for medical insurance for the employee and dependents
100% company paid dental insurance for employees and dependents
100% company paid long-term and short-term disability insurance
100% company paid vision insurance for employees and dependents
401k plan with generous match and 100% immediate vesting
Competitive Pay
Generous paid leave and holiday package
Tuition and training reimbursement
Life and AD&D Insurance
About AnaVation
AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.
If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you!
AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.
Responsibilities
- Build and maintain CI/CD pipelines for an enterprise consisting of many applications
- Develop, test, and maintain containerized applications
- Develop Infrastructure as Code (IaC) and Configuration as Code (CaC)
- Automate security control implementation, validation, and evidence collection
- Integrate and tune pipeline security tooling
- Support security-relevant changes and control validation
- Collaborate with stakeholders across sprint cadences
- Architect logging, monitoring, and telemetry
Qualifications
- U.S. Citizen; TS/SCI clearance
- Bachelor's degree in Computer Science, Cybersecurity, IT, Software Engineering, or related field
- DoD 8140/8570 IAT Level II certification
- Senior level comprehensive knowledge across key tasks
- Deep understanding of Agile and DevSecOps methodologies
- Experience developing IaC/CaC with Packer, Terraform, and Ansible
- Experience with cloud systems and architectures
Benefits
- Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance
Skills mentioned
About AnaVation LLC
AnaVation is a trusted partner that delivers high-value, cost-effective solutions to solve our customers’ most complex technical and analytical problems. AnaVation believes that the future of securing, collecting, processing, and analyzing cyber data will require the development of advanced ANAlytical technologies derived via the innoVATION of current and future technologies. AnaVation believes in the “Idea of the Possible” — that it is possible for our experts, partnering with our customers in the right environment, to create innovative technical solutions that expand our customers’ capabilities. We want to do two things for our customers. We want to resolve existing challenges and we want to prepare them for the future. Our technical expertise and innovative engineering culture enable us to do those things.