About this DevSecOps Engineer, AWS Secure Delivery role at OpenDataJobs
Peregrine Advisors is a firm founded on a simple conviction: the best solutions come from the people closest to the problem, given real ownership and the tools to deliver. We are a data and technology innovation hub and a Benefit Corporation working at the center of the federal government's mission to deliver for client stakeholders and the US public, looking for highly motivated contributors who thrive when trusted to own a hard problem and equipped to deliver the solution.
Your first assignment
In your first assignment, you will own assigned delivery pipelines, automation, and environments that carry federal systems into production. You will take responsibility for these components from implementation through operation, within the system's established architecture and security requirements. That means continuous integration and continuous delivery (CI/CD) pipelines with security gates built in, infrastructure as code that makes environments reproducible, and the automation, monitoring, and evidence that support Risk Management Framework (RMF) authorization and continuous monitoring. You will work in Amazon Web Services (AWS) or a client-managed, on-premises environment. What you build will carry real systems into production. The work is real and hard, and it matters. This first assignment is a starting point, not the shape of your career here. We hire people, not seats, and move our best to where the hardest problems are.
What you'll build
- Assigned CI/CD pipelines with security built into delivery through automated security testing, including static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA); policy-as-code checks; and controlled promotion. A release passes review because the pipeline enforced the required controls and produced the evidence for review.
- The infrastructure beneath those pipelines, defined as code, with reproducible environments, containerization and container-image scanning, least-privilege access, secrets management, and encryption built in as defaults.
- Monitoring, logging, vulnerability scanning, and incident-response practices that keep your assigned delivery components running.
- Progressive delivery and low-downtime deployment strategies, including blue/green and canary deployments with automated health checks and rollback.
- Pipeline reliability and software-delivery performance metrics, together with evidence supporting an Authority to Operate (ATO) and continuous monitoring.
- And over time, the firm itself, through the new capabilities, tools, and lines of business you help launch.
Who you are
You build security and reliability into the work from the start because they cannot be afterthoughts in a federal environment. You automate what others do by hand and leave an audit trail. You experiment, learn from failure, and try again quickly. You would rather own an outcome than simply be given a task.
What you bring
- Hands-on ownership of assigned CI/CD pipelines, whether AWS-native or comparable, together with infrastructure as code and containerization for deploying real systems in AWS or a client-managed, on-premises environment.
- The security skills a pipeline needs, including automated security testing (SAST, DAST, SCA), vulnerability scanning, secrets management, and least-privilege design.
- Python or Bash scripting beyond pipeline configuration, so you can automate the work the tools do not cover.
- Judgment suited to building where security and auditability are not optional.
What you'll need
Sole United States citizenship and the ability to obtain a Public Trust determination are required for this initial engagement. This is a hybrid role based in the Washington, DC metropolitan area, and it requires commuting into DC regularly. Everything else, including the years, certifications, and specific tools, we ask in the application and discuss during the interview.
What we offer
A high-performing team of developers, engineers, data scientists, architects, and strategists solving complex, real-world problems, with work that runs from strategy formulation to hands-on implementation. We develop people across roles and clients, with extensive onboarding and sponsored training and professional development. And Peregrine has been a Benefit Corporation from day one: public value is built into the work itself, not bolted on afterward. Work worth your best years.
What we commit to
As a Benefit Corporation, our commitment runs three ways: real, measurable value for our clients; government that works better for the public; and a team that makes everyone in it better.
We hire people who want to help build the firm, not just work at it. If that is you, apply.
Peregrine Advisors is an equal opportunity employer.
Peregrine exclusively works with OPEN Data Jobs to recruit our team. Register with OPEN Data Jobs to be considered for this opening and future roles.
Requirements
- At least four years of DevSecOps or platform engineering experience
- A bachelor's degree in computer science or a related field
- Hands-on CI/CD pipeline automation with security gates, using AWS-native tools (CodePipeline, CodeBuild) or comparable tools (GitHub Actions, GitLab CI)
- Infrastructure as code (CloudFormation or Terraform) and containerization
- Automated security testing (SAST, DAST, SCA) and vulnerability scanning
- Scripting in Python or Bash
- Git-based version control
- Monitoring and logging
- Basic proficiency in writing, PowerPoint, and Excel
Preferred
- Federal security experience supporting Federal Information Security Modernization Act (FISMA) compliance, implementing National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53) controls, and providing Authority to Operate (ATO) support
- An Amazon Web Services certification
- Kubernetes
- Secrets management with HashiCorp Vault, AWS Secrets Manager, or a comparable tool
- Experience applying zero trust principles, including identity-centered access, least privilege, and continuous verification
- Software supply-chain integrity practice, including software bills of materials (SBOMs) and artifact signing
- Federal information technology experience
- Familiarity with artificial intelligence (AI)-assisted developer tooling
Benefits
Medical, dental, and vision with the employee premium fully paid and half of dependent premiums; employer-paid life, accidental death, and short-term and long-term disability insurance; a 401(k) matched 100% up to 4% of salary, vesting immediately; unlimited paid time off; and sponsored professional certifications and continuing education.