About this DevSecOps Engineer, AWS Secure Delivery role at OpenDataJobs
At Peregrine Advisors, you will own the delivery pipelines, automation, and environments that carry federal systems into production. But we hire people, not seats. As the work evolves, you will learn new systems and tools, take on greater responsibility, and help develop the firm's capabilities, tools, and lines of business. We move our best to where the hardest problems are.
This is a full-time W-2 position with a salary of $120,000 to $140,000 per year. It is a hybrid work arrangement based in the Washington, DC metropolitan area, and the commuting cadence varies by assignment. The initial engagement requires United States citizenship and the ability to obtain a Public Trust determination.
We are a data and technology innovation hub and a Benefit Corporation working at the center of the federal government's mission to deliver for client stakeholders and the US public.
Your first project
Your first project will likely have you owning assigned delivery pipelines and the environments beneath them. Depending on the assignment, you may:
- Build continuous integration and continuous delivery (CI/CD) pipelines with security gates and controlled promotion.
- Define the infrastructure beneath those pipelines as code, with reproducible environments and least-privilege access.
- Automate security testing, vulnerability scanning, and secrets management across the delivery path.
- Build the monitoring and evidence that support Risk Management Framework (RMF) authorization and continuous monitoring.
You deliver pipelines that enforce the required controls and produce the evidence a release review needs. You automate the manual steps out of the release path, and you build progressive delivery with automated health checks and rollback so that deploying stops being an event.
This is where you start, not the shape of your career here.
Requirements
- At least four years of DevSecOps or platform engineering experience
- A bachelor's degree in computer science or a related field
- Hands-on CI/CD pipeline automation with security gates, using AWS-native tools (CodePipeline, CodeBuild) or comparable tools (GitHub Actions, GitLab CI)
- Infrastructure as code (CloudFormation or Terraform) and containerization
- Automated security testing (SAST, DAST, SCA) and vulnerability scanning
- Scripting in Python or Bash
- Git-based version control
- Monitoring and logging
- Basic proficiency in writing, PowerPoint, and Excel
Preferred
- Federal security experience supporting Federal Information Security Modernization Act (FISMA) compliance, implementing National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53) controls, and providing Authority to Operate (ATO) support
- An Amazon Web Services certification
- Kubernetes
- Secrets management with HashiCorp Vault, AWS Secrets Manager, or a comparable tool
- Experience applying zero trust principles, including identity-centered access, least privilege, and continuous verification
- Software supply-chain integrity practice, including software bills of materials (SBOMs) and artifact signing
- Federal information technology experience
- Familiarity with artificial intelligence (AI)-assisted developer tooling
Who you are
You build security and reliability into the work from the start because they cannot be afterthoughts in a federal environment. You automate what others do by hand and leave an audit trail. You experiment, learn from failure, and try again quickly. You would rather own an outcome than simply be given a task.
What you bring
- Hands-on ownership of assigned CI/CD pipelines, whether AWS-native or comparable, together with infrastructure as code and containerization for deploying real systems in AWS or a client-managed, on-premises environment.
- The security skills a pipeline needs, including automated security testing (SAST, DAST, SCA), vulnerability scanning, secrets management, and least-privilege design.
- Python or Bash scripting beyond pipeline configuration, so you can automate the work the tools do not cover.
- Judgment suited to building where security and auditability are not optional.
You adapt your development workflow as AI tools evolve, using them to help implement, test, and improve the components you own. You give the tools clear context, review and test their output, and remain accountable for the code you deliver.
When we talk
Be prepared to discuss a difficult problem you worked through, the decisions you made, what happened, and what you learned.
Benefits
Medical, dental, and vision with the employee premium fully paid and half of dependent premiums; employer-paid life, accidental death, and short-term and long-term disability insurance; a 401(k) matched 100% up to 4% of salary, vesting immediately; unlimited paid time off; and sponsored professional certifications and continuing education.
What we offer
You will work alongside developers, engineers, data scientists, architects, and strategists, on work ranging from strategy to implementation. We support your development across assignments and clients through extensive onboarding, sponsored professional certifications such as the Data Management Capability Assessment Model (DCAM) and AWS technical certifications, and rotation across functions to expand your skills and perspective. The mission is real, the problems are hard, and you own what you ship.
What we commit to
As a Benefit Corporation, our commitment runs three ways: real, measurable value for our clients; government that works better for the public; and a team that makes everyone in it better.
We hire people who want to help build the firm, not just work at it. If that is you, apply.
Peregrine Advisors is an equal opportunity employer.
Peregrine exclusively works with OPEN Data Jobs to recruit our team. Register with OPEN Data Jobs to be considered for this and future openings.