Washington, DC

Salary
Posted
Jul 14, 2026
Location
Washington, DC
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A mid-level DevSecOps engineer role supporting a federal agency's hybrid-cloud infrastructure, focused on maintaining and improving Terraform/OpenTofu and Ansible codebases, building security-integrated CI/CD pipelines with GitHub Actions, and managing containerized workloads via Docker, Kubernetes, and Helm. The role suits someone with hands-on infrastructure automation experience who is comfortable working within formal change control, compliance frameworks such as NIST SP 800-53 and FISMA, and government IT environments.

Mid level · 5+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Full-time

Must have (11)
Terraform or OpentofuAnsibleGitHub ActionsDockerKubernetesHelmTrivy or GrypeSemgrep, Checkov or TfsecGitleaks or Detect SecretsOPARego
Nice to have (2)
CKAHashiCorp Terraform Associate

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 75 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (software developers). range 15–140

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
Trivy1%Ansible8%Terraform11%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Docker53%GitHub Actions40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $158,337 (middle half $126,441–$180,105).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The job description contains a significant copy-paste anomaly: the Work Environment, Physical Demands, and Position Type sections describe an unrelated 'executive Navy leadership' role with classified communication systems and extensive travel — this boilerplate is clearly mismatched and should be disregarded; the actual role is a hybrid on-site DevSecOps engineer supporting CBO facilities in Washington, DC, Ashburn, VA, and Manassas, VA.

Security clearance: the JD requires a Public Trust Tier 2 (not a national-security clearance), obtained via a U.S. Capitol Police background check. This is a suitability/fitness determination, not a DoD clearance, so the clearance requirement is set to None — but hiring managers should note the Public Trust requirement as a meaningful vetting gate.

Degree: the JD accepts 'equivalent professional experience' in lieu of a Bachelor's degree, so no hard degree gate is set.

SAST tools (Semgrep, Checkov, tfsec) are listed together as a single requirement; Semgrep is used as the primary name with Checkov and tfsec as alternatives. Similarly, container scanning tools Trivy/Grype are captured as one requirement, and secrets-scanning tools Gitleaks/Detect-Secrets as one requirement.

OPA and Rego are emitted as separate skills because they are distinct (the policy engine vs. its query language), both named explicitly in the requirements section.

Federal/regulated environment experience is listed as 'preferred' in the Experience section and is marked accordingly.

CKA and HashiCorp Terraform Associate certifications are explicitly called 'preferred' and marked accordingly.

No compensation range is stated in the posting.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, Federal/regulated environment experience.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗