DevSecOps Engineer at Avyanna Technologies
Bethesda, MD
—
Aug 14, 2026
Bethesda, MD
Aug 18, 2026
What this job asks for AI summary
A lead DevSecOps Engineer role supporting a large federal IT program, responsible for designing and operating secure CI/CD pipelines that embed security tooling (SAST, DAST, SCA, container scanning) at every stage. The position manages containerized workloads in GovCloud environments, drives FISMA/RMF compliance and ATO activities, and serves as the technical authority for the DevSecOps toolchain while mentoring junior engineers.
Senior level · 8+ years · Bachelor's required · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $138,970 (middle half $107,524–$175,762).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 18, 2026. It is a model, not a headcount.
Why we read it this way (9)
No work location or metro area is specified in the posting. The role appears to be US-based (federal program, GovCloud, Public Trust clearance) but no city, state, or remote status is stated.
The clearance gate is a federal Public Trust background investigation (MBI or HBI), not a national security clearance (Secret/TS). This does not meet the threshold for any of the clearance enum values above 'None', so it is recorded as None — but hiring managers should note that US citizenship or permanent residency is explicitly required.
SOC classification is Medium confidence. The role primarily BUILDS and operates CI/CD pipelines and IaC (pointing to 15-1252 Software Developers), but the heavy FISMA/RMF/ATO compliance and security-gate integration work creates a genuine pull toward 15-1212 Information Security Analysts.
SAST, DAST, SCA, and container scanning are listed as required capabilities but no specific vendor tools are named; they are captured as named security-practice skills rather than specific products.
OPA ('or similar') is listed under required IaC/policy-as-code responsibilities; alternatives are not named, so the field is left empty per the posting's open-ended framing.
Jenkins is listed with 'GitLab CI/CD or GitHub Actions' as interchangeable options in the required qualifications; all three are captured under one skill entry with alternatives.
OpenShift appears both in the required container technologies list and as a preferred item; it is marked required as part of the Kubernetes/OpenShift pairing in the Required Qualifications section, and also emitted separately as preferred to reflect its standalone mention.
Certifications (CKA, AWS Certified DevOps Engineer, Azure DevOps Engineer) are listed under Preferred Qualifications and are not captured as skills since they are credentials rather than concrete technologies.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.