About this role
Position Title: Senior DevSecOps & Software Engineer
Location: Pentagon, Arlington, Virginia
Category: Funded
Schedule (FT/PT): Full Time
Travel Required: May require occasional domestic travel
Shift: Day
Remote Type: In-Office
Clearance required: Current Top Secret. Sensitive Compartmented Information (SCI) eligibility
Salary: $170,000 - $200,000
Who is ACT1 Federal? ACT1 Federal LLC is a 100% employee-owned company. We’ve served the Department of War (DoW) for nearly thirty years. Our core missions include weapon systems engineering, logistics, space domain expertise, global defense and security, business and financial management for security assistance and major defense articles, as well as military training and arctic security. Join us!
Description: ACT1 Federal is seeking an experienced Senior DevSecOps & Software Engineer to provide senior-level software-engineering, DevSecOps, cybersecurity-engineering, and implementation-support services to the Director of Data Management and Performance Assessment, Office of the Deputy Assistant Secretary of the Navy for the Defense Industrial Base (DASN (DIB)). The engineer supports Department of the Navy (DON) efforts to develop, secure, deploy, and sustain software applications and analytic tools used to assess the defense industrial base, including industrial capacity, supply-chain risk, investment activity, performance, and program outcomes.
This position requires a senior technical subject matter expert with demonstrated experience delivering secure software applications and DevSecOps capabilities in Department of War, Federal, regulated, or other enterprise-scale environments. The engineer shall be capable of designing, developing, testing, containerizing, securing, and supporting deployment of applications through Government-approved pipelines and authorized environments.
Responsibilities:
- Provide software-engineering, DevSecOps, cybersecurity-engineering, platform-engineering, and implementation-support services for DASN (DIB) data-management and performance-assessment initiatives.
- Design, develop, test, document, maintain, and support deployment of software applications, analytic tools, data services, application programming interfaces, and related components.
- Develop applications using Python or comparable modern programming languages, frameworks, libraries, and development practices appropriate to Government-approved technical environments.
- Design and implement secure application architectures, application programming interfaces, data integrations, authentication and authorization mechanisms, error handling, logging, monitoring, and performance-management capabilities.
- Containerize applications and services; develop container-orchestration configurations; and support deployment through Government-approved development, testing, staging, and production environments.
- Develop, configure, maintain, document, and improve continuous integration and continuous delivery pipelines, source-code-management practices, artifact-management processes, automated testing, release-management workflows, and deployment automation, as authorized by the Government.
- Develop infrastructure-as-code artifacts, configuration-management approaches, automation scripts, deployment manifests, and repeatable environment-configuration practices supporting authorized application delivery and sustainment.
- Support integration with Department of War software factories, enterprise pipelines, cloud services, data platforms, source systems, and other Government-approved technical environments.
- Support deployment and sustainment of approved analytics, data-engineering, artificial-intelligence, machine-learning, reporting, and business-intelligence applications developed within or provided to DASN (DIB).
- Provide technical implementation, documentation, remediation, and coordination support for Government-led Risk Management Framework activities.
- Support implementation and documentation of security controls; secure configuration practices; vulnerability identification and remediation; Security Technical Implementation Guide assessment and remediation; continuous-monitoring activities; and authorization-package development.
- Prepare technical artifacts supporting Government security-review, assessment, authorization-package, and continuous-monitoring activities, including system descriptions, architecture diagrams, control-implementation narratives, configuration documentation, test evidence, remediation plans, and related work products.
- Conduct code reviews, automated testing, static and dynamic application-security testing, dependency analysis, container scanning, configuration reviews, and other Government-approved secure-software-development activities.
- Prepare executive briefings, technical memoranda, implementation plans, architecture diagrams, decision packages, status reports, and risk summaries for senior technical and nontechnical stakeholders.
- Coordinate technical products and supporting information with DASN (DIB) directorates, ASN (RD&A) offices, DON acquisition organizations, DON enterprise service providers, Department of War stakeholders, cybersecurity organizations, and other Government-approved points of contact, as directed by the Government.
- Support time-sensitive taskers, technical reviews, executive engagements, and approved working groups associated with software development, DevSecOps, cybersecurity, data, analytics, and industrial-base performance-assessment initiatives.
Requirements:
- Bachelor's degree from an accredited institution in data science, statistics, mathematics, economics, operations research, engineering, computer science, business analytics, or a related quantitative discipline.
- 10+ years’ experience in software engineering, DevSecOps, platform engineering, cloud-native application development, cybersecurity engineering, or related technical fields.
- Demonstrated experience designing, developing, testing, containerizing, securing, and deploying production software applications.
- Demonstrated experience developing or maintaining continuous integration and continuous delivery pipelines, source-code-management processes, artifact-management workflows, automated testing, deployment automation, and release-management practices.
- Demonstrated experience with Python or a comparable modern programming language.
- Demonstrated experience with container technologies, container orchestration, infrastructure as code, configuration management, cloud-native or enterprise application deployment, and automation.
- Demonstrated experience developing, integrating, securing, or sustaining application programming interfaces, data integrations, and enterprise application services.
- Demonstrated experience supporting Risk Management Framework technical implementation, security-control implementation, security documentation, vulnerability management, Security Technical Implementation Guide assessment and remediation, or authorization-package development.
- Demonstrated ability to communicate technical risks, implementation status, security findings, architecture decisions, and delivery tradeoffs to senior technical and nontechnical stakeholders.
- At least one relevant cybersecurity, cloud-security, DevSecOps, container-security, software-engineering, or Department of War workforce-qualification certification.
- The position may require support outside normal business hours to meet time-sensitive transaction, interagency, executive, or industrial-base requirements.
- Current Top Secret. Sensitive Compartmented Information (SCI) eligibility required
Benefits:
- Medical/Dental/Vision Insurance
- ACT1 Employee Stock Ownership Plan (ESOP)
- Company Paid Life and AD&D Insurance
- Company Paid Short-Term Disability
- Voluntary Long-Term Disability
- Flexible Spending Accounts (FSA)
- Health Savings Account (HSA)
- 401K with employer match
- Paid Time Off
- Paid Holidays
- Parental Leave
- Military Leave
- Education, Training & Professional Development
- Voluntary Accidental Injury/Critical Illness/Hospital Care
- Voluntary Pet Insurance, Legal Resources, and Identity Protection
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
- If this position is listed as remote or hybrid, you’ll periodically work from a ACT1 Federal or client site facility.
- If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local or international law.