Kgs

Open

DevSecOps Lead Engineer

Location
Washington, DC, US
Posted
Jul 14, 2026
Last seen
Aug 21, 2026

About the role

Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a DevSecOps Lead Engineer to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more. Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced DevSecOps Lead Engineer to support the design, implementation, and management of DevSecOps practices, pipelines, and culture in support of the U.S. Small Business Administration (SBA). The ideal candidate is a senior-level engineering professional with deep expertise in DevSecOps methodologies, CI/CD pipeline development, security automation, and cloud-native technologies, and a proven track record of leading DevSecOps transformation efforts within complex federal government environments. This individual will serve as the technical lead and subject matter expert for SBA's DevSecOps program, driving the integration of security into every phase of the software development lifecycle, accelerating the delivery of secure, high-quality software, and fostering a culture of collaboration, automation, and continuous improvement across SBA's development and operations teams. The DevSecOps Lead Engineer will serve as the senior technical lead and SME for DevSecOps practices and implementation at the SBA, working closely with SBA's IT leadership, development teams, security teams, operations staff, and program managers to design, build, and continuously improve a robust DevSecOps program that enables the rapid, secure, and reliable delivery of software and infrastructure solutions in support of SBA's mission. Principal responsibilities will include but are not limited to: • Serve as the senior technical lead and SME for DevSecOps practices, pipelines, and culture at the SBA, providing expert guidance, strategic direction, and hands-on technical leadership to development, security, and operations teams across the organization. • Lead the design, development, implementation, and continuous improvement of SBA's CI/CD pipelines and DevSecOps toolchain, ensuring pipelines are automated, secure, scalable, and aligned with SBA's software delivery and security requirements. • Drive the integration of security practices, tools, and automation throughout the software development lifecycle (SDLC), including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container security scanning, and infrastructure as code (IaC) security scanning. • Lead the development and implementation of SBA's DevSecOps strategy, roadmap, and standards, ensuring alignment with federal DevSecOps guidance, SBA's enterprise architecture framework, and industry best practices. • Oversee the design, implementation, and management of infrastructure as code (IaC) practices and tools, enabling automated, repeatable, and auditable provisioning and management of SBA's IT infrastructure and cloud environments. • Collaborate with SBA's development, security, and operations teams to establish and enforce DevSecOps standards, coding best practices, security requirements, and quality gates within the CI/CD pipeline. • Lead the evaluation, selection, and implementation of DevSecOps tools and platforms, including source code management, CI/CD orchestration, container orchestration, artifact management, security scanning, and monitoring solutions appropriate for SBA's environment. • Provide technical leadership and oversight for the containerization and orchestration of SBA applications, ensuring container images are properly secured, scanned, and managed in accordance with SBA security requirements and federal guidelines. • Support the planning and execution of cloud migration and modernization initiatives, applying DevSecOps principles and practices to accelerate the secure migration of SBA workloads to cloud environments. • Develop and maintain comprehensive DevSecOps documentation including pipeline architecture designs, technical runbooks, standards and guidelines, and training materials to support SBA's DevSecOps program. • Collaborate with SBA's ISSO and security teams to ensure DevSecOps pipelines and practices support the maintenance of system Authorization to Operate (ATO) requirements, including the automation of security control testing and continuous monitoring activities where applicable. • Lead and conduct code reviews, architecture reviews, and security reviews for DevSecOps pipeline components and infrastructure as code artifacts, ensuring they meet SBA's quality and security standards. • Provide technical mentorship and guidance to junior and mid-level engineers, developers, and operations staff, fostering a culture of learning, collaboration, and continuous improvement across SBA's technical teams. • Develop and deliver DevSecOps training, workshops, and knowledge-sharing sessions for SBA technical staff, helping to build organizational capability and support for DevSecOps principles and practices • Monitor and analyze the performance, reliability, and security of SBA's DevSecOps pipelines and toolchain, identifying and implementing improvements to enhance pipeline efficiency, security, and overall effectiveness. • Stay at the forefront of DevSecOps technology developments, federal policy guidance, and industry best practices, applying this knowledge to continuously refine and improve SBA's DevSecOps program. Education and Experience: Required: • Bachelor's degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or a related field from an accredited college or university, OR equivalent combination of education and extensive relevant work experience. • 7+ years of progressive experience in software engineering, systems engineering, or DevOps/DevSecOps, with significant demonstrated experience designing, implementing, and managing CI/CD pipelines and DevSecOps practices in a federal government or large enterprise environment. • Demonstrated expert-level hands-on experience with CI/CD tools and platforms such as Jenkins, GitLab CI/CD, GitHub Actions, or similar, and container orchestration platforms such as Kubernetes or Red Hat OpenShift.Demonstrated experience integrating security tools and automation into CI/CD pipelines including SAST, DAST, SCA, and container security scanning solutions. • One or more of the following certifications: Certified Kubernetes Administrator (CKA), AWS Certified DevOps Engineer, Microsoft Certified: DevOps Engineer Expert, or equivalent senior-level DevSecOps or cloud engineering certification. Desired: • Master's degree in Computer Science, Software Engineering, Information Technology, or a related field. • Prior experience leading DevSecOps program development and implementation at a federal civilian agency, preferably the SBA or a similar organization. • Certified Kubernetes Security Specialist (CKS), AWS Certified Security – Specialty, or other relevant advanced cloud security or DevSecOps certifications. • Red Hat Certified Engineer (RHCE) or Red Hat Certified Architect (RHCA) certification. Required Skills and Competencies: • Expert-level knowledge of DevSecOps principles, methodologies, and best practices and their application to the design, implementation, and management of secure, automated software delivery pipelines in a federal government environment. • Demonstrated expert-level hands-on experience with CI/CD tools and platforms including Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, or similar, and the ability to design, build, and optimize complex CI/CD pipeline architectures. • Deep technical expertise in containerization and container orchestration technologies including Docker, Kubernetes, and Red