DevSecOps Engineer
Sign up free to see how well your resume matches this role.
About this role
ICF’s Digital Modernization division is a rapidly growing, entrepreneurial, technology department, seeking a DevSecOps Engineer to support upcoming needs with our federal customers.
Our Digital Modernization division is an information technology and management consulting department that offers integrated, strategic solutions to its public and private-sector clients. ICF has the expertise, agility, and commitment to design, build, and operate high-performance IT engines to support all aspects of our client’s business.
We are seeking a DevSecOps Engineer to support a federal client by helping integrate security practices into modern cloud and application delivery workflows. You will work alongside senior DevOps, security, and application teams to support CI/CD pipelines, cloud infrastructure, automated testing, and security controls in alignment with federal standards. Work is fully remote within the United States on government-furnished equipment, with core collaboration hours in Eastern Time.
Job Location: Remote work is authorized. Must support US Eastern time zone working hours.
*If you accept this position, you should note that ICF does monitor employee work locations blocks access from foreign locations/foreign IP addresses and prohibits personal VPN connections.
What You Will Do:
- Assist in the development, maintenance, and monitoring of CI/CD pipelines using tools such as GitLab CI or Jenkins, including artifact management (e.g., Nexus)
- Support automated deployment and environment promotion for applications built on a COTS/low-code platform (e.g., Appian), from development through test and production
- Help implement automated quality gates in pipelines — unit/integration test execution, automated regression suites, and code-quality/static analysis — in support of contract quality targets
- Help integrate security scanning and compliance checks into build and deployment pipelines (SAST, DAST, dependency scanning, container scanning)
- Support cloud infrastructure in AWS or Azure, including GovCloud regions, with an emphasis on security best practices; support infrastructure as code (IaC) using tools like Terraform, CloudFormation, or platform-native tooling
- Support monitoring and observability — log aggregation and streaming to enterprise monitoring (e.g., Splunk), alerting, performance testing (e.g., JMeter) — and assist with troubleshooting and incident response
- Support backup/recovery operations and availability, recovery-time, and recovery-point objectives
- Document configurations, processes, and security controls to support audits, Assessment & Authorization (ATO) activities, and continuous-monitoring evidence
- Collaborate with development, operations, and security teams in an Agile/Scrum environment
- Learn and apply federal security frameworks such as NIST 800-53, FISMA, and FedRAMP
What You Will Bring:
- U.S. citizenship, required due to federal contract requirements
- Must reside in the United States (U.S.) and the work must be performed in the United States (U.S.), as this work is for a federal contract and laws do apply
- Ability to obtain and maintain a favorable federal agency background investigation / suitability determination
- 5+ years of experience in DevOps, cloud engineering, systems engineering, or cybersecurity
What We Would Like You To Have:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related technical field
- An active federal security clearance or a prior favorable federal background investigation (supports reciprocity and faster onboarding)
- Basic understanding of CI/CD concepts and DevOps practices; experience with GitLab and/or Jenkins specifically
- Familiarity with at least one cloud platform (AWS or Azure preferred, including GovCloud)
- Working knowledge of Linux (e.g., RHEL) and Windows Server environments, and basic scripting (Bash, Python, PowerShell, or similar)
- Exposure to DevSecOps and security tooling (e.g., SonarQube, Tenable, Snyk, Trivy, Checkov, Prisma Cloud)
- Experience with Docker and basic Kubernetes or OpenShift concepts
- Familiarity with SIEM/log-analysis platforms such as Splunk
- Exposure to low-code or COTS application platforms (e.g., Appian, Salesforce, ServiceNow) and their deployment/release models
- Basic familiarity with relational databases (e.g., SQL Server)
- Familiarity with NIST 800-53, FedRAMP, or other federal security standards
- Entry-level certifications such as AWS Cloud Practitioner, Azure Fundamentals, Security+, or similar
- Experience supporting applications in a regulated or government environment
#LI-CC1
#Indeed
Bot and Third-Party Applications
Please note that this application must be submitted directly by the applicant for consideration. Failure to do so may result in the application being excluded for consideration. Applicants needing an accommodation for disability or religious purposes in connection with the application process should contact Candidateaccommodation@icf.com for assistance.
Working at ICF
ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy.
We will consider for employment qualified applicants with arrest and conviction records.
Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act.
At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.
However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.
Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position.
The pay range for this position based on full-time employment is:
$98,614.00 - $167,644.00Nationwide Remote Office (US99)Company
Company facts come from this company's own listings. We only show what the postings themselves carry.