NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / DevOps Engineer in United States of America
8 hours ago
Apply with autofill
Apply with autofill
BO
Bowhead·8 hours ago
8 hours ago

Sr. DevSecOps Engineer

San Diego, United States of AmericaSenior · 5-8 yearsDevOps Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at bowhead

How you compare FREE

?
Your scoreYour score: not yet known
→
68
Top 10%Top 10%: 68 out of 100

Top 10% of NextRaise users matched against DevOps Engineer roles in United States.

Must-have skills for this role

  • linux
  • openscap
  • disa stigs
  • rmf

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Build automated OpenSCAP pipelines to scan Ubuntu 24.04 LTS and other Linux hosts using DISA STIG benchmarks.
  • Integrate XCCDF and OVAL results into OpenRMF using automated ingestion workflows.
  • Develop hardened base images (VMs and containers) aligned to DISA STIG requirements.
  • Integrate RapidFort scans into CI/CD pipelines.
  • Automate ingestion of SCAP JSON into OpenRMF.
  • Ensure curated images remain compliant and low-CVE.
  • Support generation of automated DISA checklists (CKLs) and POA&M updates.
  • Work with compliance and engineering teams to resolve findings and track remediation progress via OpenRMF.
  • Deploy/tune Wazuh agents across hosts and workloads.
  • Configure pipelines from Wazuh → Elastic → Tines.
  • Write and maintain Elastic SIEM detection rules.
  • Develop Tines workflows to automate SCAP ingestion, RapidFort event processing, Elastic SIEM alert enrichment, and compliance notifications & ticketing.

What they're looking for

  • Five to ten (10+) years Linux engineering with security hardening focus
  • Hands-on experience with OpenSCAP, DISA STIGs, SCAP benchmarks, and STIG automation
  • Experience working with OpenRMF (or similar RMF automation platforms)
  • Strong knowledge of RMF, FedRAMP, or CMMC
  • CI/CD pipeline experience (GitLab CI, GitHub Actions, Jenkins, etc.)
  • Hands-on experience with Elastic Stack and Wazuh
  • Experience deploying or integrating SOAR platforms (Tines preferred; XSOAR or Splunk SOAR acceptable)
  • Container security experience (RapidFort, Anchore, Trivy, Aqua, etc.)

Nice to have

  • Familiarity with ATO workflows (IL4/IL5, DoD impact levels)
  • AI integration experience using OpenAI, Azure OpenAI, or similar
  • Python or Bash scripting for automation
  • Experience with NIST 800-53, CNSSI 1253, or DoD Cybersecurity standards

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Overview

SR. DEVSECOPS ENGINEER (PACMED):

 

Bowhead seeks a Sr. DevSecOps Engineer to support in operational systems integration, development, test, evaluation, operation, sustainment, and maintenance using technologies and acquisition management to support technical, ancillary, and clinical support to military medical treatment facilities in the pacific Region. This position will support building a next-generation automated compliance and AI-driven security operations platform supporting DoD, federal health, and enterprise health-care environments. The Sr. DevSecOps Engineer will provide deep experience in DISA STIGs, SCAP automation, RMF workflows, container security, SIEM/SOAR integrations, and AI-assisted security operations.

 

Responsibilities

SCAP / STIG Automation

  • Build automated OpenSCAP pipelines to scan Ubuntu 24.04 LTS and other Linux hosts using DISA STIG benchmarks.
  • Integrate XCCDF and OVAL results into OpenRMF using automated ingestion workflows.
  • Develop hardened base images (VMs and containers) aligned to DISA STIG requirements.

Container Security

  • Integrate RapidFort scans into CI/CD pipelines.
  • Automate ingestion of SCAP JSON into OpenRMF.
  • Ensure curated images remain compliant and low-CVE.

Compliance Operations (RMF/FedRAMP/CMMC)

  • Support generation of automated DISA checklists (CKLs) and POA&M updates.
  • Work with compliance and engineering teams to resolve findings and track remediation progress via OpenRMF.

Security Telemetry & SIEM Engineering

  • Deploy/tune Wazuh agents across hosts and workloads.
  • Configure pipelines from Wazuh → Elastic → Tines.
  • Write and maintain Elastic SIEM detection rules.

SOAR Automation & AI SOC Buildout

  • Develop Tines workflows to automate:
    • SCAP ingestion
    • RapidFort event processing
    • Elastic SIEM alert enrichment
    • Compliance notifications & ticketing
  • Integrate LLMs to:
    • Summarize alerts
    • Draft POA&M entries
    • Generate remediation guidance
    • Produce daily/weekly SOC and compliance reports

Infrastructure & DevSecOps

  • Contribute to secure CI/CD pipelines, secrets management, system hardening, logging, and access control aligned with DoD RMF.

Qualifications

Must-Have Technical Expertise

  • Five to ten (10+) years Linux engineering with security hardening focus
  • Hands-on experience with OpenSCAP, DISA STIGs, SCAP benchmarks, and STIG automation
  • Experience working with OpenRMF (or similar RMF automation platforms)
  • Strong knowledge of RMF, FedRAMP, or CMMC
  • CI/CD pipeline experience (GitLab CI, GitHub Actions, Jenkins, etc.)
  • Hands-on experience with Elastic Stack and Wazuh
  • Experience deploying or integrating SOAR platforms (Tines preferred; XSOAR or Splunk SOAR acceptable)
  • Container security experience (RapidFort, Anchore, Trivy, Aqua, etc.)

Bonus Skills

  • Familiarity with ATO workflows (IL4/IL5, DoD impact levels)
  • AI integration experience using OpenAI, Azure OpenAI, or similar
  • Python or Bash scripting for automation
  • Experience with NIST 800-53, CNSSI 1253, or DoD Cybersecurity standards

Soft Skills

  • Ability to lead architecture decisions and mentor others
  • Strong communicator capable of translating compliance needs into technical workflows
  • Able to operate independently in a fast-paced federal/healthcare environment
  • Comfortable producing documentation for audits and ATO packages

 

Physical Demands:

  • Must be able to lift up to 20 pounds
  • Must be able to stand and walk for prolonged amounts of time
  • Must be able to twist, bend and squat periodically

Target salary range is between $120,000 - $150,000 commensurate with experience.

 

Please note that the salary information is a general guideline only. Bowhead considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.

 

SECURITY CLEARANCE REQUIREMENTS: Must be able to obtain a security clearance at the Public Trust level. US Citizenship is a requirement.

 

#LI-KC1

Company

BO
Bowhead
San Diego, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Bowhead's careers site·first seen 22 Sept 2026·last verified 22 Sept 2026·How we source jobs

Similar jobs

  • DevOps Engineer Senior at Science Applications InternationalSterling, United States of America–match not yet calculated
  • Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada at Shift TechnologyBoston, United States of America–match not yet calculated
  • Senior DevOps Engineer 25k Sign on Bonus at leidosColumbia, MD–match not yet calculated
  • Co-op, DevOps Engineer: January - June 2027 (Hybrid) at insuletActon, United States of America–match not yet calculated
  • Senior DevOps Engineer at 1xSan Carlos, United States of America–match not yet calculated

Browse more jobs

  • DevOps Engineer jobs in United States
  • Systems Engineer jobs in United States
  • Network Engineer jobs in United States
  • Platform Engineer jobs in United States
  • DevOps Engineer jobs in India
  • DevOps Engineer jobs in United Kingdom