
DevSecOps Engineer / Cyber Engineer
- $150k – $185k
- |
- |6 years of exp
- |Full Time
In office
Not Available
About the job
Location: Fairfax, VA (On-site, full-time)
Employment Type: Full-time
Status: Immediate
About the Role
Signal Hill Technologies is seeking a DevSecOps Engineer / Cyber Engineer to embed security throughout the software development and delivery lifecycle for our government and commercial clients. This is both a hands-on engineering role and a technical advisory role — you'll build security directly into CI/CD pipelines, assess the applications and infrastructure moving through them, and help our teams ship secure, resilient systems faster.
You'll work across the hardware-to-application stack: reviewing code and pipeline configurations, running and triaging security scans, and partnering with engineering teams so that security is a built-in property of what we ship - not a gate at the end.
About Signal Hill Technologies
Founded and led by veteran cyber operators, Signal Hill Technologies delivers advanced cybersecurity solutions to DoD, Intelligence Community, financial services, and critical infrastructure clients, with many years of experience defending both US Government and commercial clients against sophisticated, well-funded, motivated adversaries. We are relentless about real results and operationally proven expertise. Our mission is to provide the best technical solutions and hands-on support to address each customer's unique cyber risks.
Position Responsibilities
- Develop secure software testing and validation procedures for applications moving through the CI/CD pipeline (e.g., Jenkins, GitHub Actions).
- Integrate and tune SAST/DAST tooling within build and release pipelines; reconcile scan output and validate findings as true positives.
- Perform secure code review and program testing to identify flaws and mitigate vulnerabilities prior to release, applying standards such as OWASP ASVS and the DevSecOps Maturity Model (DSOMM).
- Perform risk analysis — threat, vulnerability, and probability of occurrence — whenever an application or system undergoes a major change.
- Address security implications across the software acceptance phase, including completion criteria, risk acceptance and documentation, and independent testing methods.
- Prepare security assessment and authorization documentation and communicate findings and secure-coding guidance clearly to both technical and non-technical stakeholders.
- Consult with engineering and development staff to evaluate the interface between hardware, software, and infrastructure, and to identify security issues around steady-state operation and end-of-life management.
- Support the development and refinement of DevSecOps processes, pipeline security gates, and reporting standards.
Minimum Qualifications
- Public Trust eligible (U.S. citizenship or green card required and ability to pass a background investigation).
- Minimum of 6 years of relevant cybersecurity/DevSecOps engineering experience, including at least 2 years of hands-on application security experience.
- Proficiency in DevSecOps concepts, including CI/CD pipelines, Jenkins and/or GitHub Actions, and SAST/DAST integration and automation.
- Scripting proficiency in Python and/or PowerShell.
- Experience with systems integration, including APIs, API security, and databases.
- Strong collaborative and interpersonal skills, with the ability to clearly communicate technical findings and secure-coding guidance to both technical and non-technical audiences.
- Working knowledge of cybersecurity and privacy principles, risk management processes, and common system/application vulnerabilities (e.g., injection, buffer overflow, cross-site scripting).
- Hands-on experience with code analysis and vulnerability scanning tools (e.g., Burp Suite Professional or similar SAST/DAST tooling).
Preferred Qualifications
- Bachelor's degree in Computer Science, Cybersecurity Engineering, Computer Engineering, Systems Engineering, Computer Information Systems, or a related field.
- Prior federal work experience.
- Cloud security engineering experience in AWS and/or Azure, including IAM policy and configuration.
- Familiarity with infrastructure automation and configuration management tooling (e.g., Ansible, Terraform).
- Familiarity with the Risk Management Framework and related security/privacy controls (NIST SP 800-37, NIST SP 800-53) and/or FedRAMP.
- Experience with enterprise security tooling such as SIEM, WAF, IPS, or endpoint security.
- Certifications: e.g., CompTIA CASP+, (ISC)² CISSP/CSSLP/SSCP, GIAC (GICSP, GISF, GSSP), or a cloud security certification such as AWS Certified Security – Specialty.
Bonus: We Love Multi-Talented Engineers
This posting is focused on DevSecOps engineering, but Signal Hill supports a range of cybersecurity engineering functions for our clients — including cloud security architecture, identity and access management, and systems security engineering — and those needs shift as our contracts evolve. We don't have a defined cross-training path mapped out yet, but if you're the kind of engineer who's comfortable picking up adjacent disciplines and growing into new responsibilities over time, we want to know that about you. Tell us in your application where else you've stretched beyond your core role.
Benefits
- Compensation: $150k-185k annually (depending on experience)
- Company health plan
- 401(k) plan with employer match
- Paid holidays and paid time off
- Education reimbursement
How to Apply
Submit a detailed resume (including complete work history with month/year for each role and all certifications) directly through LinkedIn. Please account for any gaps in employment and specify all relevant training and degrees with the year and month earned.
Signal Hill Technologies is an equal opportunity employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law.
About the company

Signal Hill Technologies
Similar Jobs




