Logo for AttainX, Inc.

DevSecOps Engineer II

Role overview

Qualifications

  • 3-5 years of related experience in DevSecOps, software engineering, infrastructure automation, or security engineering.
  • A bachelor's degree in computer science, cybersecurity, information systems, engineering, or a related field.
  • Proficiency with CI/CD tools such as Jenkins, GitLab, or Azure DevOps.
  • Experience with static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), vulnerability scanning, and penetration testing frameworks.

Responsibilities

  • Integrate security practices throughout the development, testing, deployment, and operation of DocuSign integrations and supporting infrastructure.
  • Design, implement, and maintain security controls across CI/CD pipelines.
  • Perform regular security assessments, vulnerability scanning, and authorized penetration testing within approved scopes.
  • Implement Infrastructure as Code, automated testing, and controlled release procedures to support secure delivery.

Key facts

Hard skills

Other skills

  • Collaboration
  • Problem Solving
  • Communication

About the company

AttainX, Inc. logo

AttainX, Inc.

IT Services & IT Consulting

AttainX is an SBA certified 8a / EDWOSB / WOSB and CMMI L3, ISO 9001:201, QMS certified company that delivers information technology solutions to Federal and state agencies. Our expertise is in software application development, testing, maintenance, cloud application offerings and migration to cloud technologies, enterprise architecture, cyber security, big data, enterprise service desk and IV&V solutions. We also specialize in ERP Implementation, maintenance and digital transformation of existing business processes. We also have an Engineering Division that support the Air Force and Navy.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Job Title: DevSecOps Engineer II

Location: Remote/Hybrid - DHS CISA; approved remote work location within the 50 United States or the District of Columbia. Government facility attendance may be required.

Work Schedule: Monday through Friday, 8:00 a.m. to 5:00 p.m. Eastern Time; core availability 9:00 a.m. to 3:00 p.m., excluding federal holidays.

Security Requirements: Must obtain and maintain a favorable DHS/CISA Entry on Duty or fitness determination and complete the background investigation appropriate to the position’s sensitivity and required access.

Work Authorization: Must be authorized to work in the United States and meet DHS/CISA personnel and system access requirements.

AttainX is seeking a DevSecOps Engineer II to integrate security practices throughout the DevOps lifecycle for CISA’s DocuSign implementation and integrations, ensuring secure deployment of high-quality IT infrastructure. This role works independently and collaboratively, contributes to moderately complex project activities, and applies secure automation, Infrastructure as Code, and continuous integration and deployment practices.

Qualifications and Education Requirements:

  • 3-5 years of related experience in DevSecOps, software engineering, infrastructure automation, or security engineering.
  • A bachelor’s degree in computer science, cybersecurity, information systems, engineering, or a related field.
  • Proficiency with CI/CD tools such as Jenkins, GitLab, or Azure DevOps, including pipeline automation, version control, Infrastructure as Code, and controlled deployments.
  • Experience with static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), vulnerability scanning, and penetration testing frameworks.
  • Experience programming or scripting in one or more languages such as Python, Perl, Bash, PHP, PowerShell, Java, SQL, or C++.
  • Knowledge of security principles, practices, and technologies, including encryption, authentication, authorization, network security, and secure handling of credentials and secrets.
  • Experience with REST APIs, connectors, webhooks, SaaS integrations, and Microsoft 365 or enterprise identity platforms; DocuSign integration experience is preferred.
  • Experience supporting lifecycle testing, technical documentation, Federal security requirements, and Section 508 accessibility compliance.
  • Ability to work independently and collaborate with architects, developers, security engineers, and stakeholders on moderately complex project activities.
  • A current Microsoft Certified: DevOps Engineer Expert or AWS Certified DevOps Engineer - Professional certification is highly preferred.
  • Must be a US Citizen able to obtain a DHS CISA Public Trust clearance.

Job Duties:

  • Integrate security practices throughout the development, testing, deployment, and operation of DocuSign integrations and supporting infrastructure.
  • Design, implement, and maintain security controls across CI/CD pipelines; automate SAST, DAST, SCA, and other security checks to identify risks before deployment.
  • Perform regular security assessments, vulnerability scanning, and authorized penetration testing within approved scope; prioritize findings and coordinate remediation with development and security teams.
  • Implement Infrastructure as Code, automated testing, and controlled release and rollback procedures to support secure, reliable delivery.
  • Configure and maintain DocuSign accounts, groups, templates, routing rules, administrative settings, policies, alerts, and approved branding.
  • Build and maintain plugins, connectors, and custom APIs for automated envelope creation, routing, and archival; integrate DocuSign with Microsoft 365, enterprise identity systems, and contract or case platforms.
  • Implement encryption, secure authentication, authorization, role-based access, network and boundary protection, and secure credential handling; monitor logs and systems for threats and escalate findings.
  • Develop, maintain, and enforce security policies and procedures aligned with Federal, DHS, and CISA requirements and approved development and deployment practices.
  • Execute developmental and operational tests; document defects, security findings, remediation, test results, and deployment readiness.
  • Automate document conversion and records capture while preserving NARA-compliant formats, metadata consistency, and disposition requirements.
  • Document configurations, deployment procedures, integration architecture, and exception handling; support secure releases and knowledge transfer to system administrators.
  • Stay current with security trends, tools, and technologies; proactively recommend and implement approved improvements to pipeline security, automation, and threat monitoring.

Non-Essential Functions:

Other related duties as assigned.

About Us

AttainX, Inc. delivers technology solutions, software products, and professional services to Federal Government customers. Our people are central to achieving our customers’ missions. We support quality, collaboration, and employee growth through teamwork and professional development.

Benefits

We are proud to offer competitive compensation and benefits packages, including paid vacation, medical, dental, and vision insurance, a matching 401(k) plan, tuition/training reimbursement, and long- and short-term disability coverage, subject to plan terms and eligibility.

EEO Commitment:

AttainX is an equal employment opportunity employer committed to a workplace free from discrimination. We provide equal opportunity to applicants and employees without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, or any other status protected by applicable law.

Accommodations:

Applicants and employees who need a reasonable accommodation for the application process or to perform essential job functions may contact Human Resources at HR@attainx.com.

Physical Demands:

This position primarily involves computer-based work, reviewing technical materials, and communicating with team members and stakeholders. Essential functions may be performed with or without reasonable accommodation.

Work Environment:

Work is performed primarily at an approved remote work location with reliable connectivity, a secure workspace, and proper protection of Government equipment and sensitive information. Government facility attendance may be required, and remote work is subject to DHS and CISA approval. General work hours are 8:00 a.m. to 5:00 p.m. Eastern Time, Monday through Friday, excluding federal holidays, with core availability from 9:00 a.m. to 3:00 p.m. Office noise is generally moderate. Occasional work outside normal hours, including weekends and holidays, may be required for crisis response or critical IT issues.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

DevSecOps Engineer Related jobs

Other jobs at AttainX, Inc.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.