Find The RightJob.
DevSecOps Engineer
Position Summary
Softtek Government Solutions (SGS) is seeking a Mid-Level DevSecOps Engineer to support the Congressional Budget Office (CBO) DevSecOps Engineering Services task order. CBO maintains a hybrid cloud infrastructure environment supported by established DevSecOps practices, security baselines, and federal compliance frameworks; this role augments existing engineering staff to extend and mature CBO's infrastructure automation, CI/CD pipeline capabilities, container orchestration, and security-hardened delivery practices.
The engineer integrates seamlessly with CBO's engineering team, inherits existing patterns and standards rather than designing from scratch, and incrementally enhances capabilities within an active production environment. Work spans Infrastructure as Code (Terraform/OpenTofu), Configuration as Code (Ansible), CI/CD pipeline development (GitHub Actions), container build and orchestration (Docker/Kubernetes), and security integration/compliance hardening — all performed within CBO's established version control, change management, and peer review workflows.
Responsibilities
Maintain, extend, and improve existing Terraform/OpenTofu codebases used to provision and manage cloud and hybrid infrastructure, including modular/reusable configurations, state/remote backend management, plan/apply workflows within change control, and refactoring legacy configurations; do not introduce new tooling without prior CBO IRM approval.
Develop and maintain Ansible playbooks and roles to automate system configuration, compliance enforcement, patch management, and application deployment; adhere to CBO role structure, variable conventions, and inventory management standards.
Build, maintain, and improve GitHub Actions workflows to automate build/test/security scanning/deployment; incorporate security gates including SAST, dependency scanning, secrets detection, and policy-as-code validation; ensure peer review and compliance with CBO branching/approval standards for workflow changes.
Support containerized delivery using Docker for builds and Kubernetes for orchestration, including hardened Dockerfiles, Kubernetes manifests and Helm charts, namespace/RBAC configuration, and cluster health monitoring/troubleshooting; scan container images for vulnerabilities prior to deployment.
Integrate shift-left security across the SDLC, including SAST/DAST integration into pipelines, enforcing CIS benchmarks and CBO baselines for infrastructure/containers, supporting NIST SP 800-53 and FISMA compliance needs, and producing documentation for audits and assessments.
Qualifications
Required Clearance
About Softtek Government Solutions
Softtek Government Solutions is a professional services firm focused on addressing our nation’s most complex threats and challenges. As a small business we’re committed to supporting our clients’ missions with services delivered by our diverse and experienced staff. With expertise in cybersecurity, emergency preparedness, and public health, our experience base spans federal, state, and local governments, as well as private sector entities.
Softtek Government Solutions encourages collaborative communication and ongoing learning. Some of our benefits include:
Softtek Government Solutions is an Equal Opportunity Employer (EOE)
© 2026 Qureos. All rights reserved.