Description
Description
SAIC is seeking a highly skilled and versatile Senior SecDevOps & Systems Engineer with strong full-stack development capabilities to join our IT team. This role unifies three critical functions: secure DevOps automation, end-to-end systems engineering, and hands-on application development. The ideal candidate will lead the design, integration, and secure delivery of complex systems — architecting the infrastructure, building the pipelines that deploy to it, developing applications that run on it, and embedding security at every layer.
This role requires deep expertise spanning software development, IT operations, systems engineering, and security engineering, with the ability to bridge gaps between systems, teams, and processes while serving as a hands-on technical leader.
This position is hybrid-remote and requires 2 days on-site per week in Sterling, VA.
Systems Engineering & Integration Responsibilities:
- Lead the design and implementation of integrated, end-to-end systems solutions spanning infrastructure, platform, and application layers to support enterprise objectives.
- Perform systems requirements analysis, decomposition, and traceability from enterprise objectives to implemented capabilities.
- Define and manage interfaces between subsystems, vendor products, and external systems, including interface control documentation.
- Plan and execute integration, verification, and validation (IV&V) activities to prove systems meet functional, performance, and security requirements.
- Conduct systems analysis, trade studies, and capacity planning to identify opportunities for optimization; document and defend technical decisions in formal reviews.
- Manage and monitor integrated systems to ensure high availability, performance, and security; lead root cause analysis and implement strategic corrective actions.
SecDevOps & Automation Responsibilities:
- Architect, implement, and maintain secure CI/CD pipelines with integrated security gates, including static and dynamic application security testing (SAST/DAST), software composition analysis (SCA), container scanning, and secrets management.
- Develop and maintain robust automation workflows for software build, test, security validation, and deployment processes.
- Implement infrastructure as code (IaC) with embedded security policy enforcement (policy-as-code) for cloud and hybrid environments.
- Harden operating systems, containers, and platforms to applicable security baselines (e.g., DISA STIGs, CIS Benchmarks) and automate compliance verification.
- Support security authorization activities, including RMF/ATO documentation, vulnerability management, remediation tracking, and audit evidence generation.
- Ensure systems integration and delivery align with industry best practices and applicable compliance and security standards.
- Provide expert guidance on SecDevOps tools and practices, facilitating knowledge sharing and maturing the organization's SecDevOps culture.
Full Stack Development Responsibilities:
- Design, develop, and maintain full-stack applications, including responsive front-end interfaces, back-end services and APIs, and supporting data layers.
- Build and integrate RESTful and/or event-driven APIs between internal systems, vendor products, and external services.
- Apply secure coding practices (e.g., OWASP Top 10 mitigation) and participate in code reviews with a security-first mindset.
- Develop internal tooling, dashboards, and automation utilities that enhance operational visibility and team efficiency.
- Collaborate with development, operations, security, and other IT teams to ensure seamless, high-quality, secure software delivery.
Leadership Responsibilities:
- Lead projects from concept through deployment and sustainment, participating in formal technical and design reviews.
- Mentor junior engineers and developers across DevOps, systems, and software disciplines.
- Stay current with emerging technologies in systems integration, SecDevOps, and application development, recommending adoption where beneficial.
Qualifications
Required Skills and Qualifications
- Strong expertise in DevOps/SecDevOps methodologies and tools (e.g., Jenkins, GitLab CI, Git, Ansible, Docker, Kubernetes).
- Demonstrated experience integrating security into CI/CD pipelines (SAST, DAST, SCA, container scanning, secrets management).
- Proficiency in scripting languages (e.g., Python, Bash, PowerShell) for automation tasks.
- Full-stack development proficiency, including a modern front-end framework (e.g., React, Angular, or Vue), a back-end language/framework (e.g., Node.js/TypeScript, Python, Java, or .NET), and relational and/or NoSQL databases.
- Experience designing, building, and consuming RESTful APIs.
- Experience with cloud services (AWS, Azure, Google Cloud), their management APIs, and cloud security services (e.g., IAM, key management, network security controls).
- Systems engineering experience, including requirements analysis, systems integration, interface management, and verification and validation.
- Experience with Linux and/or Windows server engineering, virtualization, and network fundamentals in enterprise or hybrid environments.
- Knowledge of security hardening baselines (DISA STIGs, CIS Benchmarks) and vulnerability management practices.
- Excellent problem-solving skills and the ability to work in a dynamic, fast-paced environment.
- Strong communication and collaboration skills to work effectively across teams.
- Proven ability to lead projects and mentor junior team members.
Preferred Skills and Qualifications
- Certifications in security, DevOps, or cloud computing (e.g., CISSP, Security+, CKA/CKS, AWS Certified DevOps Engineer, AWS Certified Security – Specialty).
- Experience with infrastructure as code using Terraform or CloudFormation, and policy-as-code tools (e.g., OPA, Sentinel).
- Experience supporting RMF/ATO processes, NIST SP 800-53 controls, or FedRAMP environments.
- Understanding of microservices architecture, container orchestration at scale, and API gateway patterns.
- Experience with model-based systems engineering (MBSE) or formal requirements management tools (e.g., DOORS, Jama).
- Experience with observability and monitoring stacks (e.g., Prometheus, Grafana, ELK, Splunk).
- Active security clearance or the ability to obtain one.
Education and Experience
- Bachelor's degree in Computer Science, Information Technology, Computer Engineering, or a related field and seven (7) or more years of related experience spanning systems integration, DevOps/SecDevOps automation, and software development; or
- Master's degree and five (5) or more years of related experience; or
- PhD and three (3) or more years of related experience.
BI Requirement
- Current holder of a DHS Public Trust clearance or the ability to obtain one.
- Note: Employment will be contingent upon having/obtaining a DHS Public Trust clearance prior to starting.
Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.
Apply on company website