AttainX,Inc logo

DevSecOps Engineer II

AttainX,Inc

RemoteseniorPosted 11h ago

Visa & sponsorship

  • US citizenship required. In the US that usually comes with federal, defense or clearance-related work — a legal requirement, not employer policy. Not open to non-citizens.
  • A US security clearance is required, which effectively means citizens only.

Job description

** Job Title: ** DevSecOps Engineer II

** Location: ** Remote/Hybrid - DHS CISA; approved remote work location within the 50 United States or the District of Columbia. Government facility attendance may be required.

** Work Schedule: ** Monday through Friday, 8:00 a.m. to 5:00 p.m. Eastern Time; core availability 9:00 a.m. to 3:00 p.m., excluding federal holidays.

** Security Requirements: ** Must obtain and maintain a favorable DHS/CISA Entry on Duty or fitness determination and complete the background investigation appropriate to the position’s sensitivity and required access.

** Work Authorization: ** Must be authorized to work in the United States and meet DHS/CISA personnel and system access requirements.

AttainX is seeking a DevSecOps Engineer II to integrate security practices throughout the DevOps lifecycle for CISA’s DocuSign implementation and integrations, ensuring secure deployment of high-quality IT infrastructure. This role works independently and collaboratively, contributes to moderately complex project activities, and applies secure automation, Infrastructure as Code, and continuous integration and deployment practices.

** Qualifications and Education Requirements: **

  • 3-5 years of related experience in DevSecOps, software engineering, infrastructure automation, or security engineering.

  • A bachelor’s degree in computer science, cybersecurity, information systems, engineering, or a related field.

  • Proficiency with CI/CD tools such as Jenkins, GitLab, or Azure DevOps, including pipeline automation, version control, Infrastructure as Code, and controlled deployments.

  • Experience with static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), vulnerability scanning, and penetration testing frameworks.

  • Experience programming or scripting in one or more languages such as Python, Perl, Bash, PHP, PowerShell, Java, SQL, or C++.

  • Knowledge of security principles, practices, and technologies, including encryption, authentication, authorization, network security, and secure handling of credentials and secrets.

  • Experience with REST APIs, connectors, webhooks, SaaS integrations, and Microsoft 365 or enterprise identity platforms; DocuSign integration experience is preferred.

  • Experience supporting lifecycle testing, technical documentation, Federal security requirements, and Section 508 accessibility compliance.

  • Ability to work independently and collaborate with architects, developers, security engineers, and stakeholders on moderately complex project activities.

  • A current Microsoft Certified: DevOps Engineer Expert or AWS Certified DevOps Engineer - Professional certification is highly preferred.

  • Must be a US Citizen able to obtain a DHS CISA Public Trust clearance.

** Job Duties: **

  • Integrate security practices throughout the development, testing, deployment, and operation of DocuSign integrations and supporting infrastructure.

  • Design, implement, and maintain security controls across CI/CD pipelines; automate SAST, DAST, SCA, and other security checks to identify risks before deployment.

  • Perform regular security assessments, vulnerability scanning, and authorized penetration testing within approved scope; prioritize findings and coordinate remediation with development and security teams.

  • Implement Infrastructure as Code, automated testing, and controlled release and rollback procedures to support secure, reliable delivery.

  • Configure and maintain DocuSign accounts, groups, templates, routing rules, administrative settings, policies, alerts, and approved branding.

  • Build and maintain plugins, connectors, and custom APIs for automated envelope creation, routing, and archival; integrate DocuSign with Microsoft 365, enterprise identity systems, and contract or case platforms.

  • Implement encryption, secure authentication, authorization, role-based access, network and boundary protection, and secure credential handling; monitor logs and systems for threats and escalate findings.

  • Develop, maintain, and enforce security policies and procedures aligned with Federal, DHS, and CISA requirements and approved development and deployment practices.

  • Execute developmental and operational tests; document defects, security findings, remediation, test results, and deployment readiness.

  • Automate document conversion and records capture while preserving NARA-compliant formats, metadata consistency, and disposition requirements.

  • Document configurations, deployment procedures, integration architecture, and exception handling; support secure releases and knowledge transfer to system administrators.

  • Stay current with security trends, tools, and technologies; proactively recommend and implement approved improvements to pipeline security, automation, and threat monitoring.

** Non-Essential Functions: **

Other related duties as assigned.

** About Us **

AttainX, Inc. delivers technology solutions, software products, and professional services to Federal Government customers. Our people are central to achieving our customers’ missions. We support quality, collaboration, and employee growth through teamwork and professional development.

** Benefits **

We are proud to offer competitive compensation and benefits packages, including paid vacation, medical, dental, and vision insurance, a matching 401(k) plan, tuition/training reimbursement, and long- and short-term disability coverage, subject to plan terms and eligibility.

** EEO Commitment: **

AttainX is an equal employment opportunity employer committed to a workplace free from discrimination. We provide equal opportunity to applicants and employees without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, or any other status protected by applicable law.

** Accommodations: **

Applicants and employees who need a reasonable accommodation for the application process or to perform essential job functions may contact Human Resources at HR@attainx.com.

** Physical Demands: **

This position primarily involves computer-based work, reviewing technical materials, and communicating with team members and stakeholders. Essential functions may be performed with or without reasonable accommodation.

** Work Environment: **

Work is performed primarily at an approved remote work location with reliable connectivity, a secure workspace, and proper protection of Government equipment and sensitive information. Government facility attendance may be required, and remote work is subject to DHS and CISA approval. General work hours are 8:00 a.m. to 5:00 p.m. Eastern Time, Monday through Friday, excluding federal holidays, with core availability from 9:00 a.m. to 3:00 p.m. Office noise is generally moderate. Occasional work outside normal hours, including weekends and holidays, may be required for crisis response or critical IT issues.