We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

SeniorDevSecOpsEngineer

Pantheon Data
tuition assistance
United States, Virginia, Reston
12001 Sunrise Valley Drive (Show on map)
Aug 27, 2026

Company Overview

Pantheon Data (a Kenific Holding company) is a private, small business based in the Washington, DC, area. Pantheon Data was founded in 2011, initially providing acquisition and supply chain management services to the US Coast Guard. Our service offerings have grown in the past ten years, including infrastructure resiliency, contact center operations, information technology, software engineering, program management, strategic communications, engineering, and cybersecurity. We have also grown our customer base to include commercial clients. The company has used this experience to expand our service offerings to other agencies within the Department of Homeland Security (DHS), the Department of Defense (DoD), and other Federal Civilian Agencies.

Position Overview

Pantheon Data is seeking a SeniorDevSecOps Engineer to design, build, andoperatesecure, cloud-native platforms in AWS GovCloud supporting ML-enabled workloads and applications that process CUI, PII, and PHI. GitLab Ultimate is ourDevSecOpsplatform: youwill own our GitLab CI/CD architecture end to end - pipelines, runners, security scanning, policy enforcement, and compliance evidence - and lead the migration of existing repositories and pipelines onto it.

The role combines secure pipeline engineering with platform operations: hardened infrastructure as code, production Amazon EKS administered throughGitOps, and gated security controls that satisfy NIST 800-53, FedRAMP, and DoD SRG requirements while keeping delivery fast. Successful candidates can walk through pipelines and platforms they have personally built - stage design, security gates, runner architecture, failure modes, and the compliance evidence they produced.

Responsibilities



  • GitLab CI/CD Engineering:Design, implement, andoperateenterprise-grade GitLab CI/CD pipelines, including multi-project/parent-child pipeline orchestration, environment promotion gates, protected branches and environments, and reusable pipeline templates and CI components.
  • GitLab Ultimate Security Suite:Deploy, configure, and tune the full GitLab Ultimate security suite as required pipeline gates: Advanced SAST, DAST, secret detection (including push protection), dependency scanning, container scanning,IaCscanning, license compliance, and API security - with findings triaged through the vulnerability management dashboard and merge request security widgets.
  • Policy-as-Code & Compliance Automation:Enforce security centrally using scan execution policies, merge request approval policies, compliance frameworks, and compliance pipelines so scanning is mandatory across all projects; maintain audit events and evidence packages that support ATO, POA&M, and continuous-monitoring activities.
  • Software Supply Chain Security:Generate and manage SBOMs (CycloneDX), enforce dependency and license policies, sign and verify build artifacts and container images, andmaintaina secure, traceable path from commit to production.
  • Runners & Cloud Auth:Architect and operate GitLab Runner fleets in GovCloud (autoscaling, isolation, hardened images) and implement keyless OIDC authentication from GitLab to AWS IAM roles - no long-lived cloud credentials in CI.
  • Secure Infrastructure:Design andmaintainhardened AWS GovCloud environments with Terraform (modular design, remote state, multi-repo dependency ordering), aligned to NIST 800-53 and FedRAMP High baselines and DISA STIG/CIS benchmarks.
  • Kubernetes &GitOps:Manage lifecycle, networking, and security for production Amazon EKS clusters; orchestrate deployments with Helm andGitOpstooling (Argo CD or Flux) for declarative state management; harden clusters, registries, and OCI image workflows.
  • ML Workload Support:Deploy and scale containerized ML models and data pipelines; build observability (metrics, logging, alerting, tracing) for regulated, restricted-egress environments.
  • Platform Migration:Lead the migration of repositories, pipelines, and integrations from GitHub/GitHub Actions to GitLab, including translation of workflows, secrets strategy, branch protection parity, and developer enablement.
  • Team Enablement:Mentor engineers on secure delivery practices, author runbooks and pipeline documentation, and partner with security and compliance teams on control implementation and assessment support.


Required Skills and Experience



  • Bachelor's degree in Computer Science, Information Technology, Information Systems, Engineering, or a related technical field,froman ABETaccredited university.
  • 5+ years inDevSecOps/DevOps engineering with responsibility forproductionAWS environments.Plusanadditional5 years of experience in arelatedtechnical field.
  • Deep, hands-on GitLabexpertise: GitLab CI/CD pipeline design at scale, GitLab Ultimatesecurityand compliance features (SAST/DAST/secret detection/dependency/container/IaCscanning, scan execution and approval policies, security dashboards), and GitLab Runner administration.
  • Experience implementing gatedDevSecOpscontrols in CI/CD - pipelines thatblock onsecurity findings, enforce approvals, and produce auditable evidence.
  • Deep hands-onexpertisewith Amazon EKS: cluster hardening, OCI-compliant image management, Helm, andGitOpsdeployment patterns (Argo CD or Flux).
  • Proficiencyin Terraform for complex networking and security stacks: modular design, state management, and multi-environment promotion.
  • Practical understanding of NIST SP 800-53, FedRAMP, and DoD RMF/SRG, and their application to technical configurations in AWS GovCloud (STIGs, CIS benchmarks, boundary controls, audit logging).
  • Scriptingproficiencyin Python or Bash for operational automation and security tooling.
  • Current AWS Certified DevOps Engineer - Professional or AWS Certified Security - Specialty.
  • Ability to work effectively in remote, cross-functional teams; meet deadlines; and produce quality work with clear written communication.
  • Proficient in Microsoft Suite software including Outlook, Word, Excel, SharePoint, and PowerPoint.


Preferred Skills and Experience



  • Experience administering self-managed GitLab (or GitLab Dedicated for Government) in GovCloud or another isolated/restricted-egress environment, including upgrades, backups, and instance hardening.
  • Experience migrating organizations from GitHub/GitHub Actions (including GitHub Advanced Security) to GitLab Ultimate.
  • Experience supporting FedRAMP High or DoD IL4/IL5 ATO efforts: control implementation statements, POA&M management, continuous monitoring, and assessor engagement.
  • Supply-chain security depth: SLSA,Sigstore/cosign artifact signing, SBOM management, and dependency provenance.
  • Experience supporting ML/AI platforms (model serving, GPU workloads, Amazon Bedrock integrations, or data pipelines) in regulated environments.
  • Secrets management with AWS KMS, Secrets Manager, orHashiCorpVault; policy-as-code tools such as OPA/Kyverno; and admission control for Kubernetes.
  • Additional AWS certifications such as Solutions Architect orSysOpsAdministrator; Kubernetes certifications (CKA/CKS).


Clearance Requirements

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements. Secret Clearance is required for continued employment.

Work Location: Reston, VA - Hybrid



  • Our company prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
  • If the position is remote or hybrid, you may periodically work from a Pantheon Data office location or client site.
  • If this position is assigned to a Pantheon Data office location or client site, you'll work with colleagues and clients in person, as needed for specific client requirements.


Interview Requirement: Candidates who are local to the area should be prepared to participate in an in-person interview as part of the selection process. Candidates outside the local area may be considered for a virtual interview.

Compensation

The salary range for this position is $140,000 - $200,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Benefits Overview

We are always looking for good people! Pantheon Data is committed to providing its employees with competitive salaries and benefits in order to increase employee satisfaction and productivity.In addition to our benefits, we also offer SmartBenefits through the Washington Metro Area Transportation Authority, where you specify an amount of your pre-tax wages be paid directly to your SmarTrip account. In some cases, tuition assistance may be available for continuing education expenses and certifications related to their position. Additional details may be found at https://pantheon-data.com/careers/

Pantheon Data Important Information

All qualified applicants will be considered for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our Talent Team at Recruiting@pantheon-data.com or by phone (571) 363-4020.

This company uses E-Verify to confirm each employee's work authorization. For more information, click here E-Verify Participation Poster


Applied = 0

(web-665cd84569-66c2c)