On-site, Washington, DC
Contract
Engineering
XCell was born out of a passion for using the power of design to transform organizations in ways that build up our communities. We work in small, fast-paced agile teams that use Design Thinking to help Government, Non-Profit and Educational organizations solve complex challenges. We value our team and culture — finding the right fit takes time, and we believe in hiring slow.
Citizenship & Eligibility
- U.S. citizenship is required.
- Must be U.S.-based and able to work on-site in Washington, DC.
- Must be able to pass a federal background investigation and suitability determination for access to the customer’s systems and facilities.
What it looks like
We are looking for a Mid-Level DevSecOps Engineer to join a federal engineering team in Washington, DC and help extend its infrastructure automation, CI/CD pipelines, container orchestration, and secure delivery. This is not a build-from-scratch role. You will inherit existing patterns, adhere to the team’s standards, and improve capabilities inside an active production environment. Candidates must be U.S. citizens, U.S.-based, and able to work on-site in DC.
In this role you will:
- Infrastructure as code: maintain, extend, and refactor Terraform and OpenTofu, including modular configurations, remote state, and workspace management.
- Configuration as code: develop and maintain Ansible playbooks and roles, using dynamic inventories and Ansible Vault for secrets.
- CI/CD: build and improve GitHub Actions workflows with security gates, including static analysis, dependency and secrets scanning, and policy-as-code validation.
- Containers: author and harden Dockerfiles, manage Kubernetes manifests and Helm charts, support namespace and RBAC configuration, and help with cluster health and image scanning.
- Security integration: embed SAST and DAST scanning in pipelines, enforce CIS benchmarks and customer security baselines, and support NIST and FISMA compliance.
- Team delivery: work within the team’s version control, change management, and peer-review workflows; participate in stand-ups, sprint planning, and technical reviews; and document your work.
What we are looking for
- Infrastructure as code: hands-on Terraform and OpenTofu, including module development, remote state, and workspace management.
- Configuration as code: proficiency with Ansible, including playbook and role development, dynamic inventories, and Ansible Vault.
- CI/CD: experience designing and maintaining GitHub Actions workflows, including reusable workflows, matrix builds, and security-gate integration.
- Containers: working knowledge of Docker image authoring and hardening, Kubernetes and Helm, and container scanning tools such as Trivy or Grype.
- Security integration: familiarity with SAST tools (Semgrep, Checkov, tfsec), secrets scanning (Gitleaks, Detect-Secrets), and policy-as-code (OPA/Rego).
- Version control: strong Git workflow skills, including branching strategies, pull-request reviews, and protected branches.
Nice-to-have
- Experience in a federal or highly regulated environment.
- Familiarity with NIST SP 800-53, FISMA, and FedRAMP compliance.
- Cloud platform experience (AWS).
- Experience with secrets management tools such as HashiCorp Vault.
- Scripting in Python and Bash.
Qualifications / Experience
- Three or more years of hands-on DevSecOps, platform, or infrastructure engineering.
- Demonstrated experience across the full toolchain: IaC, CI/CD, containers, and security integration, not just one slice.
- Experience working inside an established team’s change-control and peer-review process.
- Strong collaboration and communication skills for an agile, cross-functional team.
What we care about
- You, the person. Bring your whole, authentic self, not a version you think we want to see.
- Your passions, professional and personal, even if they have nothing to do with the job.
- Your honest thoughts on technology, teamwork, and how you approach problems.
Location & On-site Requirement
- On-site in Washington, DC. This is not a remote role.
- Applicants must be U.S. citizens, U.S.-based, and able to work on-site in DC.
- Applicants must live in, or be willing to relocate to, the DC metro area.
Work Authorization
We participate in E-Verify. Upon hire, we provide the federal government with your Form I-9 information to confirm you are authorized to work in the U.S. XCell is a federal contractor, and all positions require work to be performed within the United States.
Benefits
Ready to Join XCell?
Submit your application for Mid-Level DevSecOps Engineer below.