Mid-Level DevSecOps Engineer

Engineering Contract On-site, Washington, DC

Location

On-site, Washington, DC

Type

Contract

Department

Engineering

XCell was born out of a passion for using the power of design to transform organizations in ways that build up our communities. We work in small, fast-paced agile teams that use Design Thinking to help Government, Non-Profit and Educational organizations solve complex challenges. We value our team and culture — finding the right fit takes time, and we believe in hiring slow.

Citizenship & Eligibility

  • U.S. citizenship is required.
  • Must be U.S.-based and able to work on-site in Washington, DC.
  • Must be able to pass a federal background investigation and suitability determination for access to the customer’s systems and facilities.

What it looks like

We are looking for a Mid-Level DevSecOps Engineer to join a federal engineering team in Washington, DC and help extend its infrastructure automation, CI/CD pipelines, container orchestration, and secure delivery. This is not a build-from-scratch role. You will inherit existing patterns, adhere to the team’s standards, and improve capabilities inside an active production environment. Candidates must be U.S. citizens, U.S.-based, and able to work on-site in DC.

In this role you will:

  • Infrastructure as code: maintain, extend, and refactor Terraform and OpenTofu, including modular configurations, remote state, and workspace management.
  • Configuration as code: develop and maintain Ansible playbooks and roles, using dynamic inventories and Ansible Vault for secrets.
  • CI/CD: build and improve GitHub Actions workflows with security gates, including static analysis, dependency and secrets scanning, and policy-as-code validation.
  • Containers: author and harden Dockerfiles, manage Kubernetes manifests and Helm charts, support namespace and RBAC configuration, and help with cluster health and image scanning.
  • Security integration: embed SAST and DAST scanning in pipelines, enforce CIS benchmarks and customer security baselines, and support NIST and FISMA compliance.
  • Team delivery: work within the team’s version control, change management, and peer-review workflows; participate in stand-ups, sprint planning, and technical reviews; and document your work.

What we are looking for

  • Infrastructure as code: hands-on Terraform and OpenTofu, including module development, remote state, and workspace management.
  • Configuration as code: proficiency with Ansible, including playbook and role development, dynamic inventories, and Ansible Vault.
  • CI/CD: experience designing and maintaining GitHub Actions workflows, including reusable workflows, matrix builds, and security-gate integration.
  • Containers: working knowledge of Docker image authoring and hardening, Kubernetes and Helm, and container scanning tools such as Trivy or Grype.
  • Security integration: familiarity with SAST tools (Semgrep, Checkov, tfsec), secrets scanning (Gitleaks, Detect-Secrets), and policy-as-code (OPA/Rego).
  • Version control: strong Git workflow skills, including branching strategies, pull-request reviews, and protected branches.

Nice-to-have

  • Experience in a federal or highly regulated environment.
  • Familiarity with NIST SP 800-53, FISMA, and FedRAMP compliance.
  • Cloud platform experience (AWS).
  • Experience with secrets management tools such as HashiCorp Vault.
  • Scripting in Python and Bash.

Qualifications / Experience

  • Three or more years of hands-on DevSecOps, platform, or infrastructure engineering.
  • Demonstrated experience across the full toolchain: IaC, CI/CD, containers, and security integration, not just one slice.
  • Experience working inside an established team’s change-control and peer-review process.
  • Strong collaboration and communication skills for an agile, cross-functional team.

What we care about

  • You, the person. Bring your whole, authentic self, not a version you think we want to see.
  • Your passions, professional and personal, even if they have nothing to do with the job.
  • Your honest thoughts on technology, teamwork, and how you approach problems.

Location & On-site Requirement

  • On-site in Washington, DC. This is not a remote role.
  • Applicants must be U.S. citizens, U.S.-based, and able to work on-site in DC.
  • Applicants must live in, or be willing to relocate to, the DC metro area.

Work Authorization

We participate in E-Verify. Upon hire, we provide the federal government with your Form I-9 information to confirm you are authorized to work in the U.S. XCell is a federal contractor, and all positions require work to be performed within the United States.

Benefits

Health Insurance Paid Time Off Flex Schedule Training & Budget Tools
We participate in E-Verify. XCell is a federal contractor; all positions require work to be done within the United States. U.S. Citizenship or Naturalization is required.
Apply

Ready to Join XCell?

Submit your application for Mid-Level DevSecOps Engineer below.