Senior DevSecOps Engineer

Coforma • United State
Remote
Apply
AI Summary

Join Coforma's distributed team as a Senior DevSecOps Engineer to deliver secure products across a modern technology stack. Collaborate with cross-disciplinary teams to tackle complex problems and improve lives through digital products and services.

Key Highlights
Implement and maintain Risk Management Framework (RMF) security controls
Manage containerized infrastructure and administer AWS cloud resources
Collaborate with team members and stakeholders to craft creative solutions
Technical Skills Required
Linux Windows Docker Kubernetes AWS Terraform Serverless Amazon CDK GitHub Actions Jenkins Circle Postgres SQL Dynamo Mongo Datadog Splunk SonarQube NewRelic Nessus STIGs RMF
Benefits & Perks
$147,290 to $165,830 Annual Salary
Benefits
Growth Potential
Remote Work
Flexible Travel

Job Description


Application Deadline: 15 December 2025

Department: Engineering

Location: Remote (select US states)

Compensation: $147,290 - $165,830 / year

Description

We are looking for a thoughtful, collaborative Senior DevSecOps Engineer to join our growing, distributed team at Coforma.

Our DevSecOps Engineers enjoy tackling complex problems while working with other members of our cross-disciplinary teams to deliver elegant, secure products across a modern technology stack. They are skilled experts across the stack, particularly with expertise in managing and securing Linux and Windows server environments and building accessible applications that put people first.

In this role, you'll work closely with researchers, designers, and your counterparts on the Engineering team early and often, collaborating to add perspective that increases understanding and empathy. As such, your passion for articulating technology solutions that aim to improve lives is a feature, not a bug. The ideal candidate will have experience in system administration, containerized infrastructure, cloud technologies, STIGs, and compliance with federal security standards. This role also involves working in AWS environments and ensuring systems meet Risk Management Framework (RMF) requirements.

Join us to build software that makes an impact and implement human-centered solutions that we can be proud to say we worked on together. If you’re passionate about improving lives through digital products and services, Coforma is a great company for you.

$147,290 to $165,830 Annual Salary + Benefits + Growth Potential
Placement within this range will be based on the competency level of the candidate. An offer will be made at one of the following tiers:
  • Tier 1 - $147,290: Meets minimum qualification/experience requirements. Beyond onboarding, will need additional guidance and training to perform key responsibilities of the role.
  • Tier 2 - $156,560: Experienced and fully competent. Will be able to independently perform key responsibilities of the role once onboarding is completed.
  • Tier 3 - $165,830: Highly experienced and can perform all responsibilities of the role at a higher level than expected once onboarding is completed.
To honor our company-wide equitable pay system, the posted salary range and corresponding tier salaries are non-negotiable.

This is a US-based remote position open to applicants in the states listed below. Some travel may be required.


To ensure we remain compliant with all state, county, and local employment and tax regulations, applicants must currently reside in one of the following states to be considered for employment with Coforma. This list will be updated periodically as our People team works to open up hiring in additional states.
  • Arizona
  • California
  • District of Columbia
  • Florida
  • Georgia
  • Idaho
  • Illinois
  • Maine
  • Maryland
  • Massachusetts
  • Montana
  • Nevada
  • New Jersey
  • New York
  • North Carolina
  • Oregon
  • South Carolina
  • Tennessee
  • Texas
  • Virginia
  • Washington
  • Wisconsin

What You’ll Do (Key Responsibilities)

  • Implement and maintain Risk Management Framework (RMF) security controls and ensure compliance with federal security and operational standards
  • Perform security configuration, patching, and ongoing maintenance of Linux and Windows server environments
  • Manage containerized infrastructure (e.g., Docker, Kubernetes) and administer/optimize AWS cloud resources
  • Consistently apply best practices, including a focus on accessibility
  • Solve problems across the tech stack alongside other engineers on the team, building new systems and improving existing ones
  • Lead other developers through ideation and articulation of solutions with an eye toward integration and reducing burden and tech debt
  • Collaborate with team members and government/client stakeholders to craft creative solutions and build technology products that improve the lives of those in the communities they serve
  • Articulate benefits and risks associated with different technical approaches

Who You Are and What You Know (Knowledge and Experience Requirements)

  • How to leverage the command line via shell scripting
  • APIs and databases of various types (SQL, Dynamo, Mongo, Postgres, etc.)
  • Infrastructure tools (Terraform, Serverless, Amazon CDK, etc.)
  • Container orchestration and management tools such as Docker or Kubernetes
  • CI/CD tools (GitHub Actions, Jenkins, Circle, etc.)
  • Cloud platforms such as AWS, Azure, and GCP
  • Observability and monitoring tools (Datadog, Splunk, SonarQube, NewRelic, Nessus, etc.)
  • Security best practices like vulnerability scanning and remediation, threat modeling and detection, and static and dynamic testing including system hardening guides (STIGs) and RMF principles
  • System administration and hardening experience in Linux and Windows server environments
  • How to communicate complex technical concepts to non-technical audiences
Preferred Qualifications and Experience:
  • 5+ years of experience working with APIs and databases of various types
  • 5+ years of experience working with infrastructure tools and IAC
  • 5+ years of experience working with CI/CD and pipeline tools
  • 5+ years of experience working with cloud platforms
  • 5+ years of experience with observability and monitoring tools
  • 5+ years of experience supporting and implementing security best practices
  • Experience implementing and maintaining RMF and compliance with federal security standards
  • Experience developing software in a remote environment
  • Experience in digital services, government, or federal consulting

Other

  • Internet: Will prioritize and maintain access to strong, reliable internet for the remote nature of our work, except when on vacation or holiday.
  • Security: Will keep the highest security practices to ensure privacy and security of Coforma and client information, given the nature of our work, even when on vacation.
  • Travel Flexibility: On request and with advanced notice, will attend in-person events such as meetings, workshops, and trainings as assigned for projects that require it.
  • Brand Representation: Will represent Coforma professionally and sincerely, modeling our Company Values in all interactions.

Subscribe our newsletter

New Things Will Always Update Regularly