ISTI is hiring a Senior DevSecOps Engineer to help our team secure, build, deploy, and operate the SPIDOR platform and its dependent services.
This is a hands-on engineering role on a small, tight-knit team — you’ll maintain GitLab CI/CD pipelines, harden containerized workloads in AWS, drive the monthly vulnerability scanning and remediation cycle, and help us meet the compliance bar required for DoD environments (FIPS 140-2, DISA STIG).
The most important thing we’re looking for isn’t a specific tool on a résumé. It’s someone who works well with others, brings a can-do attitude, and is genuinely willing to dig in and learn when they hit something they haven’t seen before. DevSecOps at AFTAC moves across a wide surface area — cloud, containers, pipelines, databases, security tooling, compliance — and nobody walks in knowing all of it. We want someone who treats “I haven’t done that yet” as the start of a good investigation, not a blocker.
WHAT YOU WILL BE DOING:
- Partnering every day with application developers, program managers, designers, and customer-side security reviewers — the job only works if the team is moving together.
- Pairing with teammates on tricky problems, reviewing each other’s pipeline and infrastructure changes, and share what you learn so the whole team levels up.
- Communicating clearly in tickets, pull requests, and stand-ups: flag blockers early, asking for help before you’re stuck for a day, and offering help when you see someone else spinning.
- When something new lands on the team — a tool, a compliance requirement, a customer ask — being one of the people who volunteers to go learn it and bring it back to the group.
- Owning and extending GitLab CI/CD pipelines for SPIDOR and its dependent software projects — build, test, scan, package, and publish.
- Integrating security gates directly into pipelines: Fortify (SAST), OWASP ZAP (DAST), Snyk (SCA), Twistlock (container scanning), and SBOM generation.
- Managing GitLab runners, optimize build performance, debug pipeline failures, and keep the pipeline reliable enough that developers trust it and use it.
- Building, tagging, and publishing runtime container images to AFTAC’s Harbor registry; coordinating image promotion across development, test, and production tiers.
- Deploying and operating containerized workloads on AWS ECS and EC2; managing supporting services (RDS/Oracle, EFS, VPC, S3, load balancers).
- Maintaining and extending Infrastructure-as-Code in Terraform; prototyping Helm charts and evaluating Kubernetes/Istio options for future orchestration — and bringing the team along on those decisions.
- Troubleshooting runtime issues in ECS (container exits, authz failures, resource pressure); instrument health checks and run load tests before major releases.
- Provisioning and decommissioning AWS resources deliberately, with an eye on cost and configuration drift.
- Running the monthly Fortify cycle and quarterly scanning campaigns across every dependent software project; aggregating findings, triaging by severity, and driving closure together with the developers who own the code.
- Generating vulnerability reports and SBOM artifacts for each project as part of the standard release deliverable package.
- When a scanner flags something you don’t fully understand yet, figuring it out — reading the CVE, reproducing the finding, talking to the developer, and coming back with a clear recommendation.
- Deploying SPIDOR onto FIPS 140-2 validated, DISA STIG-hardened Red Hat servers; validating compliance posture before delivery.
- Owning TLS, certificate, and PKI configuration across services; handling credentials and secrets through an approved secret-management pattern (e.g., HashiCorp Vault).
- Authoring and maintaining authentication/authorization architecture diagrams aligned to DoD requirements; walkiing the team and customer reviewers through them.
- Designing PostgreSQL schemas in AWS RDS, writing and validating migration scripts, and coordinating schema rollouts with application releases — pairing with the app team, don’t design in a vacuum.
- Running the release process together with the team: version numbering, changelogs, submodule coordination, packaging, and customer delivery for phased releases.
- Keeping system-interaction documentation, READMEs, and architecture diagrams current — the team and our customers rely on them.
REQUIRED EXPERIENCE
- U.S. citizen with Public Trust certification, able to obtain and maintain the clearance required for DoD-adjacent work.
- 3–10 years of hands-on DevSecOps, site reliability, or platform engineering experience, including at least 1 year in a security-integrated delivery role.
- Production experience with AWS ECS, EC2, RDS, VPC, S3, IAM, and EFS. You’ve deployed real workloads, not just labs.
- Strong Docker container fundamentals, image build/promotion workflows, and registry operations (Harbor, ECR, or equivalent).
- Deep, practical GitLab CI/CD experience — writing pipelines, managing runners, and integrating third-party scanners.
- Production Terraform IAC working knowledge of Helm and at least exposure to Kubernetes.
- Hands-on experience with several of security tools— Fortify, OWASP ZAP, Snyk, Twistlock/Prisma Cloud, or equivalents — including acting on the output, not just running the scans. If you’ve used two and are willing to learn the rest, we want to talk.
- PostgreSQL schema database design and migration script authoring in a team setting.
- Fluent in Python and Bash scripting; comfortable reading Java, Node.js, or similar application code well enough to diagnose build and dependency issues.
- Direct experience with FIPS 140-2, DISA STIG, CIS Benchmarks, or an equivalent regulated framework (FedRAMP, SOC 2, HIPAA). If you haven’t worked in FIPS/STIG specifically but you’ve navigated a real compliance regime, that counts.
- ITS A PLUS IF YOU HAVE THIS
- Prior work delivering software into DoD or Intelligence Community customer environments.
- Experience with Istio service mesh, or migrating workloads from ECS to Kubernetes/EKS.
- Observability stack familiarity (Prometheus, Grafana) and production load-testing experience.
- Ansible or Packer for image baking and configuration management.
- Experience with Oracle and Postgres databases
- A habit of writing things down for the next person — clear READMEs, architecture diagrams, runbooks.
HOW YOU WILL WORK:
- Small team, real mission. You’ll work alongside application engineers, program management, and customer-side reviewers on roughly 60–100 tickets a year spanning scanning, CI/CD, deployment, container lifecycle, and release engineering.
- Monthly scanning cadences and quarterly phased releases are the heartbeat of the role. Most work is well-scoped and medium-priority — the bar is steady throughput, good judgment, and good teamwork, not heroics.
- You’ll own tickets end-to-end, but you will not be working in isolation. Expect regular pairing, code review, and design conversations.
- When we don’t know how to do something yet — and that happens often — we go figure it out together. Bring curiosity.
WHAT'S IN IT FOR YOU
- SPIDOR is a real mission-facing system with real compliance obligations and a real customer.
- The work is technical, concrete, and visible: the pipelines you build, the images you ship, and the scans you drive to closure are the product.
- It’s a team you’ll actually enjoy working with — people who care about the work, care about each other, and are happy to learn something new on a Wednesday.
ABOUT ISTI
ISTI's mission is to merge innovative software engineering with cutting-edge scientific research to become the premier provider of monitoring and scientific software solutions vital to the world’s safety. Known for its experience in earthquake, tsunami, volcano monitoring, early warning systems , nuclear test and proliferation analysis; ISTI is an international company whose clients include some of the largest research institutions, government organizations, and companies in the world.
We are an EEOC employer that doesn't discriminate based on race, religion, national origin, gender, age, or marital, veteran, or disability status.