Sr. DevSecOps Engineer

Bowhead / UIC Technical Services

San Diego, CA

JOB DETAILS
SKILLS
Access Control, Acquisitions Management, Artificial Intelligence (AI), Automation, Bash Scripting, Benchmarking, Clinical Support, Communication Skills, Continuous Deployment/Delivery, Continuous Integration, Defense Information Systems Agency (DISA), Documentation, GitHub, Healthcare, Internet Security, JSON, Jenkins, Leadership, Lift/Move 20 Pounds, Linux Operating System, Medical Treatment, Mentoring, Microsoft Windows Azure, Military, Military/DoD Standards, Operational Audit, Operational Support, Python Programming/Scripting Language, Sales Pipeline, Scripting (Scripting Languages), Security Clearance, Security Information and Event Management (SIEM), Security Infrastructure, Software Engineering, Splunk, System Integration (SI), Technical Leadership, Technical Support, Test Plan/Schedule, U.S. National Institute of Standards and Technology (NIST), Ubuntu, United States Citizen, United States Department of Defense (DoD), VMS Operating System, Virtual Machine (VM)
LOCATION
San Diego, CA
POSTED
30+ days ago

Overview

SR. DEVSECOPS ENGINEER (PACMED):

Bowhead seeks a Sr. DevSecOps Engineer to support in operational systems integration, development, test, evaluation, operation, sustainment, and maintenance using technologies and acquisition management to support technical, ancillary, and clinical support to military medical treatment facilities in the pacific Region. This position will support building a next-generation automated compliance and AI-driven security operations platform supporting DoD, federal health, and enterprise health-care environments. The Sr. DevSecOps Engineer will provide deep experience in DISA STIGs, SCAP automation, RMF workflows, container security, SIEM/SOAR integrations, and AI-assisted security operations.

Responsibilities

SCAP / STIG Automation

  • Build automated OpenSCAP pipelines to scan Ubuntu 24.04 LTS and other Linux hosts using DISA STIG benchmarks.
  • Integrate XCCDF and OVAL results into OpenRMF using automated ingestion workflows.
  • Develop hardened base images (VMs and containers) aligned to DISA STIG requirements.

Container Security

  • Integrate RapidFort scans into CI/CD pipelines.
  • Automate ingestion of SCAP JSON into OpenRMF.
  • Ensure curated images remain compliant and low-CVE.

Compliance Operations (RMF/FedRAMP/CMMC)

  • Support generation of automated DISA checklists (CKLs) and POA&M updates.
  • Work with compliance and engineering teams to resolve findings and track remediation progress via OpenRMF.

Security Telemetry & SIEM Engineering

  • Deploy/tune Wazuh agents across hosts and workloads.
  • Configure pipelines from Wazuh → Elastic → Tines.
  • Write and maintain Elastic SIEM detection rules.

SOAR Automation & AI SOC Buildout

  • Develop Tines workflows to automate:
    • SCAP ingestion
    • RapidFort event processing
    • Elastic SIEM alert enrichment
    • Compliance notifications & ticketing
  • Integrate LLMs to:
    • Summarize alerts
    • Draft POA&M entries
    • Generate remediation guidance
    • Produce daily/weekly SOC and compliance reports

Infrastructure & DevSecOps

  • Contribute to secure CI/CD pipelines, secrets management, system hardening, logging, and access control aligned with DoD RMF.

Qualifications

Must-Have Technical Expertise

  • Five to ten (10+) years Linux engineering with security hardening focus
  • Hands-on experience with OpenSCAP, DISA STIGs, SCAP benchmarks, and STIG automation
  • Experience working with OpenRMF (or similar RMF automation platforms)
  • Strong knowledge of RMF, FedRAMP, or CMMC
  • CI/CD pipeline experience (GitLab CI, GitHub Actions, Jenkins, etc.)
  • Hands-on experience with Elastic Stack and Wazuh
  • Experience deploying or integrating SOAR platforms (Tines preferred; XSOAR or Splunk SOAR acceptable)
  • Container security experience (RapidFort, Anchore, Trivy, Aqua, etc.)

Bonus Skills

  • Familiarity with ATO workflows (IL4/IL5, DoD impact levels)
  • AI integration experience using OpenAI, Azure OpenAI, or similar
  • Python or Bash scripting for automation
  • Experience with NIST 800-53, CNSSI 1253, or DoD Cybersecurity standards

Soft Skills

  • Ability to lead architecture decisions and mentor others
  • Strong communicator capable of translating compliance needs into technical workflows
  • Able to operate independently in a fast-paced federal/healthcare environment
  • Comfortable producing documentation for audits and ATO packages

Physical Demands:

  • Must be able to lift up to 20 pounds
  • Must be able to stand and walk for prolonged amounts of time
  • Must be able to twist, bend and squat periodically

SECURITY CLEARANCE REQUIREMENTS: Must be able to obtain a security clearance at the Public Trust level. US Citizenship is a requirement.

#LI-KC1

About the Company

B

Bowhead / UIC Technical Services

UIC Government Services (UICGS) and its Bowhead family of companies are a division of Ukpeaġvik Iñupiat Corporation (UIC), an Alaskan Native Corporation (ANC). UIC is one of the largest ANC’s in Alaska, and combined with UICGS/Bowhead, we offer a wide variety of services to defense and civilian government agencies that reach across multiple disciplines, the U.S., and the world. With our excellent management team and great range of services in the areas of Information Technology, Logistics & Marine, Manufacturing & Products, Program Management and Operations, and Systems & Technology, we perform over 250 contracts worldwide with innovative business solutions in areas such as engineering, maintenance services, manufacturing, information technology, program support, logistics/base support, and procurement. Collectively, our 3,500+ employees of the Bowhead family of companies, UIC, UIC Government Services, UIC Government Construction, and UIC Commercial remain committed to delivering quality results to ensure our customers’ success. Headquartered in Virginia, we are a fast-growing, multi-million-dollar corporation consistently recognized as one of the top 25 8(a) certified small business companies for government contracting.

COMPANY SIZE
2,500 to 4,999 employees
INDUSTRY
Real Estate/Property Management
EMPLOYEE BENEFITS
Employee Referral Program, Flexible Spending Accounts, Tuition Reimbursement, Life Insurance, Military Leave, Professional Development, 401K
FOUNDED
1999
WEBSITE
https://www.bowheadsupport.com/