Jobs and Careers
FI

Senior DevSecOps Engineer

Firestorm
San Diego, United Statesfull_timeVerifiedPosted 3 Jun 2025
💰 $175,000/yr($145,000/yr$175,000/yr)

About the role

Who We Are  At Firestorm, we’re on a mission to revolutionize how defense solutions are designed and delivered. Our goal is to empower U.S. ally nations to effectively deter aggressors—regardless of their defense budget—through innovative, cost-efficient technologies. We call this vision “democratized deterrence.”  As a VC-backed company at the intersection of defense and Silicon Valley, we’re pioneering the development of mission-adaptable aerial vehicles that put power back into the hands of operators. By prioritizing operator effectiveness, we’re pioneering a new era of aerial vehicle design. We aim to upend the traditional defense procurement model by delivering world-class capabilities at a fraction of the usual cost.  Join us at Firestorm as we redefine defense procurement, making cutting-edge technology accessible to all at a fraction of the cost.  About the Role  Firestorm is building out a specialized DevSecOps function to drive a secure, automated software factory supporting every product we ship—from firmware and FPGA to Android apps, desktop GUIs, and cloud-native microservices. As our first Senior DevSecOps Engineer, you’ll design, build, and harden an end-to-end pipeline that meets DoD continuous Authorization-to-Operate (cATO) requirements across continuous monitoring, active cyber defense, and software supply chain security.  This is a high-ownership, deeply technical, on-site role based at our San Diego headquarters. You’ll be a key individual contributor from day one, with opportunities to mentor teammates, shape platform strategy, and embed DevSecOps best practices company-wide.  You’ll thrive here if you treat manual work as a system flaw, communicate security clearly across diverse teams, and strike the right balance between startup agility and long-term compliance. We’re looking for someone who sees across systems—firmware, cloud, mobile—and knows how to secure them holistically.  What You’ll Do  
  • Own the architecture for a secure, cATO-compliant DevSecOps pipeline—selecting tooling (e.g., Platform One / Big Bang), defining workflows, and building support for diverse targets (cloud, embedded, mobile, desktop). 
  • Automate controls across all three cATO pillars: continuous monitoring dashboards, active cyber-defense sensors, and secure supply chain attestations. 
  • Stand up multi-stage pipelines using GitHub Actions, GitLab CI, or Azure DevOps to cross-compile C/C++ and Rust for ARM, build Android and Windows apps, and produce Iron Bank-ready OCI containers. 
  • Implement Infrastructure- and Compliance-as-Code (Terraform, Bicep, Ansible) with policy-as-code guardrails (OPA, Conftest, Checkov) and STIG baseline generation via OpenSCAP. 
  • Secure artifacts and identities using Entra ID, Key Vault, mTLS, SPIFFE/SPIRE, and Sigstore for cryptographic signing of binaries, containers, and firmware. 
  • Embed supply chain security via in-toto attestations, CycloneDX SBOMs, SLSA Level 3+ provenance, and artifact quarantines. 
  • Deploy active cyber defense controls including runtime agents (Falco, Sysdig), zero-trust segmentation, and automated rollback triggered by security events. 
  • Work closely with our Information System Security Officer (ISSO) to align pipeline controls, documentation, and automation with evolving compliance and accreditation needs. 
  • Automate ATO evidence generation—producing OSCAL artifacts, SSPs, and POA&Ms integrated with eMASS or Xacta. 
  • Instrument full-stack observability using OpenTelemetry, Prometheus, ELK/Splunk, and SLO-driven alerting. 
  • Guide developers on secure-by-default practices, incident response, and threat modeling; build a culture of blameless postmortems and continuous improvement. 
 Minimum Qualifications  
  • Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience) 
  • 7+ years in DevOps, SRE or security automation role, with 3+ years supporting regulated U.S. Government environments 
  • Demonstrated success building or operating a pipeline that achieved ATO, FedRAMP, DoD RMF, or cATO 
  • Deep expertise with at least one major CI platform and IaC toolset (e.g., GitHub Actions, GitLab CI, Azure DevOps + Terraform, Bicep, CloudFormation, or Ansible) 
  • Experience hardening containers and Kubernetes (e.g., AKS, EKS, RKE2), including SCAP/Inspec scanning, signing, and admission control 
  • Strong scripting or automation skills (Python, Bash, Go, or Rust) 
  • Familiarity with NIST 800-53 Rev 5, DISA STIGs, OWASP SAMM, and SLSA—comfortable writing CCIs and inheriting controls 
  • Experience securing heterogeneous build targets: embedded Linux (Yocto/Buildroot), Android, Windows code-signing, and macOS notarization 
  • U.S. citizenship required with the ability to obtain and maintain a U.S. Government security clearance 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Firestorm

View company profile →