Jobs and Careers
FI
Senior DevSecOps Engineer
FirestormSan Diego, United Statesfull_timeVerifiedPosted 3 Jun 2025
💰 $175,000/yr($145,000/yr – $175,000/yr)
About the role
Who We Are At Firestorm, we’re on a mission to revolutionize how defense solutions are designed and delivered. Our goal is to empower U.S. ally nations to effectively deter aggressors—regardless of their defense budget—through innovative, cost-efficient technologies. We call this vision “democratized deterrence.” As a VC-backed company at the intersection of defense and Silicon Valley, we’re pioneering the development of mission-adaptable aerial vehicles that put power back into the hands of operators. By prioritizing operator effectiveness, we’re pioneering a new era of aerial vehicle design. We aim to upend the traditional defense procurement model by delivering world-class capabilities at a fraction of the usual cost. Join us at Firestorm as we redefine defense procurement, making cutting-edge technology accessible to all at a fraction of the cost. About the Role Firestorm is building out a specialized DevSecOps function to drive a secure, automated software factory supporting every product we ship—from firmware and FPGA to Android apps, desktop GUIs, and cloud-native microservices. As our first Senior DevSecOps Engineer, you’ll design, build, and harden an end-to-end pipeline that meets DoD continuous Authorization-to-Operate (cATO) requirements across continuous monitoring, active cyber defense, and software supply chain security. This is a high-ownership, deeply technical, on-site role based at our San Diego headquarters. You’ll be a key individual contributor from day one, with opportunities to mentor teammates, shape platform strategy, and embed DevSecOps best practices company-wide. You’ll thrive here if you treat manual work as a system flaw, communicate security clearly across diverse teams, and strike the right balance between startup agility and long-term compliance. We’re looking for someone who sees across systems—firmware, cloud, mobile—and knows how to secure them holistically. What You’ll Do
- Own the architecture for a secure, cATO-compliant DevSecOps pipeline—selecting tooling (e.g., Platform One / Big Bang), defining workflows, and building support for diverse targets (cloud, embedded, mobile, desktop).
- Automate controls across all three cATO pillars: continuous monitoring dashboards, active cyber-defense sensors, and secure supply chain attestations.
- Stand up multi-stage pipelines using GitHub Actions, GitLab CI, or Azure DevOps to cross-compile C/C++ and Rust for ARM, build Android and Windows apps, and produce Iron Bank-ready OCI containers.
- Implement Infrastructure- and Compliance-as-Code (Terraform, Bicep, Ansible) with policy-as-code guardrails (OPA, Conftest, Checkov) and STIG baseline generation via OpenSCAP.
- Secure artifacts and identities using Entra ID, Key Vault, mTLS, SPIFFE/SPIRE, and Sigstore for cryptographic signing of binaries, containers, and firmware.
- Embed supply chain security via in-toto attestations, CycloneDX SBOMs, SLSA Level 3+ provenance, and artifact quarantines.
- Deploy active cyber defense controls including runtime agents (Falco, Sysdig), zero-trust segmentation, and automated rollback triggered by security events.
- Work closely with our Information System Security Officer (ISSO) to align pipeline controls, documentation, and automation with evolving compliance and accreditation needs.
- Automate ATO evidence generation—producing OSCAL artifacts, SSPs, and POA&Ms integrated with eMASS or Xacta.
- Instrument full-stack observability using OpenTelemetry, Prometheus, ELK/Splunk, and SLO-driven alerting.
- Guide developers on secure-by-default practices, incident response, and threat modeling; build a culture of blameless postmortems and continuous improvement.
- Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience)
- 7+ years in DevOps, SRE or security automation role, with 3+ years supporting regulated U.S. Government environments
- Demonstrated success building or operating a pipeline that achieved ATO, FedRAMP, DoD RMF, or cATO
- Deep expertise with at least one major CI platform and IaC toolset (e.g., GitHub Actions, GitLab CI, Azure DevOps + Terraform, Bicep, CloudFormation, or Ansible)
- Experience hardening containers and Kubernetes (e.g., AKS, EKS, RKE2), including SCAP/Inspec scanning, signing, and admission control
- Strong scripting or automation skills (Python, Bash, Go, or Rust)
- Familiarity with NIST 800-53 Rev 5, DISA STIGs, OWASP SAMM, and SLSA—comfortable writing CCIs and inheriting controls
- Experience securing heterogeneous build targets: embedded Linux (Yocto/Buildroot), Android, Windows code-signing, and macOS notarization
- U.S. citizenship required with the ability to obtain and maintain a U.S. Government security clearance
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s