Job Title: SRE Engineer - (DevSecOps
Engineer)
Job Location: Washington, DC (Hybrid –
Required 1-2 Days in a Month)
Job Type: Contract
This role is not for a traditional DevOps Engineer. The client is specifically looking for DevSecOps Engineer candidates with strong experience in integrating security practices into CI/CD pipelines, implementing shift-left security, and working with security tools and frameworks (e.g., SAST tools, OWASP, NIST, CIS) alongside cloud and automation expertise.
Notes:
- Only for H1B & H4-EAD Candidates
- Only for DC/MD/VA/WV/NC/NY/NJ/PA/DE Candidates
- Must have 7 Years of USA Experience
- Overall 12-15 Years of Experience
Job Description:
We are seeking a highly
skilled DevSecOps Engineer to lead the integration of security into
our cloud-native development and operations workflows. This role requires deep
expertise in AWS tooling, infrastructure automation, and secure CI/CD practices.
The ideal candidate will have hands-on experience with AWS CodePipeline, Code
Build, Code Deploy (including blue/green deployments), Bitbucket, Python CDK,
and Terraform.
Key Responsibilities:
- Design and implement secure
CI/CD pipelines using AWS Code Pipeline, Code Build,
and Code Deploy.
- Configure and manage blue/green
deployments for zero-downtime releases.
- Integrate Dynatrace
Observability with Amtrak applications.
- Automate infrastructure
provisioning using Terraform and AWS CDK (Python).
- Integrate security scanning
tools (SAST, DAST, SCA) into build and deployment workflows.
- Collaborate with development
and operations teams to enforce secure coding and deployment standards.
- Monitor and respond to
vulnerabilities across applications and infrastructure.
- Ensure compliance with security
policies and cloud governance frameworks.
- Maintain documentation for
security processes, configurations, and deployment strategies.
Required Skills:
- Strong hands-on experience
with AWS services, including:
- Code Pipeline, Code
Build, Code Deploy
- IAM, EC2, Lambda, S3,
CloudFormation
- Proficiency in Python,
especially for infrastructure automation using AWS CDK.
- Proficient with Dynatrace
Observability platform.
- Experience
with Terraform for infrastructure-as-code.
- Familiarity
with Bitbucket for source control and pipeline management.
- Knowledge of containerization
and orchestration (Docker, Kubernetes).
- Experience with security tools
(e.g. Checkmarx, SonarQube).
- Understanding of security
frameworks (e.g., OWASP, NIST, CIS).
Preferred Certifications:
- AWS Certified DevOps Engineer
- Certified DevSecOps
Professional (CDP)
- CISSP or equivalent security
certification
Soft Skills:
- Strong analytical and
problem-solving abilities.
- Excellent communication and
collaboration skills.
- Ability to work independently
and in cross-functional teams.
- Passion for automation,
security, and continuous improvement.