Software Engineer, DevSecOps
Anavationllc · San Antonio, TX, US
Checked against lever — still accepting applications.
- Location
- San Antonio, TX, US
- Type
- Full-time
- Posted
Be Challenged and Make a Difference
In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.
Description of Task to be Performed:
AnaVation is seeking a Software Engineer-DevSecOps to support one of our cybersecurity programs in our San Antonio office. In this position, the right candidate will develop and manage the CI/CD pipelines of mission applications across value streams. Considered a strong generalist on CI/CD and security requirements, the role automates security control implementation and evidence collection and advances inheritance and automation aligned with the Government’s Cyber Assessment Roadmap to sustain IATT, ATO, and cATO readiness.
Position Responsibilities: This position establishes the automation standard for secure software delivery, ensuring security is built into pipelines, and control evidence is generated continuously.
Responsibilities include:
Build and maintain CI/CD pipelines (e.g., GitLab CI, Jenkins) for an enterprise consisting of many applications.
Develop, test, and maintain containerized applications; work with source version control and build/release tooling.
Develop Infrastructure as Code (IaC) and Configuration as Code (CaC) using Packer, Terraform, and Ansible.
Automate security control implementation, validation, and evidence collection supporting RMF, ATO, and cATO.
Integrate and tune pipeline security tooling: SAST, DAST, SCA, container scanning, secrets detection, and policy gates.
Support security-relevant changes (SRCs), Security Impact Assessments (SIAs), and control validation for embedded value streams.
Support application/container vulnerability management, whitelisting decisions, and CTF/pipeline compliance so changes do not invalidate the ATO.
Collaborate with ISSEs, software developers, Value Stream engineers, COT, CPT, and Government stakeholders across sprint cadences.
Architect logging, monitoring, and telemetry to support continuous monitoring.
Maintain a strong security-first mindset and support Zero Trust and secure software supply chain practices.
Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness.
Develop automated security policies in CI/CD (e.g., GitLab Policies) to flag End-of-Life images, remediate pipeline vulnerabilities, prevent unauthorized deployments, and quarantine compromised artifacts.
Description of Task to be Performed:
AnaVation is seeking a Software Engineer-DevSecOps to support one of our cybersecurity programs in our San Antonio office. In this position, the right candidate will develop and manage the CI/CD pipelines of mission applications across value streams. Considered a strong generalist on CI/CD and security requirements, the role automates security control implementation and evidence collection and advances inheritance and automation aligned with the Government’s Cyber Assessment Roadmap to sustain IATT, ATO, and cATO readiness.
Position Responsibilities: This position establishes the automation standard for secure software delivery, ensuring security is built into pipelines, and control evidence is generated continuously.
Responsibilities include:
Build and maintain CI/CD pipelines (e.g., GitLab CI, Jenkins) for an enterprise consisting of many applications.
Develop, test, and maintain containerized applications; work with source version control and build/release tooling.
Develop Infrastructure as Code (IaC) and Configuration as Code (CaC) using Packer, Terraform, and Ansible.
Automate security control implementation, validation, and evidence collection supporting RMF, ATO, and cATO.
Integrate and tune pipeline security tooling: SAST, DAST, SCA, container scanning, secrets detection, and policy gates.
Support security-relevant changes (SRCs), Security Impact Assessments (SIAs), and control validation for embedded value streams.
Support application/container vulnerability management, whitelisting decisions, and CTF/pipeline compliance so changes do not invalidate the ATO.
Collaborate with ISSEs, software developers, Value Stream engineers, COT, CPT, and Government stakeholders across sprint cadences.
Architect logging, monitoring, and telemetry to support continuous monitoring.
Maintain a strong security-first mindset and support Zero Trust and secure software supply chain practices.
Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness.
Develop automated security policies in CI/CD (e.g., GitLab Policies) to flag End-of-Life images, remediate pipeline vulnerabilities, prevent unauthorized deployments, and quarantine compromised artifacts.
Stop retyping the same form
Upload a CV once. Otto fills in this application and the next forty.
Try Free Now →