Devsec Ops Engineer

Anduril Anduril · Defense · Broomfield, CO +1 · Mission Systems : Battlespace Awareness Engineering

Anduril Industries is a defense technology company developing AI-powered systems for military applications. The Air & Missile Defense Radar team focuses on tracking algorithms and software. This DevSecOps Engineer role will build and maintain secure automation infrastructure for radar tracking deployments, create testing and analysis tools, and accelerate developer workflows. Responsibilities include designing CI/CD pipelines for classified environments, implementing Infrastructure-as-Code, automating security compliance, developing containerization solutions, and managing secrets. The role requires experience with CI/CD tools, IaC, containerization, Linux administration, and familiarity with DoD security frameworks. Experience in classified environments and with ATO processes is desired.

What you'd actually do

  1. Design and implement secure CI/CD pipelines for classified environments, enabling automated build, test, and deployment of radar tracking software across multiple enclaves
  2. Build Infrastructure-as-Code frameworks (Terraform, Ansible, or similar) to provision and configure development, test, and production environments that meet DISA STIG and NIST 800-53 requirements
  3. Automate security compliance workflows, including STIG scanning, vulnerability assessment, configuration validation, and compliance reporting for continuous monitoring
  4. Develop containerization and orchestration solutions (Docker, Kubernetes) tailored for classified networks with appropriate security hardening
  5. Implement secrets management, certificate rotation, and access control systems that balance security with developer productivity

Skills

Required

  • 5+ years of experience and a Bachelor's degree in Computer Science, Engineering, Cybersecurity, or related field (or equivalent experience)
  • Strong hands-on experience with CI/CD tools such as GitLab CI, Jenkins, GitHub Actions, or similar
  • Understanding of software engineering fundamentals: design patterns, testing, version control, and debugging
  • Proficiency with Infrastructure-as-Code using Terraform, Ansible, Puppet, Chef, or similar tools
  • Working knowledge of containerization technologies (Docker) and orchestration platforms (Kubernetes, Docker Swarm)
  • Understanding of Linux system administration, networking, and scripting (Python, Bash)
  • Familiarity with DoD security frameworks (RMF, NIST 800-53, DISA STIGs)
  • Ability to obtain and maintain a U.S. Top Secret SCI security clearance

Nice to have

  • Experience deploying and maintaining systems in classified DoD or IC environments
  • Hands-on experience with ATO processes, STIG implementation, and continuous monitoring for accredited systems
  • Proficient in Python package development
  • Familiarity with SCAP-compliant scanning tools (OpenSCAP, Nessus, ACAS) and automated compliance frameworks
  • Experience with secure software supply chain practices, artifact signing, and software bill of materials (SBOM)
  • Knowledge of zero-trust architectures and microsegmentation in Kubernetes environments
  • Experience with GitOps workflows and declarative infrastructure management
  • Proficiency with observability and monitoring tools (Prometheus, Grafana, ELK stack, Splunk)
  • Understanding of PKI, certificate management, and secrets management solutions (Vault, AWS Secrets Manager)
  • Experience with air-gapped or disconnected network deployments
  • Familiarity with real-time or embedded systems and their unique deployment constraints
  • Active U.S. Top Secret SCI clearance
  • Relevant certifications such as Security+, CISSP, or AWS/Azure security certifications

What the JD emphasized

  • stringent DoD and IC security requirements
  • DISA STIG and NIST 800-53 requirements
  • DoD security frameworks (RMF, NIST 800-53, DISA STIGs)
  • classified environments
  • ATO processes
  • continuous monitoring