Job Description

Overview

We are seeking a Senior DevSecOps Engineer to build and improve secure software delivery, release engineering, and deployment platforms. This role will maintain GitLab CI/CD pipelines for TypeScript/JavaScript, Python, and Rust applications across Linux, Windows, and macOS.

 

The ideal candidate combines strong CI/CD and cloud-native engineering experience with practical application-security expertise. They will partner with engineering, security, and infrastructure teams to make secure, reliable delivery the default throughout the software development lifecycle.

 

LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.

 

Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors—helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value.

Responsibilities

  • Design and maintain reusable GitLab CI/CD pipelines and templates.
  • Integrate automated testing, code-quality checks, and security scanning using tools such as SonarQube, Vitest, Playwright, Cypress, pytest, Cargo, Trivy, Sonatype, OWASP tools, and KICS.
  • Build secure workflows for scanning, signing, attesting, and publishing containers and packages to Nexus.
  • Develop cross-platform release processes, including packaging, signing, versioning, and artifact promotion.
  • Deploy and operate Kubernetes workloads across on-premises, Azure, and AWS environments.
  • Support elastic and high-performance computing workloads using platforms such as Slurm and Azure CycleCloud.
  • Manage dependency updates and remediate vulnerabilities across applications, containers, build systems, and infrastructure.
  • Establish practical security policies, remediation timelines, exceptions, and release quality gates.
  • Improve pipeline reliability, performance, documentation, and developer self-service capabilities.
  • Partner with engineering teams to strengthen security without unnecessarily slowing delivery.

Qualifications

Required Qualifications

  • Bachelor’s degree in computer science, engineering, information security, or a related field.
  • Significant experience in DevOps, DevSecOps, platform engineering, site reliability engineering, or release engineering.
  • Advanced experience designing and operating GitLab CI/CD pipelines.
  • Strong Linux and shell-scripting skills.
  • Experience supporting build, test, and packaging workflows for JavaScript/TypeScript, Python, or Rust.
  • Hands-on experience with automated security scanning, vulnerability management, and CI/CD quality gates.
  • Experience building, scanning, signing, and publishing OCI container images.
  • Experience with artifact repositories such as Sonatype Nexus Repository.
  • Strong Kubernetes experience and familiarity with Azure or AWS.
  • Working knowledge of infrastructure as code and configuration management.
  • Experience creating releases for Linux, Windows, or macOS.
  • Strong troubleshooting, documentation, communication, and cross-team collaboration skills.

Preferred Qualifications

  • Experience with Slurm, Azure CycleCloud, HPC, or compute-intensive workloads.
  • Familiarity with Helm, Kustomize, Terraform, Ansible, or similar tools.
  • Experience with SBOMs, artifact provenance, SLSA, Sigstore/Cosign, or code-signing systems.
  • Knowledge of OWASP, CWE, CVE, CVSS, CIS benchmarks, NIST guidance, and secure SDLC practices.
  • Experience with dependency automation, self-hosted GitLab runners, observability, or incident response.
  • Relevant cloud, Kubernetes, security, or GitLab certifications.

What Success Looks Like

Within the first year, the successful candidate will:

  • Establish reusable CI/CD standards across supported platforms and languages.
  • Increase automated testing and security coverage while improving pipeline reliability and speed.
  • Deliver secure, repeatable container, package, and cross-platform release workflows.
  • Improve vulnerability ownership, prioritization, and remediation.
  • Strengthen the consistency and resilience of Kubernetes and HPC deployments.
  • Enable teams to deliver secure software with less manual intervention.

 

Target salary range: $122,000 - $200,000

 

Disclaimer: 

The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

Job Locations

US-CO-Colorado Springs