ApplySarthi

Cybersecurity Engineer – DevSecOps

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

304 open cybersecurity roles across 67 companies are on ApplySarthi right now, most of them in Delhi NCR (8), Chennai (5), Mumbai (4).

Cybersecurity Engineer jobs in the United States · CI/CD jobs · IAM jobs

Jobgether has 4,533 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

304 open cybersecurity roles are hiring right now across 67 companies, mostly in Delhi NCR — so the questions repeat. Practise them before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with CI/CD? Tell me one thing you learned the hard way.
  3. Tell me about an outage you handled. What did you learn from it?
  4. How do you decide what to monitor, and what should wake someone up at night?
  5. How would you cut the cloud bill of a system without hurting it?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Cybersecurity Engineer – DevSecOps at Jobgether interview free →

Accountabilities: Conduct code and container vulnerability assessments using approved DoD vulnerability scanning tools, DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and applicable software assurance tools. Assess operating system security configurations against applicable DISA STIGs, SRGs, and cybersecurity requirements. Perform cybersecurity assessments, security audits, and risk analyses to identify vulnerabilities, security weaknesses, and compliance gaps. Apply Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies throughout the software development lifecycle. Integrate and assess cybersecurity policies and controls within CI/CD pipelines to support secure software delivery. Serve as a GitLab security reviewer and approver for merge requests, evaluating scan results and confirming that findings are remediated or appropriately documented before release. Review GitLab SAST, dependency, secret detection, and container scanning results and coordinate remediation with development teams. Track cybersecurity findings through closure and ensure appropriate risk-management processes are followed for unresolved issues. Review changes to GitLab security policies, pipeline controls, and protected branch settings to ensure required security checks and approvals remain enforced. Provide cybersecurity oversight for containerized workloads using NeuVector, including vulnerability findings, admission control decisions, and runtime security alerts. Collaborate with application and platform teams to investigate NeuVector findings, refine security policies, and document remediation or accepted risks. Ensure security provisions within system acquisition and program documentation address identified cybersecurity requirements. Provide cybersecurity guidance and support the development of mitigation strategies for DoD information systems. Prepare Risk Management Framework (RMF) artifacts and Memoranda of Agreement (MoAs) supporting system interfaces and networking implementations. Identify and evaluate Common Criteria and National Information Assurance Partnership (NIAP)-certified technologies when applicable. Evaluate cybersecurity products and technologies to determine alignment with applicable DoD and DoN requirements. Collaborate with engineering, development, platform, and program teams throughout the software lifecycle to address security requirements and manage cybersecurity risks. Support business development activities as needed, including technical interviews, technical documentation, proposal writing, and proposal review activities. Requirements Active Secret security clearance required. Bachelor’s degree with 8 years of relevant experience, or high school diploma/equivalent with 13 years of relevant experience. Experience working within the DoD Risk Management Framework (RMF) and familiarity with DoDI 8510.01. DoD 8570.01-M Information Assurance Manager (IAM) Level II certification, such as CISSP, GSLC, or CISM. Strong knowledge of DoD cybersecurity requirements, including DISA STIGs and SRGs. Experience with software security testing methodologies, including SAST and DAST. Demonstrated experience supporting cybersecurity within CI/CD pipelines or DevSecOps environments. Experience with GitLab security tools and processes, including reviewing security scan results and coordinating vulnerability remediation. Experience with container security and vulnerability management is preferred. Proficiency with GitLab, NeuVector, and Sonatype is preferred. Experience supporting cybersecurity initiatives within a DoD or Department of the Navy environment is preferred. Experience with the Navy’s Rapid Assess and Incorporate Software Engineering (RAISE) methodology and RAISE Platform of Choice (RPOC) is advantageous. Experience evaluating Common Criteria and NIAP-certified technologies is preferred. Experience developing or supporting RMF artifacts, security documentation, and cybersecurity mitigation strategies is advantageous. Strong analytical, problem-solving, documentation, and communication skills. Ability to collaborate effectively with technical teams, security stakeholders, program leadership, and system owners. Ability to work independently in a fully remote environment while maintaining strong attention to detail and compliance. Candidates located in or near major U.S. Navy installations are preferred, particularly in the New Orleans, Orlando, and Washington, DC metropolitan areas. Candidates near other major Navy facilities may also be considered. Comfortable working for prolonged periods at a desk and on a computer. Able to lift approximately 10–15 pounds when required. Benefits Annual compensation range of $125,000–$135,000 , with final compensation determined by relevant education, experience, knowledge, skills, abilities, and other applicable factors. Fully remote work arrangement. Opportunity to support cybersecurity and secure software delivery within a DoD/DoN mission environment. Hands-on exposure to DevSecOps, application security, CI/CD security, container security, vulnerability management, and cybersecurity compliance. Opportunity to work with technologies and tools including GitLab, NeuVector, Sonatype, SAST, DAST, and container security platforms. Exposure to Risk Management Framework processes and federal cybersecurity standards. Opportunity to collaborate with engineering, development, platform, and program professionals on mission-focused initiatives. Potential involvement in technical business development, proposal development, and strategic growth activities. Professional development opportunities through exposure to evolving cybersecurity technologies and methodologies.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-09-28. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.