SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 110,000 - 160,000 / annual
CHAOS Industries is a defense technology company founded in 2022 and backed by $1 billion in funding from investors including 8VC, Accel, and Valor Equity Partners. The company develops multi-product solutions powered by Coherent Distributed Networks (CDN™) for warfighters, commercial air operators, and border protection teams.
You will serve as a DevSecOps Engineer, embedding security into every layer of the software development and infrastructure delivery lifecycle. This is a hands-on engineering role where you'll own CI/CD pipeline security, automate compliance and vulnerability checks, harden cloud and on-premise environments, and partner with development and operations teams to make "secure by default" a reality. You'll work across classified and unclassified environments, applying engineering rigor to security—fast, repeatable, and built to scale.
Key Responsibilities:
- Design, implement, and maintain secure CI/CD pipelines integrating automated security scanning tools (SAST, DAST, SCA, secrets detection) using GitHub Actions, GitLab CI, Jenkins, or equivalent
- Automate security and compliance controls including STIG/SRG validation, vulnerability scanning (ACAS/Nessus), and policy-as-code enforcement (OPA, Conftest)
- Collaborate with software engineers to identify, triage, and remediate application security vulnerabilities; champion secure coding practices and threat modeling
- Build and manage container security posture including image hardening, runtime protection, Kubernetes security configurations (RBAC, Pod Security Admission, network policies), and registry scanning
- Design and maintain infrastructure-as-code (Terraform, CloudFormation, Ansible) with integrated security controls; enforce least-privilege and secrets management
- Support RMF/ATO activities by automating evidence collection, generating compliance reports, and maintaining continuous monitoring artifacts for classified or CUI environments
- Monitor security tooling telemetry, pipeline health dashboards, and vulnerability metrics; produce trend reports and actionable remediation backlogs
- Coordinate with ISSM/ISSO teams to ensure DevSecOps practices align with authorization boundary requirements, CMMC Level 2/3 controls, and DFARS obligations
- Evaluate and introduce new DevSecOps tooling, frameworks, and practices; build internal documentation and runbooks
- Travel up to 15% CONUS to support program site integrations, government customer engagements, and security architecture reviews
You'll sit at the intersection of Engineering and Cybersecurity divisions, collaborating daily with software engineers, cloud architects, ISSMs, and platform teams. You're not a gatekeeper; you're an accelerant who happens to care deeply about security.
Requirements:
- Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related technical field (equivalent experience considered)
- 4–7 years of experience in DevOps, software engineering, or cybersecurity with demonstrated hands-on experience integrating security tooling into CI/CD pipelines and cloud environments
- Proficiency in at least one scripting or programming language (Python, Bash, Go, or equivalent) for building automation, security tooling integrations, or infrastructure-as-code
- Hands-on experience with container technologies (Docker, Kubernetes) including security hardening, image scanning, and runtime protection in production environments
- Working knowledge of cloud security on AWS GovCloud or Azure Government including IAM, network security groups, security monitoring services, and secrets management
- Familiarity with SAST, DAST, and SCA tooling (SonarQube, Checkmarx, Snyk, OWASP ZAP, Black Duck, or equivalent) and their integration into automated pipelines
- Eligibility for Security Clearance
Preferred:
- Active TS clearance
- Experience supporting NIST RMF ATO processes for software systems or cloud environments
- Familiarity with CMMC Level 2/3 practices and DFARS 252.204-7012
- Experience with GitOps workflows and policy-as-code frameworks (OPA/Gatekeeper, Kyverno, Conftest)
- Knowledge of software supply chain security practices: SBOM generation, artifact signing (Sigstore/Cosign), dependency provenance tracking
- Experience operating in classified or air-gapped environments with disconnected CI/CD toolchains
- Relevant certifications: Security+, AWS Security Specialty, or equivalent