SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Applied Intuition is seeking a DevSecOps Engineer to own secure code integration across the software delivery lifecycle for government and defense customers. This role requires a DoD security clearance and involves working directly with developers to ensure software is securely built, tested, packaged, and deployed into government and customer environments, including classified and air-gapped systems.
Key Responsibilities:
- Own secure code integration from source through build, test, release, and deployment
- Build and maintain secure CI/CD pipelines, reusable pipeline templates, and hardened build environments
- Integrate and tune SAST, DAST, SCA, secrets scanning, container scanning, and infrastructure-as-code scanning tools
- Define and enforce promotion gates with documented severity thresholds and exception paths
- Serve as primary technical resource for developers, troubleshooting findings and removing delivery blockers
- Automate system hardening, security validation, and compliance evidence collection using infrastructure-as-code and policy-as-code (OPA/Rego, cfn-guard, Cedar, or equivalent)
- Build preventive and detective controls in AWS GovCloud, including Service Control Policies, Resource Control Policies, Config, Security Hub, IAM, KMS, CloudTrail, and EventBridge
- Implement software supply chain protections including SBOM generation, artifact signing, and secure dependency management
- Support software promotion into classified and air-gapped environments with offline dependencies and controlled transfer workflows
- Lead threat modeling and security design reviews for new services and pipeline changes
- Partner with ISSM and Cyber Security Engineer to map technical controls to NIST 800-53, NIST 800-171, DISA STIGs, and CMMC Level 2
- Establish secure development guidance and repeatable engineering patterns for product teams
- Participate in security on-call rotation
Applied Intuition is a $15 billion Series A company founded in 2017, headquartered in Sunnyvale, California, with offices globally including Washington, D.C. The company powers physical AI infrastructure for autonomous systems across automotive, defense, trucking, construction, mining, and agriculture. Eighteen of the top 20 global automakers and the U.S. military trust the company's solutions.
The role is in-office at the Washington, D.C. location with expectation of 5 days per week, though occasional flexibility is available. Travel of approximately 10% is required for company and customer business.
Requirements:
- Bachelor's degree in Computer Science, Software Engineering, Cyber Security, or related field, or equivalent hands-on experience
- Minimum 5 years of experience across software engineering, DevOps, platform engineering, or security engineering
- DoD 8140/8570 IAT Level II (Security+ Certification, condition of employment)
- Hands-on scripting or software development experience using Python, Bash, Go, or similar languages
- Experience with CI/CD platforms such as GitLab CI, GitHub Actions, Jenkins, or equivalent
- Production experience with containers and orchestration technologies such as Docker and Kubernetes
- Experience with infrastructure-as-code or configuration management technologies such as Terraform, Ansible, AWS CDK, or CloudFormation
- Hands-on AWS experience, including working knowledge of Config, Security Hub, IAM, KMS, CloudTrail, and CloudWatch/EventBridge
- Experience writing and deploying policy-as-code (OPA Rego, cfn-guard, Cedar, or equivalent)
- Working knowledge of NIST 800-53, NIST 800-171, DISA STIGs, and RMF, and of DFARS 252.204-7012 and CMMC Level 2 obligations
- Experience producing audit-ready evidence and working directly with third-party assessors
- Experience introducing blocking security gates into a delivery pipeline and sustaining them under delivery pressure
- Demonstrated ability to integrate security tooling into developer workflows and make findings actionable
- Proven ability to work directly with developers to troubleshoot issues, teach secure practices, and unblock delivery
- Must be a U.S. Citizen
- Must have or be able to obtain an active DoD security clearance (minimum Secret, prefer Top Secret)
Nice to Have:
- CISSP, CSSLP, or CKS certification, or AWS Security Specialty
- Experience with DoD software factories such as Platform One, Iron Bank, or Big Bang
- Experience with hardware-isolated container runtimes such as Kata Containers or gVisor
- Experience delivering software into classified or air-gapped environments
- Familiarity with software supply chain frameworks such as SLSA, SSDF, CycloneDX, or SPDX
- Experience supporting a FedRAMP or DoD Impact Level 4/5 authorization
- Experience securing AI/ML workloads or machine-generated code and container artifacts
- Prior software development experience on a product engineering team