What are the responsibilities and job description for the IT Specialist (DevSecOps) position at Case Management Modernization Office?
The CMM drives change management and adoption practices to achieve delivery of a modernized, efficient, and secure case management environment. This role leads teams, manages resources, and delivers solutions supporting the judiciary's mission and operational excellence.
Qualifications:
Applicants must have demonstrated experience as listed below. This requirement is according to the AO Classification, Compensation, and Recruitment Systems which include interpretive guidance and reference to the OPM Operating Manual for Qualification Standards for General Schedule Positions.Specialized Experience: Applicants must have at least one full year (52 weeks) of specialized experience in each of the following:
- Advancing DevSecOps maturity by implementing automated and manual application security testing, including static application security testing, dynamic application security testing, interactive application security testing, software composition analysis, and container scanning; implementing and enforcing secure coding practices and hardened deployment standards; and continuously monitoring environments for cybersecurity events.
- Applying deep technical expertise in major cloud platforms, scripting and automation tools such as Python, Bash, or Golang, and cybersecurity frameworks such as NIST, OWASP, and CIS, including hands-on execution of Zero Trust concepts and secure AI practices.
- Leading major information security initiatives by balancing workload across projects and incidents, keeping leadership informed, and facilitating, executing, or directing efforts involving governance, risk, and compliance; security operations center activities; compliance or authorization activities such as FedRAMP; enterprise-level guidance; and adversarial exercises such as blue, red, or purple team activities.
- Certified Cloud Security Professional (CCSP)
- GIAC Cloud Security Automation (GCSA)
- Certified DevSecOps Engineer (ECDE)
- AWS Certified DevOps Engineer - Professional
Preferred qualifications include:
- Experience with Terraform, AWS CloudFormation, or other infrastructure as code tools.
- Experience implementing security scanning tools within CI/CD pipelines such as Jenkins, GitLab CI, or GitHub Actions.
- Practical knowledge of Docker, Kubernetes, and container security.
- Proficiency in Python, Bash, or Go.
- Familiarity with NIST 800-53, FedRAMP, FISMA, or similar federal security standards.
- Hands-on experience with AWS security services such as Identity and Access Management (IAM), GuardDuty, Security Hub, Web Application Firewall (WAF), CloudTrail, CloudWatch, or Config.
Responsibilities:
The Administrative Office of the U.S. Courts (AO), Case Management Modernization (CMM) Program Office, is seeking an experienced IT Specialist (DevSecOps) to support secure cloud operations, automate security controls, and strengthen delivery pipelines and infrastructure across AWS-based environments. The incumbent is responsible for embedding security into continuous integration/continuous delivery (CI/CD) processes, infrastructure as code, cloud services, containerized environments, monitoring capabilities, and vulnerability management practices.
The incumbent must have strong technical, analytical, and problem-solving skills and the ability to communicate effectively with technical and non-technical stakeholders; manage multiple priorities under demanding circumstances and time constraints; automate and improve security processes; and collaborate effectively across engineering, security, operations, and compliance teams.
The duties of this position include, but are not limited to:
- Implementing and maintaining CI/CD pipelines with automated security checks, including static application security testing, dynamic application security testing, software composition analysis, and other security validation capabilities.
- Developing and maintaining secure infrastructure as code using tools such as Terraform or related automation frameworks to support consistent, secure cloud deployments.
- Configuring, hardening, and managing AWS services and cloud security controls, including identity and access management, network security, encryption, container registries, and Kubernetes environments.
- Supporting secure container operations through the management and hardening of Docker, Kubernetes, and AWS Elastic Kubernetes Service (EKS) environments.
- Implementing and maintaining continuous monitoring, logging, audit, and compliance capabilities using cloud-native and related security tools.
- Monitoring, assessing, patching, and remediating security vulnerabilities across applications, infrastructure, and cloud services.
- Guiding secure cloud operations and sustainment by identifying and mitigating technical threat vectors, reducing attack surface, and implementing practical remediation strategies.
- Advancing DevSecOps maturity through automated and manual application security testing, secure coding practices, hardened deployment standards, and continuous monitoring for cybersecurity events.
- Supporting federal information security compliance activities, including vulnerability remediation, security documentation, control assessments, compliance monitoring, and related risk management efforts.
Salary : $102,415