Demo

Senior DevSecOps Engineer @ Cumberland County, PA - Hybrid

KSN Technologies, Inc.
Pennsylvania, PA Full Time
POSTED ON 11/26/2025
AVAILABLE BEFORE 12/26/2025

Job Details

Senior DevSecOps Engineer

Cumberland County, PA Hybrid

7 months contract

This is a Hybrid Position - NO REMOTE Position available.

We are currently hiring candidates who are authorized to work on our W2.

Candidate with previous state/govt client experience is preferred.

Commonwealth of PA/OA (PSDC) requires the services of a TAS1 A4 SC3 to act as a Senior DevSecOps Engineer.

Work Location: Hybrid with two days onsite (1920 Technology Parkway, Mechanicsburg, PA 17050). Schedule can be discussed during interview.

Work hours: 8AM to 5PM (hourlong lunch)

Start date can be ID'd upon after compliant PATCH and PSDC-related clearance has been processed and approved.

This req is available to candidates nationwide, but candidate must be ready to relocate for this hybrid position (60% remote vs. 40% onsite). Candidate must go onsite on their first day to pick up commonwealth-issued equipment, badging, etc.. Role contingent on compliant PATCH and passing PSDC/CJIS background checks.

PSDC (Public Safety Delivery Center) requires the services of a Senior DevSecOps Engineer to act as consultant with the PSDC Solutions Management group.

Role summary

Hands-on security automation for AWS delivery. Build secure-by-default CDK constructs and CloudFormation templates, wire them into CI/CD, and enforce compliance checks that map to CJIS and NIST. Azure support is a future consideration, not a core day-one duty.

Scope boundaries

  • Does not own enterprise AWS Organizations or SCP operations.
  • Designs and builds reference guardrails and enforcement patterns that can be deployed by enterprise teams.
  • Focuses on preventive controls and compliance automation, not incident response.

What you will deliver

First 90 days

  • Pipeline security templates in GitHub Actions and Azure DevOps with SAST, SCA, IaC, container, and secret scanning gates.
  • Compliance as code in reference accounts: AWS Config rules and Security Hub standards aligned to CJIS and NIST 800-53, with exceptions workflow documented.
  • IaC reference modules using AWS CDK and CloudFormation for IAM least privilege, KMS, Secrets Manager, logging, and network baselines; Terraform equivalents provided where teams require them.
  • Evidence exports tying checks to control IDs and producing auditor-ready artifacts.

Ongoing

  • Harden CDK/CFT modules and pipeline templates as compliance needs evolve.
  • Coach pilot teams to adopt templates.
  • Raise gaps to enterprise teams for org-level enforcement.

Day-to-day responsibilities

  • Author and maintain AWS CDK constructs and CloudFormation templates; provide Terraform versions as secondary.
  • Implement AWS Config conformance, Security Hub standards, and GuardDuty routing in reference accounts.
  • Wire scanning in CI/CD for app code, containers, and IaC.
  • Create reusable GitHub/Azure DevOps templates with enforcement gates and exception handling.
  • Generate posture and evidence reports mapped to CJIS and NIST controls.

Required skills

  • 5 years AWS security automation and DevOps.
  • Strong with AWS CDK and CloudFormation; working proficiency in Terraform.
  • CI/CD authoring in GitHub Actions and Azure DevOps.
  • Proficient in Python and Bash, with PowerShell for Windows automation.
  • Able to read Java and C# to integrate and tune SAST/SCA.
  • Practical knowledge of CJIS and NIST 800-53 control families and how to automate checks and evidence.

Nice to have

  • EKS/ECS/Lambda hardening patterns.
  • OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent.
  • Basic Azure security automation for future phases.

Decision rights

  • Independent on design and build within standards; proposes guardrails and reference patterns; escalates enterprise-wide changes.

Skill

Required Exp

Candidate exp

5 years AWS security automation and DevOps

5

Strong with AWS CDK and CloudFormation; working proficiency in Terraform

Required

CI/CD authoring in GitHub Actions and Azure DevOps

Required

Proficient in Python and Bash, with PowerShell for Windows automation

Required

Able to read Java and C# to integrate and tune SAST/SCA

Required

Practical knowledge of CJIS and NIST 800-53 control families and how to automate checks and evidence

Required

EKS/ECS/Lambda hardening patterns

Nice to have

OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent

Nice to have

Basic Azure security automation for future phases

Nice to have

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

Salary : $60

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Senior DevSecOps Engineer @ Cumberland County, PA - Hybrid?

Sign up to receive alerts about other jobs on the Senior DevSecOps Engineer @ Cumberland County, PA - Hybrid career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$34,477 - $41,836
Income Estimation: 
$38,552 - $46,597
Income Estimation: 
$92,369 - $122,605
Income Estimation: 
$117,024 - $149,811
Income Estimation: 
$158,960 - $205,707
Income Estimation: 
$154,509 - $200,187
Income Estimation: 
$71,493 - $96,419
Income Estimation: 
$92,369 - $122,605
Income Estimation: 
$117,024 - $149,811
Income Estimation: 
$137,568 - $176,908
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at KSN Technologies, Inc.

KSN Technologies, Inc.
Hired Organization Address Hartford, CT Contractor
Senior Salesforce Developer Hartford, CT – Hybrid – Only Locals One Year Contract Candidate Must Be Local Candidate must...
KSN Technologies, Inc.
Hired Organization Address Lansing, MI Full Time
Job Details .NET DEVELOPER Lansing, MI Hybrid Only Locals One Year Contract Please do not submit profiles of candidates ...
KSN Technologies, Inc.
Hired Organization Address Austin, TX Full Time
Job Details Senior RPA Developer Austin, TX Hybrid Only Locals 8 months contract Please do not submit profiles of candid...
KSN Technologies, Inc.
Hired Organization Address Lansing, MI Full Time
Job Details Data Modeler Lansing, MI Hybrid Only Locals One Year Contract Please do not submit profiles of candidates wh...

Not the job you're looking for? Here are some other Senior DevSecOps Engineer @ Cumberland County, PA - Hybrid jobs in the Pennsylvania, PA area that may be a better fit.

Administrative Specialist- Cumberland County Prison

Cumberland County, PA, Carlisle, PA

AI Assistant is available now!

Feel free to start your new journey!