Demo

Sr. DevSecOps Engineer

UICGS / Bowhead Family of Companies
San Diego, CA Full Time
POSTED ON 4/25/2026
AVAILABLE BEFORE 6/13/2026

SR. DEVSECOPS ENGINEER (PACMED): 

 

Bowhead seeks a Sr. DevSecOps Engineer to support in operational systems integration, development, test, evaluation, operation, sustainment, and maintenance using technologies and acquisition management to support technical, ancillary, and clinical support to military medical treatment facilities in the pacific Region. This position will support building a next-generation automated compliance and AI-driven security operations platform supporting DoD, federal health, and enterprise health-care environments. The Sr. DevSecOps Engineer will provide deep experience in DISA STIGs, SCAP automation, RMF workflows, container security, SIEM/SOAR integrations, and AI-assisted security operations. 

 

 

SCAP / STIG Automation 

  • Build automated OpenSCAP pipelines to scan Ubuntu 24.04 LTS and other Linux hosts using DISA STIG benchmarks. 
  • Integrate XCCDF and OVAL results into OpenRMF using automated ingestion workflows. 
  • Develop hardened base images (VMs and containers) aligned to DISA STIG requirements. 

    Container Security 

    • Integrate RapidFort scans into CI/CD pipelines. 
    • Automate ingestion of SCAP JSON into OpenRMF. 
    • Ensure curated images remain compliant and low-CVE. 

      Compliance Operations (RMF/FedRAMP/CMMC) 

      • Support generation of automated DISA checklists (CKLs) and POA&M updates. 
      • Work with compliance and engineering teams to resolve findings and track remediation progress via OpenRMF. 

        Security Telemetry & SIEM Engineering 

        • Deploy/tune Wazuh agents across hosts and workloads. 
        • Configure pipelines from Wazuh → Elastic → Tines. 
        • Write and maintain Elastic SIEM detection rules. 

          SOAR Automation & AI SOC Buildout 

          • Develop Tines workflows to automate: 
            • SCAP ingestion 
            • RapidFort event processing 
            • Elastic SIEM alert enrichment 
            • Compliance notifications & ticketing 
            • Integrate LLMs to: 
              • Summarize alerts 
              • Draft POA&M entries 
              • Generate remediation guidance 
              • Produce daily/weekly SOC and compliance reports 

                Infrastructure & DevSecOps 

                • Contribute to secure CI/CD pipelines, secrets management, system hardening, logging, and access control aligned with DoD RMF. 

                   

                  Must-Have Technical Expertise 

                  • Five to ten (10 ) years Linux engineering with security hardening focus 
                  • Hands-on experience with OpenSCAP, DISA STIGs, SCAP benchmarks, and STIG automation 
                  • Experience working with OpenRMF (or similar RMF automation platforms) 
                  • Strong knowledge of RMF, FedRAMP, or CMMC 
                  • CI/CD pipeline experience (GitLab CI, GitHub Actions, Jenkins, etc.) 
                  • Hands-on experience with Elastic Stack and Wazuh 
                  • Experience deploying or integrating SOAR platforms (Tines preferred; XSOAR or Splunk SOAR acceptable) 
                  • Container security experience (RapidFort, Anchore, Trivy, Aqua, etc.) 

                    Bonus Skills 

                    • Familiarity with ATO workflows (IL4/IL5, DoD impact levels) 
                    • AI integration experience using OpenAI, Azure OpenAI, or similar 
                    • Python or Bash scripting for automation 
                    • Experience with NIST 800-53, CNSSI 1253, or DoD Cybersecurity standards Soft Skills 
                      • Ability to lead architecture decisions and mentor others 
                      • Strong communicator capable of translating compliance needs into technical workflows 
                      • Able to operate independently in a fast-paced federal/healthcare environment 
                      • Comfortable producing documentation for audits and ATO packages 

                         

                        Physical Demands: 

                        • Must be able to lift up to 20 pounds 
                        • Must be able to stand and walk for prolonged amounts of time 
                        • Must be able to twist, bend and squat periodically 

                           

                          SECURITY CLEARANCE REQUIREMENTS: Must be able to obtain a security clearance at the Public Trust level. US Citizenship is a requirement. 

                           

Salary.com Estimation for Sr. DevSecOps Engineer in San Diego, CA
$126,629 to $157,409
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at UICGS / Bowhead Family of Companies

  • UICGS / Bowhead Family of Companies Anchorage, AK
  • UIC Oil & Gas Support, LLC (OGS), a subsidiary of UIC Commercial Services, is seeking an experienced and results-oriented General Manager to lead its Arcti... more
  • 1 Day Ago

  • UICGS / Bowhead Family of Companies Washington, DC
  • ENGINEER III (NHTSA): Bowhead is seeking an Engineer III to support the National Highway Traffic Safety Administration (NHTSA) in Washington, DC. This posi... more
  • 1 Day Ago

  • UICGS / Bowhead Family of Companies Washington, DC
  • SCRUM MASTER (HUDSN): Bowhead seeks a Scrum Master located in Washington D.C. to support the Department of Housing and Urban Developmnet (HUD), Enterprise ... more
  • 1 Day Ago

  • UICGS / Bowhead Family of Companies Washington, DC
  • Industrial Engineer (SIOP-2026-24678): Bowhead seeks an Industrial Engineer to join our team in providing program management support in a broad range of se... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Sr. DevSecOps Engineer jobs in the San Diego, CA area that may be a better fit.

  • Bowhead San Diego, CA
  • Overview SR. DEVSECOPS ENGINEER (PACMED): Bowhead seeks a Sr. DevSecOps Engineer to support in operational systems integration, development, test, evaluati... more
  • 1 Month Ago

  • Trabus Technologies San Diego, CA
  • Position: DevSecOps Engineer Full-time Location: San Diego, CA Salary: $120k-$150k Clearance Level: Secret Trabus Technologies (TRABUS) is a minority-owned... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!