
location_onColonial Warehouse, 212, 3rd Avenue North, North Loop, Central, Minneapolis, Hennepin County, Minnesota, 55401, United States
Maximus Technology and Consulting Services (TCS) operates at the intersection of advanced technology and critical national security. Our team is dedicated to securing the infrastructure that powers essential government operations, ensuring resilience against evolving cyber threats while maintaining the highest standards of compliance and operational excellence.
As a DevSecOps Engineer within our TCS division, you will serve as a vital guardian of our network and application security posture. This role exists to bridge the gap between development, security, and operations, transforming manual security processes into robust, automated frameworks. You will be the architect of our defense strategy, implementing automated application security testing, managing vulnerability lifecycles, and orchestrating secure deployment pipelines.
Your day-to-day involves a dynamic blend of proactive defense and reactive remediation. You will design and implement solutions for network security issues, conduct deep-dive root cause analyses using advanced monitoring tools, and maintain critical runbooks to prevent recurring incidents. From setting up and monitoring proxy servers and firewalls to performing rigorous penetration testing and security code reviews, you will ensure our systems remain secure against sophisticated threats. You will also collaborate closely with cross-functional teams to develop automated security frameworks, leveraging scripting languages and open-source solutions to replace manual tasks and enhance efficiency.
Candidates selected for this role must possess an active Top Secret with SCI eligibility. The interview process is designed to assess both technical expertise and cultural fit within our security-focused environment. Successful candidates will be expected to demonstrate proficiency in cloud platforms, automation tools, and security testing methodologies.
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information, and other legally protected characteristics. We are committed to fostering a diverse and inclusive workplace where every team member can contribute to our mission of national security.
Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process—including accessing job postings, completing assessments, or participating in interviews—please contact People Operations at applicantaccom@maximus.com.
Work model: On-site
Colonial Warehouse, 212, 3rd Avenue North, North Loop, Central, Minneapolis, Hennepin County, Minnesota, 55401, United States
Minneapolis, Minnesota
Certified Kubernetes Application Developer (CKAD), Red Hat Certified Engineer (RHCE), Certified Jenkins Engineer (CJE), AWS Certified DevOps Engineer, Certified Kubernetes Engineer (CKA), GitLab Certified DevOps Professional, or similar certifications. Familiarity with technical aspects for IT and IAT-Level II Certifications. Experience with CI/CD pipelines, infrastructure as code, and containerization technologies. Expertise in cloud platforms, automation tools, scripting languages, and security testing tools. Understanding of AWS, Azure, or GCP and their security services. Understanding of USAF IT systems, networks, and platforms. Experience with Jenkins, GitLab CI, Azure DevOps, or similar tools for automating the build, test, and deployment process. Proficiency with tools like Terraform, Ansible, or CloudFormation to automate infrastructure provisioning and configuration. Familiarity with Docker, Kubernetes, and related technologies. Proficiency in scripting languages like Python, Bash, or PowerShell to automate security tasks and workflows. Experience with static analysis (SAST), dynamic analysis (DAST), and software composition analysis (SCA) tools, as well as vulnerability scanners. Solid understanding of network security principles, including firewalls, intrusion detection/prevention systems, and network segmentation. Familiarity with SIEM solutions (like Splunk or ELK) and log aggregation tools for security monitoring. Familiarity with Identity and Access Management (IAM) and Zero Trust (ZT) security models.