DevSecOps Engineer
Fortreum is a trusted leader in cloud and cybersecurity services, ranked among the Top 5 FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, we have expanded our capabilities to include advanced cyber risk quantification and analytics, enabling organizations to better understand, measure, and communicate risk. Together, we deliver independent, third-party, vendor-agnostic regulatory assessment and advisory services, alongside advanced cybersecurity offensive and compliance technical solutions. Our comprehensive service portfolio spans regulatory compliance frameworks including FedRAMP, CMMC, FISMA, SOC, PCI, ISO, and HIPAA.
Working with Fortune 500 companies and leading cloud service providers, we’ve built our reputation on service-delivery excellence and an unwavering commitment to client success. Our continued rapid growth creates exceptional opportunities for driven professionals to make their mark in the cybersecurity industry—guided by our core values: quality above all, a customer-driven mindset, autonomy, and personal accountability.
Fortreum is transforming how compliance gets done through the Kovr AI Platform — our AI-native compliance automation solution. In the age of agentic AI, Kovr applies intelligent, autonomous workflows to the assessment and authorization lifecycle, turning slow, manual, evidence-heavy compliance work into a faster, repeatable, and more reliable process. By automating artifact generation, evidence and control mapping, and continuous validation across frameworks such as FedRAMP, CMMC, SOC, ISO, and HIPAA, the platform dramatically compresses assessment timelines and is setting a new standard for how organizations achieve and sustain compliance.
The Opportunity
On our team, you will have the opportunity to work with industry-leading experts who’ve supported the world’s most security-conscious organizations. As a DevSecOps Engineer, you will embed with enterprise and federal customers to deploy, integrate, and operationalize the Kovr AI Platform within their environments—building integrations with their DevSecOps toolchains, automating evidence collection and continuous monitoring, and configuring compliance workflows that accelerate Authority to Operate (ATO). You will serve as the hands-on technical bridge between our customers and Kovr’s engineering team, solving complex deployment challenges across cloud, hybrid, and classified National Security and Intelligence Community (IC) environments..
Key Responsibilities
Design, build, and maintain CI/CD pipelines supporting rapid, secure software delivery
Manage cloud infrastructure (AWS, with exposure to Azure/GCP) using Infrastructure as Code (Terraform), including module design and reusable patterns for the broader team
Administer and scale containerized workloads (Kubernetes/EKS, Helm, ArgoCD)
Implement and maintain security controls and monitoring aligned to NIST 800-53 and OSCAL-based frameworks
Design observability strategy (logging, metrics, alerting, SLOs) to support production reliability at scale
Integrate DevOps tooling (GitHub, JIRA, Splunk, Snyk) into automated compliance and remediation workflows
Collaborate with existing engineering and compliance teams to ensure infrastructure changes maintain continuous authorization posture
Support continuous monitoring and audit-readiness activities, including evidence collection and control mapping
Troubleshoot production issues and drive continuous improvement in deployment reliability
Build and maintain documentation, runbooks, and architecture decision records
Represent infrastructure/security in cross-functional planning, including customer-facing technical conversations when needed
Basic Qualifications
7+ years of DevOps, Platform Engineering, or Site Reliability Engineering experience
Hands-on experience architecting AWS infrastructure using Terraform at scale
Strong production experience with Kubernetes (EKS or similar), including cluster design, Helm Charts, and GitHub/GitOps workflows
Direct experience with FedRAMP, CMMC, NIST 800-53/800-171, or DoD SRG compliance environments
Familiarity with OSCAL or other machine-readable compliance/documentation frameworks
Experience integrating SAST/DAST or IaC security scanning into a pipeline
Scripting/automation proficiency (Python, Bash, or similar)
U.S. Citizenship, with the ability to obtain and maintain a Top Secret clearance
Comfortable working in a fast-moving startup-within-a-company environment
Local to Washington, DC metro area
Preferred Qualifications
Existing security or cloud certifications (Security+, AWS Certified Security, CYSA+, CISSP)
Experience integrating LLM coding agents, MCPs, and automations into DevOps workflows
Prior experience holding or maintaining a Top Secret security clearance
Background supporting federal DevSecOps deployments or highly regulated commercial clients Charts
Posted Salary Range
$155,000 - $205,000 annual salary
What Fortreum Offers
We offer a competitive compensation package, where you will be rewarded based on your performance/outcomes and recognized for the value you bring to our business. Our benefits package includes medical insurance, dental insurance, vision insurance, 401K plan with a 4% match, company paid short-term disability, company paid long-term disability, company paid AD&D and life insurance, flex time off, annual bonuses, training stipends, certification reimbursements, access to over 30,000 free online training courses, personal cell phone allowance, new hire and annual home office stipend, spot awards and eleven paid holidays.
An Affirmative Action and Equal Opportunity Employer
Fortreum is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. If you’d like to view a copy of the company’s affirmative action plan or policy statement, please email [email protected]. If you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application, please e-mail [email protected] or call 703-594-1460. This email and phone number is created exclusively to assist disabled job seekers whose disability prevents them from being able to apply online. Only messages left for this purpose will be returned. Messages left for other purposes, such as following up on an application or technical issues not related to a disability, will not receive a response.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
Job Details
Salary
$155,000 – $205,000/yr
Experience
Staff · 7+ yrs