IT Lead - DevSecOps Engineer
IT Lead - DevSecOps Engineer At KBR, we deliver science, technology, and engineering solutions that help governments and companies around the world accomplish their most critical missions and objectives. Our team is committed to innovation, collaboration, and delivering impactful solutions that drive business value. The Lead DevSecOps Engineer provides technical leadership and strategic direction for integrating security practices across the software development lifecycle, enabling secure, scalable, and compliant application delivery. This role serves as the enterprise leader for DevSecOps platforms and practices, owning the strategy, governance, modernization, and continuous evolution of the DevSecOps toolchain, including Azure DevOps, GitHub, SonarQube, Sonatype, Fortify, Katalon, and OpenShift. The position drives repository and pipeline migrations, strengthens security and quality controls, reduces delivery risk, and advances enterprise capabilities that improve developer experience and support business-critical technology initiatives. Trinzic is being established as an independent public company through the planned separation of KBR's Mission Technology Solutions business, which is expected to be completed on January 4, 2027. This role offers a rare opportunity to join the organization during a pivotal period of growth and transformation, helping build and support technology strategies, platforms, and practices that will position the company for long-term success while serving critical government and commercial missions around the world. Key Responsibilities DevSecOps Leadership & Governance
- Lead the design, implementation, and continuous improvement of secure CI/CD pipelines using Azure DevOps and GitHub Actions.
- Define, implement, and enforce enterprise-wide code quality and application security standards using SonarQube and Fortify.
- Establish and maintain DevSecOps governance, including security gates, policies, standards, and compliance controls.
- Partner with architecture, cybersecurity, infrastructure, and application development teams to embed security throughout the software development lifecycle.
- Provide technical leadership, mentorship, and guidance to engineering and DevOps teams on secure development and DevSecOps best practices.
- Oversee Software Composition Analysis (SCA) practices using Sonatype to identify and manage open-source software risks.
- Lead the development, adoption, and standardization of automated testing frameworks utilizing Katalon or comparable platforms.
- Drive container platform security, governance, and operational best practices within OpenShift environments.
- Oversee vulnerability management activities, including identification, prioritization, remediation planning, and risk reduction efforts.
- Develop and maintain reusable pipeline templates, automation frameworks, and standardized DevSecOps components.
- Lead enterprise repository migrations between development platforms, including Azure DevOps and GitHub, ensuring governance, traceability, and minimal operational disruption.
- Architect and oversee CI/CD pipeline modernization initiatives aligned with enterprise standards and strategic objectives.
- Drive DevSecOps toolchain rationalization and consolidation efforts to improve efficiency, reduce technical debt, and standardize engineering practices.
- Establish migration frameworks, playbooks, and implementation standards to support scalable adoption across the enterprise.
- Own lifecycle management activities for DevSecOps platforms, including upgrades, patching, integrations, and roadmap planning.
- Evaluate, pilot, and deploy emerging technologies and capabilities that advance organizational DevSecOps maturity.
- Ensure platform stability, scalability, performance, and security throughout transformation and modernization initiatives.
- Provide strategic recommendations on DevSecOps tooling investments, architecture decisions, and long-term roadmap development.
- Ensure compliance with internal governance requirements, security policies, and applicable regulatory frameworks while driving continuous improvement in automation and developer experience.
- Bachelor's degree in Computer Science, Information Security, or a related discipline; equivalent combination of education and experience will be considered.
- Minimum 7 years of experience in DevOps, DevSecOps, software engineering, or related technical disciplines.
- Minimum 2 years of experience in a technical lead, architect, or comparable leadership role.
- Proven experience leading enterprise repository migrations and CI/CD pipeline transformations across development platforms.
- Experience implementing and supporting enterprise-scale automated testing frameworks.
- Experience working with containerized platforms such as OpenShift or Kubernetes.
- Experience supporting cloud-based environments, preferably Microsoft Azure.
- Deep expertise with CI/CD platforms and software delivery tooling, including Azure DevOps and GitHub.
- Strong knowledge of application security, code quality, and software composition analysis tools, including SonarQube, Fortify, and Sonatype.
- Strong understanding of secure software development practices and common application security vulnerabilities, including OWASP Top 10 risks.
- Experience designing and implementing enterprise DevSecOps governance frameworks and security controls.
- Proficiency in scripting or programming languages such as PowerShell, Python, Bash, or similar technologies.
- Demonstrated ability to lead complex technical initiatives across multiple stakeholder groups.
- Strong analytical, problem-solving, and decision-making capabilities.
- Excellent communication and collaboration skills with the ability to influence technical and non-technical audiences.
- Ability to balance strategic planning with hands-on technical execution.
- Strong focus on continuous improvement, automation, operational excellence, and risk management.
- Experience with GitHub Advanced Security and enterprise repository governance models.
- Experience leading large-scale DevSecOps transformations within global organizations.
- Familiarity with policy-as-code frameworks and technologies such as Open Policy Agent or Azure Policy.
- Professional security certifications such as CISSP, CSSLP, CEH, or equivalent.
- Knowledge of regulatory and compliance frameworks, including NIST, ISO 27001, and SOC 2.
Recommended Jobs
Land Survey - Assistant Project Manager
Control Point Associates is seeking an experienced Assistant Project Manager in our Virginia Beach, VA office. Competitive pay, excellent benefits, an amazing team, and endless opportunities for …
OTR Flatbed Company driver Job in Harrisonburg, VA by Eclectic Logistics
Requirements No more than two moving violations (last 3 years) No more than one accident (last 3 years) No more than 3 job changes per year No positive drug results in the past - no refusal…
Data Analyst
Data Analyst Position Description CGI Federal is seeking a Data Analyst to collect, analyze, and visualize data to support client decision making and operational improvements. You will work with…
Senior Manager, GPN Information Security Office Consultant
Overview Senior Manager, GPN Information Security Office Consultant At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. Yo…
Entry-Level Freight Dispatcher - $1,200-$2,500 Weekly
ntry-Level Freight Dispatcher – $1,200–$2,500 Weekly We are seeking reliable and organized individuals for an Entry-Level Freight Dispatcher opportunity. This is an independent contractor role …
Experienced Medical Assistant
Job Description Job Description Experienced Medical Assistant – Spine Surgery Practice Location: Northern Virginia (Sterling / Annandale) Position Type: Full-Time About Us We are …
Onsite Support Lead, Senior
Onsite Support Lead, Senior Position Description CGI Federal has an exciting opportunity for an Onsite Support Lead within our Intel sector advancing the national security mission through cuttin…
Energy Engineer Discipline Lead
Energy Engineering Discipline Lead CEG Solutions is hiring an Energy Engineering Discipline Lead to provide senior technical leadership for our energy engineering practice. This role will impact…
Customer Service Representative
Job Description Job Description Benefits/Perks Competitive Pay Professional Development Job Stability in a growing industry Job Description We are seeking a professional and person…
Part-Time Restaurant Assistant Manager
Apply in ~60 Seconds Join Our Team: A career at Cinemark means you'll have epic opportunities to immerse yourself in our industry. But that's just the beginning — a front row seat means incredi…