This is a hands-on build role at the center of a DevSecOps program. The engineer will deploy and operate DefectDojo Pro inside a FedRAMP-authorized AWS environment as the single source of truth for vulnerability findings.
The role involves integrating seven detection sources:
while retiring a legacy multi-hop pipeline (GHAS Splunk Email Jira). The engineer will own all integration code, CI/CD wiring, and automation that moves findings from detection through evaluation to ticketing and reporting.
This position requires deep AWS expertise, robust Python development skills, Kubernetes operational fluency, and experience with security tooling in regulated environments.
Key Responsibilities
- Deploy and operate DefectDojo Pro within a FedRAMP-authorized AWS environment, including:
- IdP/SSO integration
- Security hardening
- Boundary-compliant configuration
- Build and maintain scanner integrations:
- API connectors
- Webhook pipelines
- CI jobs feeding findings from all detection sources into the aggregation platform
- Integrate container scanning into:
- GitHub CI pipelines
- Amazon ECR registry workflows (Trivy)
- Runtime container scanning for EKS/ECS workloads
- Build a runtime reconciliation loop matching scanned images to deployed workloads.
- Implement KEV/EPSS enrichment and internet-reachability tagging.
- Build FedRAMP JSON export services (VDT/AVI/MRH schemas).
- Implement link-only bidirectional Jira synchronization while keeping vulnerability metadata inside the ATO boundary.
- Configure PagerDuty alerting for emergency-patch scenarios (12-hour to 2-day SLAs).
- Decommission the legacy GHAS Splunk Email findings chain and migrate active workflows without losing audit continuity.
- Write infrastructure-as-code, deployment automation, and operational documentation for all components.
Required Skills
- 6+ years of experience in DevOps, DevSecOps, or Platform Engineering with significant security tooling exposure.
- Experience operating security tooling within a FedRAMP or other regulated environment.
- Understanding of
- ATO scope
- Hardening baselines
- Change control
- Familiarity with SBOM formats (CycloneDX).
- Familiarity with VEX, KEV, and EPSS data sources.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.