Logo
SR International

Senior DevSecOps Engineer

SR International, Harrisburg, Pennsylvania, us, 17124

Save Job

Job Description:

This req is available to candidates nationwide, but candidate must be ready to relocate for this hybrid position (60% remote vs. 40% onsite). Candidate must go onsite on their first day to pick up commonwealth-issued equipment, badging, etc. Role contingent on compliant PATCH and passing PSDC/CJIS background checks.

Questions

Q1 - Background Check: This position requires an in-depth background check, including fingerprinting, and requires successful results. Do you accept this requirement?

Q2- Where does your candidate currently reside?

Work Location: Hybrid with two days onsite (1920 Technology Parkway, Mechanicsburg, PA 17050). Schedule can be discussed during interview

PSDC (Public Safety Delivery Center) requires the services of a Senior DevSecOps Engineer to act as consultant with the PSDC Solutions Management group.

Role summary

Hands-on security automation for AWS delivery. Build secure-by-default CDK constructs and CloudFormation templates, wire them into CI/CD, and enforce compliance checks that map to CJIS and NIST. Azure support is a future consideration, not a core day-one duty.

Scope boundaries Does not own enterprise AWS Organizations or SCP operations. Designs and builds reference guardrails and enforcement patterns that can be deployed by enterprise teams. Focuses on preventive controls and compliance automation, not incident response. What you will deliver First 90 days Pipeline security templates in GitHub Actions and Azure DevOps with SAST, SCA, IaC, container, and secret scanning gates. Compliance as code in reference accounts: AWS Config rules and Security Hub standards aligned to CJIS and NIST 800-53, with exceptions workflow documented. IaC reference modules using AWS CDK and CloudFormation for IAM least privilege, KMS, Secrets Manager, logging, and network baselines; Terraform equivalents provided where teams require them. Evidence exports tying checks to control IDs and producing auditor-ready artifacts. Ongoing Harden CDK/CFT modules and pipeline templates as compliance needs evolve. Coach pilot teams to adopt templates. Raise gaps to enterprise teams for org-level enforcement. Day-to-day responsibilities Author and maintain AWS CDK constructs and CloudFormation templates; provide Terraform versions as secondary. Implement AWS Config conformance, Security Hub standards, and GuardDuty routing in reference accounts. Wire scanning in CI/CD for app code, containers, and IaC. Create reusable GitHub/Azure DevOps templates with enforcement gates and exception handling. Generate posture and evidence reports mapped to CJIS and NIST controls. Required skills

5+ years AWS security automation and DevOps. Strong with AWS CDK and CloudFormation; working proficiency in Terraform. CI/CD authoring in GitHub Actions and Azure DevOps. Proficient in Python and Bash, with PowerShell for Windows automation. Able to read Java and C# to integrate and tune SAST/SCA. Practical knowledge of CJIS and NIST 800-53 control families and how to automate checks and evidence. Nice to have

EKS/ECS/Lambda hardening patterns. OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent. Basic Azure security automation for future phases. Decision rights Independent on design and build within standards; proposes guardrails and reference patterns; escalates enterprise-wide changes.

Compensation: $59.00 - $65.00 per hour

About SR International INC

SR International has been a leading name among the IT consulting companies with offices in US and India. For past 16 years, our industry experience and domain knowledge have enabled us to provide innovative solutions to our customers.

Who We Are We Are Leading IT Based Solution Providers

Today, the world of business information represents the realization of our collective efforts toward improving the future. Held only by the limits of our imagination, the business world is accelerating at an ever-increasing pace. Imagine a better way of doing business, of implementing the perfect software, of refining practice or business integration. All it takes are benchmark standards in service, support, and technical know-how, which have been our bread and butter.

Our Vision

Established in 2002, SR International Inc is one of the fastest growing and reputed provider of Information Technology Services and Solutions in the USA. Since our inception, we have been a trusted IT partner for our clients. We take pride in our highly skilled IT Resources and unique engagement model. We have been consistently delivering on our promises as a high-performance team. Our expertise in Cloud Computing, Mobility, Web Technologies, ERP and CRM are second to none. Our industry-leading flagship product iMathSmart is re-defining math learning experience for school students.

Career At SR International

At SR International, we treat our consultants like family. Our business and our reputation have been built and maintained by quality resources working onboard, so it's important for us to maintain the quality resource pool.