← All jobs

DevSec Ops Engineer

Anduril Industries · Fort Collins, Colorado, United States

onsitefull-timemid level

About this role

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

ABOUT THE TEAM

Anduril's Air & Missile Defense Radar team develops cutting-edge tracking algorithms and software systems that detect, track, and characterize airborne threats in real-time. Working in small, focused teams, our software engineers design and implement sophisticated tracking solutions that protect lives and critical assets. Our work spans the full spectrum—from developing novel multi-target tracking algorithms to building high-performance distributed systems that process massive amounts of sensor data in milliseconds.

ABOUT THE JOB

We are seeking a DevSecOps Engineer to build and maintain the secure automation infrastructure that powers our radar tracking deployments. You'll design CI/CD pipelines, implement Infrastructure-as-Code, and establish continuous compliance workflows that enable our engineering teams to deploy updates rapidly while meeting stringent DoD and IC security requirements.
 

WHAT YOU WILL DO

  • Design and implement secure CI/CD pipelines for classified environments, enabling automated build, test, and deployment of radar tracking software across multiple enclaves
  • Build Infrastructure-as-Code frameworks (Terraform, Ansible, or similar) to provision and configure development, test, and production environments that meet DISA STIG and NIST 800-53 requirements
  • Automate security compliance workflows, including STIG scanning, vulnerability assessment, configuration validation, and compliance reporting for continuous monitoring
  • Develop containerization and orchestration solutions (Docker, Kubernetes) tailored for classified networks with appropriate security hardening
  • Implement secrets management, certificate rotation, and access control systems that balance security with developer productivity
  • Create monitoring and logging infrastructure to support security operations, troubleshooting, and incident response
  • Collaborate with software engineers to optimize build processes, reduce deployment friction, and integrate security controls early in the development lifecycle
  • Support ATO preparation and continuous monitoring by generating compliance artifacts, evidence packages, and security documentation
  • Partner with system administrators and ISSM/ISSO personnel to ensure deployed systems meet customer security requirements 

REQUIRED QUALIFICATIONS

  • 5+ years of experience and a Bachelor's degree in Computer Science, Engineering, Cybersecurity, or related field (or equivalent experience)
  • Strong hands-on experience with CI/CD tools such as GitLab CI, Jenkins, GitHub Actions, or similar
  • Proficiency with Infrastructure-as-Code using Terraform, Ansible, Puppet, Chef, or similar tools
  • Working knowledge of containerization technologies (Docker) and orchestration platforms (Kubernetes, Docker Swarm)
  • Understanding of Linux system administration, networking, and scripting (Python, Bash)
  • Familiarity with DoD security frameworks (RMF, NIST 800-53, DISA STIGs)
  • Ability to obtain and maintain a U.S. Top Secret SCI security clearance

DESIRED QUALIFICATIONS

  • Experience deploying and maintaining systems in classified DoD or IC environments
  • Hands-on experience with ATO processes, STIG implementation, and continuous monitoring for accredited systems
  • Familiarity with SCAP-compliant scanning tools (OpenSCAP, Nessus, ACAS) and automated compliance frameworks
  • Experience with secure software supply chain practices, artifact signing, and software bill of materials (SBOM)
  • Knowledge of zero-trust architectures and microsegmentation in Kubernetes environments
  • Experience with GitOps workflows and declarative infrastructure management
  • Proficiency with observability and monitoring tools (Prometheus, Grafana, ELK stack, Splunk)
  • Understanding of PKI, certificate management, and secrets management solutions (Vault, AWS Secrets Manager)
  • Experience with air-gapped or disconnected network deployments
  • Familiarity with real-time or embedded systems and their unique deployment constraints
  • Active U.S. Top Secret SCI clearance
  • Relevant certifications such as Security+, CISSP, or AWS/Azure security certifications
US Salary Range
$111,000—$147,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including: 

Healthcare Benefits 

  • US Roles: Comprehensive medical, dental, and vision plans at little to no cost to you. 
  • UK & AUS Roles: We cover full cost of medical insurance premiums for you and your dependents. 
  • IE Roles: We offer an annual contribution toward your private health insurance for you and your dependents. 

Additional Benefits 

  • Income Protection: Anduril covers life and disability insurance for all employees. 
  • Generous time off: Highly competitive PTO plans with a holiday hiatus in December. Caregiver & Wellness Leave is available to care for family members, bond with a new baby, or address your own medical needs. 
  • Family Planning & Parenting Support: Coverage for fertility treatments (e.g., IVF, preservation), adoption, and gestational carriers, along with resources to support you and your partner from planning to parenting. 
  • Mental Health Resources: Access free mental health resources 24/7, including therapy and life coaching. Additional work-life services, such as legal and financial support, are also available. 
  • Professional Development: Annual reimbursement for professional development 
  • Commuter Benefits: Company-funded commuter benefits based on your region. 
  • Relocation Assistance: Available depending on role eligibility. 

Retirement Savings Plan 

  • US Roles: Traditional 401(k), Roth, and after-tax (mega backdoor Roth) options. 
  • UK & IE Roles: Pension plan with employer match. 
  • AUS Roles: Superannuation plan. 

The recruiter assigned to this role can share more information about the specific compensation and benefit details associated with this role during the hiring process. 

 

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:

  • No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:
    • Direct from Anduril: Our recruiters will only email you from an @anduril.com address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to contact@anduril.com
  • Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy

To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/

Jobb.ai is an independent skill benchmarking platform. Applications are submitted on the employer's official website.