

DevOps Engineer
β - Featured Role | Apply direct with Data Freelance Hub
This role is for a Senior DevSecOps Engineer with 8 years of experience, offering a 12-month hybrid contract in Cumberland County, PA. Key skills include AWS security automation, CDK, CloudFormation, CI/CD, and familiarity with CJIS and NIST standards. Pay rate is unspecified.
π - Country
United States
π± - Currency
$ USD
-
π° - Day rate
-
ποΈ - Date discovered
September 27, 2025
π - Project duration
More than 6 months
-
ποΈ - Location type
Hybrid
-
π - Contract type
Unknown
-
π - Security clearance
Unknown
-
π - Location detailed
Cumberland County, PA
-
π§ - Skills detailed
#DevSecOps #Azure Security #DevOps #AWS (Amazon Web Services) #Infrastructure as Code (IaC) #Containers #Bash #Cloud #Lambda (AWS Lambda) #Python #Azure #Security #Automation #Java #Compliance #Azure DevOps #C# #GitHub #Terraform
Role description
Job Title: Senior DevSecOps Engineer
Experience: 8 years
Location: Cumberland County, PA (Hybrid β 2 days onsite)
Duration: 12 Months Contract
Key Responsibilities
Hands-on security automation for AWS delivery. Build secure-by-default CDK constructs and CloudFormation templates, wire them into CI/CD, and enforce compliance checks that map to CJIS and NIST. Azure support is a future consideration, not a core day-one duty.
Scope boundaries
β’ Does not own enterprise AWS Organizations or SCP operations.
β’ Designs and builds reference guardrails and enforcement patterns that can be deployed by enterprise teams.
β’ Focuses on preventive controls and compliance automation, not incident response.
β’ What you will deliver
Day-to-day responsibilities
β’ Author and maintain AWS CDK constructs and CloudFormation templates; provide Terraform versions as secondary.
β’ Implement AWS Config conformance, Security Hub standards, and GuardDuty routing in reference accounts.
β’ Wire scanning in CI/CD for app code, containers, and IaC.
β’ Create reusable GitHub/Azure DevOps templates with enforcement gates and exception handling.
β’ Generate posture and evidence reports mapped to CJIS and NIST controls.
Required skills
β’ 5+ years AWS security automation and DevOps.
β’ Strong with AWS CDK and CloudFormation; working proficiency in Terraform.
β’ CI/CD authoring in GitHub Actions and Azure DevOps.
β’ Proficient in Python and Bash, with PowerShell for Windows automation.
β’ Able to read Java and C# to integrate and tune SAST/SCA.
β’ Practical knowledge of CJIS and NIST 800-53 control families and how to automate checks and evidence.
Nice to have
β’ EKS/ECS/Lambda hardening patterns.
β’ OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent.
β’ Basic Azure security automation for future phases.
β’ Decision rights
Job Title: Senior DevSecOps Engineer
Experience: 8 years
Location: Cumberland County, PA (Hybrid β 2 days onsite)
Duration: 12 Months Contract
Key Responsibilities
Hands-on security automation for AWS delivery. Build secure-by-default CDK constructs and CloudFormation templates, wire them into CI/CD, and enforce compliance checks that map to CJIS and NIST. Azure support is a future consideration, not a core day-one duty.
Scope boundaries
β’ Does not own enterprise AWS Organizations or SCP operations.
β’ Designs and builds reference guardrails and enforcement patterns that can be deployed by enterprise teams.
β’ Focuses on preventive controls and compliance automation, not incident response.
β’ What you will deliver
Day-to-day responsibilities
β’ Author and maintain AWS CDK constructs and CloudFormation templates; provide Terraform versions as secondary.
β’ Implement AWS Config conformance, Security Hub standards, and GuardDuty routing in reference accounts.
β’ Wire scanning in CI/CD for app code, containers, and IaC.
β’ Create reusable GitHub/Azure DevOps templates with enforcement gates and exception handling.
β’ Generate posture and evidence reports mapped to CJIS and NIST controls.
Required skills
β’ 5+ years AWS security automation and DevOps.
β’ Strong with AWS CDK and CloudFormation; working proficiency in Terraform.
β’ CI/CD authoring in GitHub Actions and Azure DevOps.
β’ Proficient in Python and Bash, with PowerShell for Windows automation.
β’ Able to read Java and C# to integrate and tune SAST/SCA.
β’ Practical knowledge of CJIS and NIST 800-53 control families and how to automate checks and evidence.
Nice to have
β’ EKS/ECS/Lambda hardening patterns.
β’ OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent.
β’ Basic Azure security automation for future phases.
β’ Decision rights