DevSecOps Engineer
Job Description
About the Job
Illuminate Technologies (ILT) is a defense technology company in Herndon, VA, founded by special operations and intelligence community veterans, delivering telecommunications intelligence, network security, and multi-INT fusion capabilities for national security customers. Unlike many contractors, our engineers don't hand off a spec and walk away — they build, deploy, and operate what they design.
We're hiring a DevSecOps Engineer to work directly with our CTO on the production infrastructure behind our customer-facing platforms. This is a hands-on engineering role on a small, fast-moving team that ships to production on a weekly cadence, not a quarterly one. You'll own your work end-to-end: architecting it, building it, deploying it, and keeping it running.
Day to day, that means building and deploying services on our Kubernetes-based platform, hardening the security of what you ship as part of the feature itself rather than a follow-on task, and operating the core infrastructure the platform depends on. You'll also help translate that engineering work into the compliance evidence our government customers require, including NIST SP 800-171 and CMMC Level 2.
Why Illuminate
At Illuminate, you won't build something and hand it off for someone else to run. You'll carry your work from architecture decision through production operation, with a direct line to the CTO and none of the layered approvals that slow larger teams down. This is a small, high-autonomy team that measures success by what shipped and whether it stayed up. If you want your engineering judgment to matter and your work to be visible right away, this is it.
What Success Looks Like
At 90 days, a successful hire is fully ramped on our platform and stack, shipping features independently, and has taken ownership of at least one meaningful piece of our security or compliance posture — for example, hardening a service end-to-end or standing up a new audit-logging capability. They understand our ship cadence, our tooling, and what “production-ready” means on this team.
At 12 months, they're a trusted, autonomous member of the engineering team — driving architecture decisions, owning the security posture of major parts of the platform, and contributing directly to our NIST SP 800-171 and CMMC Level 2 compliance work. They're someone the CTO relies on to take a problem from idea to production without hand-holding.
Core Requirements
• Location: Remote-first, based out of our Herndon, VA office, with occasional on-site work expected.
• Eligibility: This position is open to U.S. Persons only, as defined by applicable export control regulations.
Responsibilities
Platform Engineering & Delivery
• Build and deploy backend services in Python (FastAPI) and/or TypeScript (Next.js), running on our Kubernetes-based platform and packaged with Helm.
• Maintain a fast, disciplined ship cadence — plan, build, deploy, and verify changes, often within the same day.
• Operate the core infrastructure the platform depends on, including PostgreSQL, object storage, vector search, and workflow orchestration.
• Manage the underlying Kubernetes cluster: networking, storage, ingress, and certificate management.
Security & Compliance
• Own the security posture of what you build: secrets management, mutual TLS, restricted pod security, network policy, RBAC, and audit logging.
• Build in defenses against common web application risks, including CSRF, SSRF, and XSS.
• Generate compliance evidence as code — audit trails, drift detection, and documentation aligned to NIST SP 800-171 and CMMC Level 2.
• Document architecture decisions clearly, so the reasoning behind changes is easy to follow later.
Qualifications
Core Qualifications
• Production experience running services on Kubernetes, including authoring Helm charts yourself, not just deploying ones someone else wrote.
• Strong backend development experience in Python (FastAPI) and/or TypeScript (Next.js / React).
• Hands-on experience with core infrastructure components such as Vault, PostgreSQL, object storage (e.g., MinIO or S3), and certificate management.
• Practical, applied security experience: authentication and authorization, RBAC, secure coding practices, and supply-chain security.
• Familiarity with NIST SP 800-171, DFARS 252. 204-7012, and CMMC Level 2, or the discipline to get up to speed on them quickly.
• Must be a U.S. Person, as defined by applicable export control regulations.
Preferred Qualifications
• Experience with Go, particularly in data-plane or infrastructure contexts.
• Familiarity with modern AI infrastructure and tooling, such as self-hosted model inference or agent frameworks.
• A visible track record of independent technical work: public repositories, technical write-ups, talks, or projects you can speak to in detail.
• Experience with supply-chain security practices such as artifact signing and provenance attestation.
The Stack
For reference, here's what you'd actually be working with day to day:
Talos Kubernetes · Cilium · Helm · Forgejo CI · HashiCorp Vault · Cloud Native PostgreSQL · MinIO · Qdrant · Temporal · Langfuse · LiteLLM · Ollama · cert-manager · ingress-nginx · Cloudflare Tunnel · Next.js · FastAPI · OSCAL-based compliance tooling
If you've shipped against most of this list in production, we'd like to talk.
Illuminate provides government agencies, commercial enterprises, and network operators with the data, services, and technology that helps them protect the information that surrounds us all and extract real value from it. We combine decades of cyber, intelligence and telecommunications expertise with innovative collection and analysis tools to deliver timely, actionable insight that our customers use to make fast, informed decisions.