IT Lead – DevSecOps Engineer
Title:
IT Lead – DevSecOps EngineerAt KBR, we deliver science, technology, and engineering solutions that help governments and companies around the world accomplish their most critical missions and objectives. Our team is committed to innovation, collaboration, and delivering impactful solutions that drive business value.
The Lead DevSecOps Engineer provides technical leadership and strategic direction for integrating security practices across the software development lifecycle, enabling secure, scalable, and compliant application delivery. This role serves as the enterprise leader for DevSecOps platforms and practices, owning the strategy, governance, modernization, and continuous evolution of the DevSecOps toolchain, including Azure DevOps, GitHub, SonarQube, Sonatype, Fortify, Katalon, and OpenShift. The position drives repository and pipeline migrations, strengthens security and quality controls, reduces delivery risk, and advances enterprise capabilities that improve developer experience and support business-critical technology initiatives.
Trinzic is being established as an independent public company through the planned separation of KBR's Mission Technology Solutions business, which is expected to be completed on January 4, 2027. This role offers a rare opportunity to join the organization during a pivotal period of growth and transformation, helping build and support technology strategies, platforms, and practices that will position the company for long-term success while serving critical government and commercial missions around the world.
Key Responsibilities
DevSecOps Leadership & Governance
- Lead the design, implementation, and continuous improvement of secure CI/CD pipelines using Azure DevOps and GitHub Actions.
- Define, implement, and enforce enterprise-wide code quality and application security standards using SonarQube and Fortify.
- Establish and maintain DevSecOps governance, including security gates, policies, standards, and compliance controls.
- Partner with architecture, cybersecurity, infrastructure, and application development teams to embed security throughout the software development lifecycle.
- Provide technical leadership, mentorship, and guidance to engineering and DevOps teams on secure development and DevSecOps best practices.
Security, Quality & Platform Enablement
- Oversee Software Composition Analysis (SCA) practices using Sonatype to identify and manage open-source software risks.
- Lead the development, adoption, and standardization of automated testing frameworks utilizing Katalon or comparable platforms.
- Drive container platform security, governance, and operational best practices within OpenShift environments.
- Oversee vulnerability management activities, including identification, prioritization, remediation planning, and risk reduction efforts.
- Develop and maintain reusable pipeline templates, automation frameworks, and standardized DevSecOps components.
Migration & Platform Transformation
- Lead enterprise repository migrations between development platforms, including Azure DevOps and GitHub, ensuring governance, traceability, and minimal operational disruption.
- Architect and oversee CI/CD pipeline modernization initiatives aligned with enterprise standards and strategic objectives.
- Drive DevSecOps toolchain rationalization and consolidation efforts to improve efficiency, reduce technical debt, and standardize engineering practices.
- Establish migration frameworks, playbooks, and implementation standards to support scalable adoption across the enterprise.
Tool Lifecycle Management & Continuous Modernization
- Own lifecycle management activities for DevSecOps platforms, including upgrades, patching, integrations, and roadmap planning.
- Evaluate, pilot, and deploy emerging technologies and capabilities that advance organizational DevSecOps maturity.
- Ensure platform stability, scalability, performance, and security throughout transformation and modernization initiatives.
- Provide strategic recommendations on DevSecOps tooling investments, architecture decisions, and long-term roadmap development.
- Ensure compliance with internal governance requirements, security policies, and applicable regulatory frameworks while driving continuous improvement in automation and developer experience.
Basic Qualifications
Education & Experience
- Bachelor's degree in Computer Science, Information Security, or a related discipline; equivalent combination of education and experience will be considered.
- Minimum 7 years of experience in DevOps, DevSecOps, software engineering, or related technical disciplines.
- Minimum 2 years of experience in a technical lead, architect, or comparable leadership role.
- Proven experience leading enterprise repository migrations and CI/CD pipeline transformations across development platforms.
- Experience implementing and supporting enterprise-scale automated testing frameworks.
- Experience working with containerized platforms such as OpenShift or Kubernetes.
- Experience supporting cloud-based environments, preferably Microsoft Azure.
Technical Expertise
- Deep expertise with CI/CD platforms and software delivery tooling, including Azure DevOps and GitHub.
- Strong knowledge of application security, code quality, and software composition analysis tools, including SonarQube, Fortify, and Sonatype.
- Strong understanding of secure software development practices and common application security vulnerabilities, including OWASP Top 10 risks.
- Experience designing and implementing enterprise DevSecOps governance frameworks and security controls.
- Proficiency in scripting or programming languages such as PowerShell, Python, Bash, or similar technologies.
Skills & Capabilities
- Demonstrated ability to lead complex technical initiatives across multiple stakeholder groups.
- Strong analytical, problem-solving, and decision-making capabilities.
- Excellent communication and collaboration skills with the ability to influence technical and non-technical audiences.
- Ability to balance strategic planning with hands-on technical execution.
- Strong focus on continuous improvement, automation, operational excellence, and risk management.
Preferred Qualifications
- Experience with GitHub Advanced Security and enterprise repository governance models.
- Experience leading large-scale DevSecOps transformations within global organizations.
- Familiarity with policy-as-code frameworks and technologies such as Open Policy Agent or Azure Policy.
- Professional security certifications such as CISSP, CSSLP, CEH, or equivalent.
- Knowledge of regulatory and compliance frameworks, including NIST, ISO 27001, and SOC 2.
Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together.
KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.