About the job
Join our dynamic team at Spear AI as a DevSecOps Engineer, where you will play a key role in designing, implementing, and managing secure DevSecOps pipelines and cloud infrastructure tailored for an Intelligence Community (IC) customer operating on MSIC Cloud infrastructure.
At Spear AI, we pride ourselves on being a forward-thinking defense contracting company, committed to delivering innovative solutions that bolster our nation's security. As we continue to grow, we are cultivating a culture where creativity meets mission-critical work. Our flat organizational structure empowers every team member to make a significant impact, collaborate directly with leadership, and contribute to vital projects. Regardless of your division—be it Hardware, Software, or Services—you will join a talented group dedicated to excellence and advancing capabilities that ensure our nation remains safe and secure.
We specialize in developing sonobuoy sensors that are deployed into water to collect edge data, and we partner with the U.S. Navy to analyze SONAR data. This role offers you the chance to engage in meaningful projects that have a direct impact on warfighter capabilities and mission success.
Key Responsibilities
As a crucial member of our small team, your responsibilities will include:
Designing, building, and maintaining secure CI/CD pipelines for AI/ML applications on MSIC Cloud (AWS GovCloud and Azure Government).
Integrating automated security testing, static/dynamic analysis, and compliance checks (SAST, DAST, SCA) throughout the software delivery lifecycle.
Implementing and managing Infrastructure as Code (IaC) using tools like Terraform, CloudFormation, or Bicep for classified cloud environments.
Ensuring compliance of cloud infrastructure and containerized workloads (Kubernetes, Docker) with applicable STIGs, CIS Benchmarks, and IC security requirements.
Collaborating with ISSOs and ISSMs to support ATO processes, continuous monitoring, and the implementation of security controls for cloud-hosted systems.
Developing and maintaining automated compliance monitoring, audit logging, and alerting capabilities across AWS and Azure environments.
Implementing best practices for container security, secrets management, and identity/access management (IAM) for classified cloud workloads.
Supporting the migration and deployment of AI/ML workloads to classified cloud environments, with a focus on performance, scalability, and security.
Maintaining comprehensive DevSecOps documentation, runbooks, and architectural diagrams for classified cloud platforms.

