Chaos Industries Logo

Chaos Industries

DevSecOps Engineer

Posted 3 Months Ago
Be an Early Applicant
In-Office
El Segundo, CA, USA
110K-160K Annually
Mid level
In-Office
El Segundo, CA, USA
110K-160K Annually
Mid level
Embed security into CI/CD and infrastructure delivery: secure pipelines, automate compliance and vulnerability checks, harden cloud and on-prem systems, manage container/Kubernetes security, support RMF/ATO and authorization boundary requirements, and partner with engineering to shift security left across classified and unclassified environments.
The summary above was generated by AI

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats. 

CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit www.chaosinc.com.

Role Overview:

Chaos Industries is hiring a DevSecOps Engineer to embed security into every layer of our software development and infrastructure delivery lifecycle. This is a broad, hands-on engineering role; you’ll own CI/CD pipeline security, automate compliance and vulnerability checks, harden cloud and on-premise environments, and partner with development and operations teams to make “secure by default” a reality, not a checkbox. You’ll work across classified and unclassified environments, applying the same engineering rigor to security that our developers apply to product - fast, repeatable, and built to scale. 

  • You’ll sit at the intersection of the Engineering and Cybersecurity divisions; collaborating daily with software engineers, cloud architects, ISSMs, and platform teams to keep the development pipeline moving without compromising the security posture. You’re not a gatekeeper; you’re an accelerant who happens to care deeply about what gets through. 
  • From day one you’ll own the security toolchain integrated into our CI/CD pipelines, lead the shift-left security initiative across active development programs, and drive the automation of compliance controls that today require manual effort. Your work directly reduces risk, accelerates delivery, and makes the whole team faster. 

Responsibilities:  

  • Design, implement, and maintain secure CI/CD pipelines integrating automated security scanning tools (SAST, DAST, SCA, secrets detection) across development workflows using GitHub Actions, GitLab CI, Jenkins, or equivalent. 
  • Automate security and compliance controls including STIG/SRG validation, vulnerability scanning (ACAS/Nessus), and policy-as-code enforcement (OPA, Conftest) within pipeline and infrastructure workflows. 
  • Collaborate with software engineers to identify, triage, and remediate application security vulnerabilities; champion secure coding practices, threat modeling, and developer security training across engineering teams. 
  • Build and manage container security posture including image hardening, runtime protection, Kubernetes security configurations (RBAC, Pod Security Admission, network policies), and registry scanning. 
  • Design and maintain infrastructure-as-code (Terraform, CloudFormation, Ansible) with integrated security controls; enforce least-privilege, secrets management (Secrets Manager), and configuration compliance. 
  • Support RMF/ATO activities by automating evidence collection, generating compliance reports, and maintaining continuous monitoring artifacts for cloud and on-premise systems operating within classified or CUI environments. 
  • Monitor security tooling telemetry, pipeline health dashboards, and vulnerability metrics; produce trend reports and actionable remediation backlogs for engineering and security leadership. 
  • Coordinate with ISSM/ISSO teams and system administrators to ensure DevSecOps practices align with authorization boundary requirements, CMMC Level 2/3 controls, and DFARS obligations. 
  • Evaluate and introduce new DevSecOps tooling, frameworks, and practices; build internal documentation, runbooks, and playbooks to operationalize security automation across teams. 
  • Travel up to 15% CONUS to support program site integrations, government customer engagements, and security architecture reviews. 

 Minimum Requirements: 

  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field. Equivalent experience considered. 
  • 4–7 years of experience in DevOps, software engineering, or cybersecurity, with demonstrated hands-on experience integrating security tooling into CI/CD pipelines and cloud environments. 
  • Proficiency in at least one scripting or programming language (Python, Bash, Go, or equivalent) used to build automation, security tooling integrations, or infrastructure-as-code. 
  • Hands-on experience with container technologies (Docker, Kubernetes) including security hardening, image scanning, and runtime protection in a production environment. 
  • Working knowledge of cloud security on AWS GovCloud or Azure Government including IAM, network security groups, security monitoring services, and secrets management. 
  • Familiarity with SAST, DAST, and SCA tooling (SonarQube, Checkmarx, Snyk, OWASP ZAP, Black Duck, or equivalent) and their integration into automated pipelines. 
  • Eligibility for Security Clearance.

Preferred Requirements: 

  • Active TS clearance. 
  • Experience supporting NIST RMF ATO processes for software systems or cloud environments, including automated evidence collection and continuous monitoring workflows.
  • Familiarity with CMMC Level 2/3 practices, DFARS 252.204-7012, and their application to software development and CI/CD pipeline security controls. 
  • Experience with GitOps workflows and policy-as-code frameworks (OPA/Gatekeeper, Kyverno, Conftest) for automated governance enforcement. 
  • Knowledge of software supply chain security practices: SBOM generation, artifact signing (Sigstore/Cosign), and dependency provenance tracking. 
  • Experience operating in classified or air-gapped environments with disconnected CI/CD toolchains and offline artifact repositories. 
  • Relevant certifications: Security+, AWS Security Specialty, or equivalent. 

Why CHAOS?

  • Health Benefits: Medical, dental, and vision benefits 100% paid for by the company
  • Additional benefits: 401k (+ 50% company match up to 6% of pay), FSA, HSA, life insurance, and more
  • Our Perks: Free daily lunch, ‘No meeting Fridays’, unlimited PTO, casual dress code
  • Compensation Components: Competitive base salaries, generous pre-IPO stock option grants, relocation assistance, and (coming soon!) annual bonuses
  • Team Growth: 250 employees and counting across 5 global offices
Salary Range: $110,000 - $160,000

The stated compensation range reflects only the targeted base compensation range and excludes additional earnings such as bonus, equity, and benefits. If your compensation requirements fall outside of the range, we still encourage you to apply. The salary range for this role is an estimate based on a range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. 


Recruiting Agencies: CHAOS Industries does not accept unsolicited resumes or outreach. Unsolicited submissions will not be reviewed or compensated.

#LI-onsite

HQ

Chaos Industries Los Angeles, California, USA Office

Los Angeles, CA, United States

Similar Jobs

23 Days Ago
In-Office
150K-230K Annually
Senior level
150K-230K Annually
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Designs and automates security controls across AWS infrastructure, containers, CI/CD systems, and platform services. Builds hardened container images, integrates vulnerability and configuration scanning, manages secrets and identity controls, automates compliance checks, and supports audit evidence. Diagnoses security weaknesses and drives remediation with engineering teams. At the Staff level, establishes reusable security patterns and promotes adoption across multiple teams while balancing security, reliability, and developer productivity.
Top Skills: AWSBashCi/CdContainerizationGoInfrastructure As CodePython
23 Days Ago
In-Office
180K-280K Annually
Senior level
180K-280K Annually
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Designs and automates security controls across AWS infrastructure, containers, CI/CD systems, and platform services. Builds hardened images, integrates security and compliance scanning, implements secrets and access controls, automates audit evidence and configuration validation, and drives remediation of infrastructure and delivery-system weaknesses. Partners with cybersecurity, infrastructure, build engineering, and product teams to create reusable security patterns and promote secure engineering practices across multiple teams.
Top Skills: AWSBashCi/CdCloud SecurityContainer ScanningContainersDependency ScanningGoIdentity And Access ManagementInfrastructure-As-CodeKubernetesPolicy-As-CodePythonSecrets ManagementSoftware Supply-Chain SecurityVulnerability Scanning
3 Days Ago
In-Office
Los Angeles, CA, USA
140K-160K Annually
Senior level
140K-160K Annually
Senior level
News + Entertainment • Esports
Leads the DevSecOps and SSDLC programs, integrating security into software development, CI/CD pipelines, cloud environments, and deployment platforms. Establishes secure development standards, governs application security tooling, performs threat modeling and code reviews, manages vulnerability remediation, and supports audits and incident response. Partners with Engineering, DevOps, Infrastructure, Platform, and GRC teams to improve security automation, monitoring, compliance, and secure software delivery across globally distributed teams.
Top Skills: Application Security MonitoringAzure DevopsC#Ci/CdCircleCICloud ComputingContainer SecurityContainer TechnologiesDastGithub ActionsInfrastructure MonitoringIso 27001JavaScriptJenkinsLaravelNistNist SsdfOwasp Top 10PHPPythonRubySastScaSoc 2

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account