We’re Hiring
USDA PHIS DevSecOps Engineer
Interested in applying? Click button above or email our HR department at HumanResources@visualconnections.net.
Visual Connections, based in Columbia, Maryland, has an exciting opportunity for a DevSecOps Engineer to join our team in a 100% remote role supporting the USDA Food Safety and Inspection Service (FSIS) modernization of the Administrative Enforcement Report (AER) capability within the Public Health Information System (PHIS). This hands-on role is responsible for building secure, repeatable, and auditable software delivery capabilities for a mission-critical Azure Government solution. You will design and operate CI/CD pipelines, automate environment configuration and deployments, integrate security and compliance controls into the software lifecycle, and support releases and issue resolution across development, test, user acceptance, and production environments. You will work closely with developers, architects, database and data specialists, testers, security personnel, operations staff, and PHIS subject matter experts to deliver reliable releases while protecting sensitive Government data and preserving complete traceability.
Essential Job Functions
· Design, implement, and maintain Azure DevOps build and release pipelines for C# and Microsoft ASP.NET Core 8 applications, web assets, APIs, database changes, automated tests, and approved Azure services.
· Automate build, test, package, configuration, deployment, verification, and rollback activities across development, test, user acceptance, staging, and production environments.
· Establish Git repository, branching, pull-request, code-review, versioning, release-tagging, and artifact-retention practices that provide end-to-end traceability from approved backlog item to deployed release.
· Implement gated promotion workflows with required approvals, separation of duties, change records, release-readiness evidence, controlled access, and recoverable rollback procedures.
· Integrate static application security testing, software composition analysis, secrets detection, dependency and license checks, infrastructure-as-code scanning, dynamic testing where appropriate, and other approved security controls into CI/CD pipelines.
· Establish secure software supply-chain practices, including trusted build agents, protected branches, artifact integrity, dependency governance, vulnerability tracking, and software bill of materials generation when required.
· Manage application settings, secrets, certificates, connection information, and environment-specific configuration using Azure Key Vault, Azure App Configuration, approved variable controls, and least-privilege access patterns.
· Automate and support configuration of approved PHIS platform components, including Azure Functions, Storage Accounts, Azure Service Bus, Azure API Management, Azure SQL Managed Instance, Azure Data Factory, and applicable application hosting services.
· Use infrastructure-as-code and configuration-as-code practices to make approved environment changes repeatable, reviewable, version-controlled, and consistent across environments.
· Coordinate with security and identity teams to implement role-based access control, service identities, USDA eAuthentication, PIV/LincPass access, credential rotation, privileged-access controls, and environment access reviews.
· Implement centralized application, API, database, messaging, deployment, and security logging; develop operational dashboards and alerts that support rapid detection, diagnosis, escalation, and audit review.
· Ensure logs and deployment records capture the actor, action, timestamp, environment, release version, approval, outcome, and relevant correlation identifiers without exposing sensitive data or secrets.
· Embed unit, API, integration, Playwright end-to-end, regression, accessibility, security, and performance tests into delivery pipelines and enforce risk-based quality gates before promotion.
· Support Section 508 and WCAG Level A and AA compliance by integrating approved accessibility checks into the build and test process and preserving evidence needed for release acceptance.
· Plan and execute controlled application, API, database-schema, and data-migration releases, including Azure Data Factory jobs, pre-deployment checks, backups, reconciliation, smoke testing, rollback, and post-deployment validation.
· Support performance and load testing with LoadRunner or approved alternatives; analyze telemetry, capacity, bottlenecks, failures, and response times and coordinate corrective action with engineering teams.
· Monitor approved dependencies, platform components, certificates, libraries, agents, and tools for vulnerabilities, expiration, unsupported versions, and configuration drift; coordinate patching and remediation based on risk and release priorities.
· Diagnose and resolve issues across application, API, database, messaging, identity, network, build-agent, and Azure service layers during development, testing, deployment, operations, and the warranty-support period.
· Maintain the Configuration Management Plan, deployment procedures, environment inventories, pipeline documentation, release notes, runbooks, rollback plans, access procedures, audit evidence, and knowledge-transfer materials.
· Participate in Agile ceremonies, refine deployment and security work, estimate tasks, identify dependencies and risks, demonstrate automation, and communicate release status and blockers to Government and contractor stakeholders.
· Mentor developers and technical staff on secure coding, pipeline use, release practices, troubleshooting, configuration management, and operational readiness while continuously improving delivery reliability and lead time.
Minimum Required Qualifications
Bachelor's degree in computer science, information systems, cybersecurity, software engineering, engineering, or a related field and at least four years of relevant DevSecOps, cloud engineering, release engineering, or systems integration experience.
At least three years of hands-on experience building and supporting CI/CD pipelines, automated deployments, source-control workflows, and environment configuration in Azure DevOps or a comparable enterprise platform.
Demonstrated experience integrating automated security testing, secrets protection, dependency governance, vulnerability remediation, and auditable approval controls into a secure software development lifecycle.
Experience deploying and supporting multi-tier .NET, API, database, and Azure workloads in a regulated, high-availability, federal, or similarly controlled enterprise environment.
The ability to successfully complete and maintain the USDA-required suitability determination, background investigation, and access authorization at the NAC or Public Trust level, as determined by the position designation.
Employer-based immigration sponsorship is not available for this role. Candidates must be legally authorized to work in the United States and satisfy applicable USDA residency and suitability requirements.
Knowledge, Skills and Abilities
Advanced proficiency with Azure DevOps Pipelines, Azure Repos or Git, pull-request policies, build artifacts, release approvals, YAML-based pipeline definitions, and deployment troubleshooting.
Strong scripting and automation skills using PowerShell, Bash, Python, or comparable languages and familiarity with the .NET build, package, test, and deployment toolchain.
Hands-on knowledge of Azure Government and services such as Functions, Storage, Key Vault, App Configuration, Service Bus, API Management, Azure SQL Managed Instance, and Data Factory.
Experience with infrastructure-as-code and configuration automation using Bicep, ARM templates, Terraform, or comparable approved technologies.
Working knowledge of SAST, DAST, software composition analysis, secrets scanning, dependency and license governance, artifact integrity, software bills of materials, and vulnerability-management workflows.
Knowledge of identity and access management, RBAC, service principals or managed identities, certificate management, privileged access, PIV or federated identity integration, and least-privilege design.
Experience with Azure-native or approved enterprise monitoring, log aggregation, dashboards, alerting, correlation identifiers, incident diagnosis, capacity analysis, and operational metrics.
Understanding of SQL Server and Azure SQL deployment practices, versioned schema changes, transaction safety, backup and recovery, data-migration cutovers, reconciliation, and rollback planning.
Knowledge of federal secure-development and configuration-management expectations, including NIST-aligned controls, FISMA concepts, auditability, vulnerability remediation, records protection, and separation of duties.
Familiarity with Playwright or comparable test automation, LoadRunner or comparable performance testing, Section 508, WCAG Level A and AA, and automated quality-gate design.
Ability to read and troubleshoot C#/.NET applications, REST APIs, SQL, messaging integrations, and web applications sufficiently to isolate failures and collaborate effectively with full-stack developers.
Excellent analytical, problem-solving, documentation, mentoring, customer-facing, and cross-functional communication skills, including calm and disciplined support during release and incident windows.
Other
This is a 100% remote position with Visual Connections in Columbia, Maryland. Candidates may perform the work remotely from within the United States, subject to project, security, and Government access requirements. Residence in the Washington, DC, Maryland, and Virginia (DMV) region is preferred but not required.
Candidates must be available for virtual collaboration, customer meetings, release, cutover, and production-support activities aligned to Eastern Time business hours. No routine on-site work is required.
Visual Connections, LLC offers a full benefits package including:
Full Medical, Dental, Prescription and Vision health care
11 Paid Holidays annually
Paid time off
Short Term, Long Term Disability and Life Insurance
Employee Assistance Program (EAP)
Training and Development opportunities including professional certification and educational reimbursement
Visual Connections, LLC provides employment opportunities for all employees and applicants in accordance with applicable federal, state and local laws. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
We are a Service-Disabled, Veteran-Owned Small Business; and a Certified Maryland Business Enterprise. We were established in 2007 to provide public and private sector clients with robust web-based applications, Health IT and Portfolio and Program Management services. We have proven ourselves to be valuable partners who can deliver both qualitative and quantitative results to our clients. Our versatile, efficient and experienced team has a stellar record of past performance, working with the Department of Defense (DoD), Department of Health and Human Services (DHHS), Veterans Health Administration (VHA), Centers for Medicare and Medicaid Services (CMS),Centers for Disease Control and Prevention (CDC) and , Blue Cross Blue Shield (BCBS). With an employee base well versed in different disciplines, we are able to deliver high quality customizable solutions.