IT Lead – DevSecOps Engineer
KBR
- Location
- Chantilly, Virginia
- Work model
- On-Site
- Level
- Senior
- Posted
- Aug 20, 2026
Skills
About this role
Title: IT Lead – DevSecOps Engineer At KBR, we deliver science, technology, and engineering solutions that help governments and companies around the world accomplish their most critical missions and objectives. Our team is committed to innovation, collaboration, and delivering impactful solutions that drive business value. The Lead DevSecOps Engineer provides technical leadership and strategic direction for integrating security practices across the software development lifecycle, enabling secure, scalable, and compliant application delivery. This role serves as the enterprise leader for DevSecOps platforms and practices, owning the strategy, governance, modernization, and continuous evolution of the DevSecOps toolchain, including Azure DevOps, GitHub, SonarQube, Sonatype, Fortify, Katalon, and OpenShift. The position drives repository and pipeline migrations, strengthens security and quality controls, reduces delivery risk, and advances enterprise capabilities that improve developer experience and support business-critical technology initiatives. Trinzic is being established as an independent public company through the planned separation of KBR's Mission Technology Solutions business, which is expected to be completed on January 4, 2027. This role offers a rare opportunity to join the organization during a pivotal period of growth and transformation, helping build and support technology strategies, platforms, and practices that will position the company for long-term success while serving critical government and commercial missions around the world.
Key Responsibilities
DevSecOps Leadership & Governance Lead the design, implementation, and continuous improvement of secure CI/CD pipelines using Azure DevOps and GitHub Actions. Define, implement, and enforce enterprise-wide code quality and application security standards using SonarQube and Fortify. Establish and maintain DevSecOps governance, including security gates, policies, standards, and compliance controls. Partner with architecture, cybersecurity, infrastructure, and application development teams to embed security throughout the software development lifecycle. Provide technical leadership, mentorship, and guidance to engineering and DevOps teams on secure development and DevSecOps best practices. Security, Quality & Platform Enablement Oversee Software Composition Analysis (SCA) practices using Sonatype to identify and manage open-source software risks. Lead the development, adoption, and standardization of automated testing frameworks utilizing Katalon or comparable platforms. Drive container platform security, governance, and operational best practices within OpenShift environments. Oversee vulnerability management activities, including identification, prioritization, remediation planning, and risk reduction efforts. Develop and maintain reusable pipeline templates, automation frameworks, and standardized DevSecOps components. Migration & Platform Transformation Lead enterprise repository migrations between development platforms, including Azure DevOps and GitHub, ensuring governance, traceability, and minimal operational disruption. Architect and oversee CI/CD pipeline modernization initiatives aligned with enterprise standards and strategic objectives. Drive DevSecOps toolchain rationalization and consolidation efforts to improve efficiency, reduce technical debt, and standardize engineering practices. Establish migration frameworks, playbooks, and implementation standards to support scalable adoption across the enterprise. Tool Lifecycle Management & Continuous Modernization Own lifecycle management activities for DevSecOps platforms, including upgrades, patching, integrations, and roadmap planning. Evaluate, pilot, and deploy emerging technologies and capabilities that advance organizational DevSecOps maturity. Ensure platform stability, scalability, performance, and security throughout transformation and modernization initiatives. Provide strategic