Company Name: Nava Job Details: Hiring,Remotely,in,USA,Remote,153K-171K,Annually,Senior,level Job Url: https://builtin.com/job/sr-principal-software-engineer-devsecops-architect/8030212 Job Description: About NavaNava is a consultancy and public benefit corporation working to make government services simple and effective. Since 2015, federal, state, and local agencies have trusted Nava to help solve highly scrutinized technology modernization challenges. As a client services company, we guide agencies constrained by legacy systems to a future with sharp user experiences built on secure, reliable, fault-tolerant cloud infrastructure. We bill for our time, offering our expertise and problem-solving approach to help our government partners enhance their digital products and services. People are at the heart of our work, from members of the public who rely on benefit programs to government agency staff. Through human-centered design and modern engineering best practices, we help our government partners understand user needs and deliver on their missions more effectively. This focus gives everyone at Nava the opportunity to do work that is meaningful, impactful, and deeply connected to public good.Position summaryThe Sr./Principal Software Engineer (DevSecOps Architect) will play a critical role in implementing and maintaining a robust information security program tailored to federal government contracts. This individual will be responsible for ensuring the security, compliance, and integrity of cloud-based solutions—primarily on Amazon Web Services (AWS)—while navigating complex regulatory requirements, including FISMA and NIST. This role supports multiple programs and contributes to strategic business development efforts. The Sr./Principal Software Engineer (DevSecOps Architect) collaborates with cross-functional teams—including engineering, operations, compliance, and leadership—to ensure secure design, development, and deployment of systems across the contract portfolio. The ideal candidate will bring deep expertise in cloud security, government compliance, and modern DevSecOps practices.What you'll doDesign, implement, and maintain the organization’s security architecture in alignment with federal security standards (e.g., FISMA, NIST SP 800-53, 800-171) and contract requirementsLead security planning and risk assessments for government systems hosted in AWSServe as the primary security point of contact for government programs, overseeing incident response, vulnerability management, and system hardening activitiesDevelop and maintain security documentation required for system authorization, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and Continuous Monitoring strategiesSupport the Authority to Operate (ATO) process across multiple projects, working closely with compliance teams, federal partners, and internal stakeholdersArchitect, oversee and support implementation of security controls across AWS services (e.g., IAM, KMS, Security Hub, GuardDuty, CloudTrail, Config, WAF, etc.)Perform regular audits, security assessments, and continuous monitoring to ensure compliance with government standards and internal policiesCollaborate with engineering teams to integrate security into SDLC/DevOps pipelines, using tools such as SonarQube, Snyk, Tenable, and JenkinsLead incident response efforts for government systems, including containment, eradication, and recovery, while maintaining proper documentation and communication protocolsResearch and recommend emerging AWS security services and technologies to improve security posture and maintain complianceMentor junior DevSecOps team members and foster a culture of security-first thinking across the organizationInterface with federal agency stakeholders, auditors, and security assessors to represent the organization’s security practices and compliance effortsParticipate in proposal development and pre-award planning by advising on security architecture and compliance strategies for new federal opportunitiesRequired skillsBachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field5+ years of experience in information security, with at least 2 years supporting federal government contracts and managing system compliance effortsDeep understanding of federal security frameworks, including FISMA, NIST 800-53, 800-171, and FedRAMPHands-on experience managing security for AWS cloud environments, including services such as: IAM, KMS, CloudTrail, Security Hub, GuardDuty, Config, VPC, EC2, Lambda, S3, RDS, DynamoDB, WAF, Shield, Inspector, Secrets ManagerExperience leading or supporting the ATO process, including documentation, control implementation, security testing, and coordination with third-party assessors or agency officialsProficiency in modern DevSecOps toolchains and methodologies (e.g., Terraform, Jenkins, GitHub, New Relic, SonarQube, Snyk, Tenable Nessus)Solid understanding of secure software development principles across languages and frameworks such as Java, Spring Boot, Python, Go, JavaScript/TypeScript, and AngularDemonstrated ability to communicate security concepts to technical and non-technical stakeholdersStrong leadership, analytical, and problem-solving skillsDesired skillsCISSP, CISM, or equivalent federal security certification (e.g., CAP, GSLC)Other requirementsAll roles at Nava require the following:Legal authorization to work in the United StatesAbility to meet any other requirements for government contracts for which candidates are hiredWork authorization that doesn’t require visa sponsorship, now or in the futureMay be subject to a government background check or security clearance, depending on the contractPerks working with NavaHealth coverage — comprehensive medical, dental, and vision plans to support your overall health needsInsurance coverage — Nava provides disability, life, and accidental death insurance at no costTime off — vacation, holidays (including Juneteenth), and floating holidays to rest and rechargeCompany holidays — enjoy 12 paid federal holidays each year on top of your regular PTOAnnual bonus — when Nava meets its goals, eligible employees receive a performance-based annual bonusParental leave — paid time off for new parents, plus weekly meals delivered to your homeWellness program — full platform offering physical, mental, & emotional health resources & support toolsVirtual care — see doctors online with no copay through UnitedHealthcare’s virtual visit programSabbatical leave — earn extended unpaid leave after continuous service for personal growth or rest401(k) match — Nava matches 4% of your salary to support your retirement savings planFlexible work — remote-first environment with flexibility built around your schedule and responsibilitiesHome office setup — company laptop & setup assistance provided via Staples for remote work needsUtility support — monthly reimbursement to help offset eligible home office utility expensesLearning opportunities — internal training programs and resources to help grow your professional skillsDevelopment opportunities — LinkedIn Learning access & an annual allowance for courses, tuition, & certs Referral bonus — get rewarded when you refer great people who join the Nava teamCommuter benefits — pre-tax commuter programs to support in-office travel when applicableSupportive culture — A collaborative and remote-friendly team environment where people genuinely careLocationWe have fully remote options if you reside in one of the following states: Alabama, Arizona, California, Colorado, DC, Delaware, Florida, Georgia, Illinois, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, North Carolina, New Jersey, New York, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Texas, Tennessee, Utah, Virginia, Washington, Wisconsin*If you are not living in one of the states listed above, unfortunately, you will not be considered for a position at this time. Stay in touchSign up for our newsletter to find out about career opportunities, new partnerships, and news from the broader civic tech community. Please contact the recruiting team at recruiting@navapbc.com if you would like to request reasonable accommodation during the application or interviewing process.  We participate in E-Verify. Upon hire, we will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. This role requires you to work from the contiguous United States.