Himalayas logo
NavaNA

Sr./Principal Software Engineer (DevSecOps Architect)

Nava PBC is a public benefit corporation that partners with government agencies to build transformative digital services, making public benefits simple, effective, and accessible to all. They emerged from the effort to fix HealthCare.gov and now work on a variety of complex modernization projects for federal, state, and local governments.

Nava

Employee count: 501-1000

Salary: 153k-171k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About Nava

Nava is a consultancy and public benefit corporation working to make government services simple and effective. Since 2015, federal, state, and local agencies have trusted Nava to help solve highly scrutinized technology modernization challenges.
As a client services company, we guide agencies constrained by legacy systems to a future with sharp user experiences built on secure, reliable, fault-tolerant cloud infrastructure. We bill for our time, offering our expertise and problem-solving approach to help our government partners enhance their digital products and services. People are at the heart of our work, from members of the public who rely on benefit programs to government agency staff. Through human-centered design and modern engineering best practices, we help our government partners understand user needs and deliver on their missions more effectively. This focus gives everyone at Nava the opportunity to do work that is meaningful, impactful, and deeply connected to public good.

Position summary

The Sr./Principal Software Engineer (DevSecOps Architect) will play a critical role in implementing and maintaining a robust information security program tailored to federal government contracts. This individual will be responsible for ensuring the security, compliance, and integrity of cloud-based solutions—primarily on Amazon Web Services (AWS)—while navigating complex regulatory requirements, including FISMA and NIST.
This role supports multiple programs and contributes to strategic business development efforts. The Security Architect collaborates with cross-functional teams—including engineering, operations, compliance, and leadership—to ensure secure design, development, and deployment of systems across the contract portfolio. The ideal candidate will bring deep expertise in cloud security, government compliance, and modern DevSecOps practices.

What you'll do

  • Design, implement, and maintain the organization’s security architecture in alignment with federal security standards (e.g., FISMA, NIST SP 800-53, 800-171) and contract requirements
  • Lead security planning and risk assessments for government systems hosted in AWS
  • Serve as the primary security point of contact for government programs, overseeing incident response, vulnerability management, and system hardening activities
  • Develop and maintain security documentation required for system authorization, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and Continuous Monitoring strategies
  • Support the Authority to Operate (ATO) process across multiple projects, working closely with compliance teams, federal partners, and internal stakeholders
  • Architect, oversee and support implementation of security controls across AWS services (e.g., IAM, KMS, Security Hub, GuardDuty, CloudTrail, Config, WAF, etc.)
  • Perform regular audits, security assessments, and continuous monitoring to ensure compliance with government standards and internal policies
  • Collaborate with engineering teams to integrate security into SDLC/DevOps pipelines, using tools such as SonarQube, Snyk, Tenable, and Jenkins
  • Lead incident response efforts for government systems, including containment, eradication, and recovery, while maintaining proper documentation and communication protocols
  • Research and recommend emerging AWS security services and technologies to improve security posture and maintain compliance
  • Mentor junior DevSecOps team members and foster a culture of security-first thinking across the organization
  • Interface with federal agency stakeholders, auditors, and security assessors to represent the organization’s security practices and compliance efforts
  • Participate in proposal development and pre-award planning by advising on security architecture and compliance strategies for new federal opportunities

Required skills

  • Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field
  • 5+ years of experience in information security, with at least 2 years supporting federal government contracts and managing system compliance efforts
  • Deep understanding of federal security frameworks, including FISMA, NIST 800-53, 800-171, and FedRAMP
  • Hands-on experience managing security for AWS cloud environments, including services such as: IAM, KMS, CloudTrail, Security Hub, GuardDuty, Config, VPC, EC2, Lambda, S3, RDS, DynamoDB, WAF, Shield, Inspector, Secrets Manager
  • Experience leading or supporting the ATO process, including documentation, control implementation, security testing, and coordination with third-party assessors or agency officials
  • Proficiency in modern DevSecOps toolchains and methodologies (e.g., Terraform, Jenkins, GitHub, New Relic, SonarQube, Snyk, Tenable Nessus)
  • Solid understanding of secure software development principles across languages and frameworks such as Java, Spring Boot, Python, Go, JavaScript/TypeScript, and Angular
  • Demonstrated ability to communicate security concepts to technical and non-technical stakeholders
  • Strong leadership, analytical, and problem-solving skills

Desired skills

  • CISSP, CISM, or equivalent federal security certification (e.g., CAP, GSLC)

Other requirements

All roles at Nava require the following:

Legal authorization to work in the United States
Ability to meet any other requirements for government contracts for which candidates are hired
Work authorization that doesn’t require visa sponsorship, now or in the future
May be subject to a government background check or security clearance, depending on the contract

Perks working with Nava

Health coverage — comprehensive medical, dental, and vision plans to support your overall health needs
Insurance coverageNava provides disability, life, and accidental death insurance at no cost
Time off — vacation, holidays (including Juneteenth), and floating holidays to rest and recharge
Company holidays — enjoy 12 paid federal holidays each year on top of your regular PTO
Annual bonus — when Nava meets its goals, eligible employees receive a performance-based annual bonus
Parental leave — paid time off for new parents, plus weekly meals delivered to your home
Wellness program — full platform offering physical, mental, & emotional health resources & support tools
Virtual care — see doctors online with no copay through UnitedHealthcare’s virtual visit program
Sabbatical leave — earn extended unpaid leave after continuous service for personal growth or rest
401(k) matchNava matches 4% of your salary to support your retirement savings plan
Flexible work — remote-first environment with flexibility built around your schedule and responsibilities
Home office setup — company laptop & setup assistance provided via Staples for remote work needs
Utility support — monthly reimbursement to help offset eligible home office utility expenses
Learning opportunities — internal training programs and resources to help grow your professional skills
Development opportunities — LinkedIn Learning access & an annual allowance for courses, tuition, & certs
Referral bonus — get rewarded when you refer great people who join the Nava team
Commuter benefits — pre-tax commuter programs to support in-office travel when applicable
Supportive culture — A collaborative and remote-friendly team environment where people genuinely care

Location

We have fully remote options if you reside in one of the following states:
Alabama, Arizona, California, Colorado, DC, Delaware, Florida, Georgia, Illinois, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, North Carolina, New Jersey, New York, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Texas, Tennessee, Utah, Virginia, Washington, Wisconsin
*If you are not living in one of the states listed above, unfortunately, you will not be considered for a position at this time.

Stay in touch

Sign up for our newsletter to find out about career opportunities, new partnerships, and news from the broader civic tech community.
Please contact the recruiting team at recruiting@navapbc.com if you would like to request reasonable accommodation during the application or interviewing process.
We participate in E-Verify. Upon hire, we will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. This role requires you to work from the contiguous United States.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Salary

Salary: 153k-171k USD

Location requirements

Hiring timezones

United States +/- 0 hours

About Nava

Learn more about Nava and their company culture.

View company profile

At Nava PBC, we are at the forefront of revolutionizing how government serves its people through groundbreaking technology and human-centered design. Our journey began with the pivotal effort to rescue and rebuild HealthCare.gov after its challenging launch in 2013. This experience solidified our mission: to make public services simple, effective, and accessible to all. Since our incorporation as a public benefit corporation in 2015, Nava has been entrusted by federal, state, and local government agencies across the United States to tackle some of the most complex and highly scrutinized technology modernization efforts. We guide agencies constrained by legacy systems toward a future defined by sharp user experiences, all built upon secure, reliable, and fault-tolerant cloud infrastructure. Our approach is rooted in a deep understanding of user needs, which we achieve through comprehensive research and an iterative development process. This ensures that the digital services we build are not only technologically advanced but also intuitive and genuinely helpful to the millions of Americans who rely on them.

Our commitment to innovation extends beyond simply fixing broken systems; we aim to build lasting solutions that enhance the adaptability and responsiveness of public programs in an ever-evolving world. We have a proven track record of delivering impactful results, having supported the disbursement of over three billion in payments and saved over 500,000 hours of manual labor for civil servants. Key projects include modernizing federal grant-making with the Department of Health and Human Services, improving tools for Veterans to submit benefits claims with the Department of Veterans Affairs, and helping the Commonwealth of Massachusetts adapt its Paid Family and Medical Leave program to new legislation through agile development. We also leverage emerging technologies, such as generative AI, to pilot new tools that can further streamline and improve public benefit programs. At Nava, we believe that by strengthening the digital foundations of critical government programs, we can restore trust between people and public institutions, ensuring that services are not just delivered, but are delivered with empathy and efficiency.

Employee benefits

Learn about the employee benefits and perks provided at Nava.

View benefits

401k salary match

4% 401k salary match.

Commuter benefits

Commuter benefits available.

Home office funding

Funding for home office setup.

Mental health support

Access to mental health support.

View Nava's employee benefits
Claim this profileNava logoNA

Nava

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

23 remote jobs at Nava

Explore the variety of open remote roles at Nava, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Nava

Remote companies like Nava

Find your next opportunity by exploring profiles of companies that are similar to Nava. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan