My wife also works for a defense contractor. Our nightly conversations kind of get tiring because virtually all she ever does is complain about it. They moved at some point away from including detailed requirements and specific feature sets in contracts to instead purchasing, I believe at this point in 12-week at a time intervals, some number of "story points," where story point is defined to be some number of labor hours at an average rate, rather than an actual story point. So what happens is the government and contractor work together to establish some backlog of possible features they might want, and I think quarterly, developers have to hold some ceremonies giving very rough estimates of how many story points each of these might be worth, even though at this point they are not discretized into user stories. Moreover, everyone has to do this, so even if you have some team whose main purpose is onboarding new users and providing maintenance and support of a development environment, they have to estimate workload in terms of stories and story points and burn these down as they respond to ad hoc support tickets.
Moreover, since they're "agile," they no longer have any kind of dedicated testing teams, so developers are responsible for creating and maintaining all of the test suites. But they're evaluated on velocity, not reliability, and velocity is defined as story points delivered, which is measured by tickets closed, but since labor hours are purchased in fixed buckets, the definition of done becomes "we ran out of hours," so in practice, developers just don't write real tests, everything always passes, and nothing actually works.
More moreover, even though the government has pushed all of its contractors to adapt some kind of "DevOps" branding that implies you have broken down the traditional barriers between development and ops, in practice, development and ops are entirely separate contracts run by separate companies and purchased by separate directorates of your sponsoring agency, so in reality, as a development contractor, your work is purchased and approved by an acquisition office that doesn't actually own the operational environment and you're not even legally allowed to directly communicate with whoever actually does own and run that environment. All communication has to go through the acquisition office. So you end up delivering exactly what was asked for, but it doesn't get accepted because the organization that gets to accept or reject changes to production isn't the same organization that was involved with all of your planning and development activities.
I understand why she still works there. She's spent her entire career working on special access and compartmentalized projects, and I worked at this same place on similar geoint projects even before she did. In spite of what Hacker News would have you believe about the quality of military technology, you really do get to see amazing shit, including satellite capabilities I worked on a decade ago that the likes of Starlink and Google are still not close to matching, but I couldn't do it any more and left years ago.