DevSecOps Analyst
Computer World Services (CWS) is seeking a highly motivated and technically skilled DevSecOps Analyst to support the National Institute of Environmental Health Sciences (NIEHS) under the NSITES III contract. The DevSecOps Analyst provides technical expertise in secure software delivery, infrastructure automation, cybersecurity operations, vulnerability management, and enterprise application security. This position combines traditional information security responsibilities with modern DevSecOps practices to ensure security is integrated throughout the Software Development Lifecycle (SDLC), Infrastructure as Code (IaC), Continuous Integration/Continuous Deployment (CI/CD), and enterprise platform operations.
The successful candidate will possess hands-on experience with vulnerability management platforms, Infrastructure as Code, CI/CD technologies, container platforms, and application security tools while supporting compliance with Federal cybersecurity standards and guidance, including FISMA, NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIH and HHS security policies, and Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directives (BODs).
Key Tasks & Responsibilities Enterprise Security Operations
Support planning, coordination, implementation, and maintenance of enterprise information security capabilities.
Administer enterprise security infrastructure supporting LAN, WAN, cloud, and hybrid environments.
Design, implement, and maintain network security controls.
Develop, review, and maintain firewall policies, NAT rules, VPN configurations, security zones, and access control lists.
Perform firewall software upgrades, patch management, and configuration maintenance.
Administer Intrusion Detection and Prevention Systems (IDS/IPS).
Administer centralized log aggregation and Security Information and Event Management (SIEM) platforms.
Support web filtering and secure web gateway technologies.
Maintain file integrity monitoring solutions.
Investigate Data Loss Prevention (DLP) alerts and resolve DLP policy issues.
Assist in incident response activities involving network, endpoint, and application security.
CI/CD Pipeline Engineering
Design, develop, maintain, and improve enterprise CI/CD pipelines.
Implement automated build, test, security validation, packaging, and deployment workflows.
Support enterprise CI/CD platforms including:
Jenkins
GitLab CI/CD
GitHub Actions
Automate application deployment across development, testing, staging, and production environments.
Support Git-based source control management, branching strategies, and release management.
Troubleshoot pipeline failures and deployment issues.
Optimize pipeline performance and automation efficiency.
Infrastructure Automation
Develop Infrastructure as Code (IaC) using Terraform.
Develop system automation using Ansible.
Automate infrastructure provisioning and configuration management.
Build reusable infrastructure modules and deployment templates.
Support enterprise platform modernization initiatives.
Automate routine administrative and operational activities.
Standardize infrastructure deployments across multiple environments.
Container Platform Administration
Support Docker-based application deployments.
Administer Kubernetes clusters.
Support Rancher-managed Kubernetes environments.
Manage enterprise container registries.
Implement container security best practices.
Perform image vulnerability scanning and remediation.
Support runtime container security initiatives.
Assist application teams with container migration and deployment.
Troubleshoot containerized applications and orchestration environments.
Application Security
Integrate security testing throughout the SDLC.
Configure and maintain:
OpenText Fortify (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Secrets Scanning
Review vulnerability scan findings.
Collaborate with developers to remediate security findings.
Implement automated security gates within CI/CD pipelines.
Promote secure coding practices.
Support software assurance initiatives.
Assist with threat modeling and application risk assessments.
Vulnerability Management
Administer Tenable Security Center (SC).
Administer Nessus vulnerability scanners.
Perform authenticated and unauthenticated vulnerability assessments.
Analyze vulnerability results.
Track remediation activities.
Conduct risk assessments.
Coordinate vulnerability remediation with infrastructure and application teams.
Support compliance reporting and continuous monitoring.
Support CISA Binding Operational Directives (BODs), CVEs, and vulnerability remediation efforts.
Assist with penetration testing remediation activities.
Software Lifecycle Management Support
Support software lifecycle management activities for:
NSITES III operational tools
Standard enterprise software deployments
Optional licensed software
Customer-requested software
Enterprise software platforms
Responsibilities include:
Software packaging
Software testing
Version control
Patch validation
Vulnerability remediation
Change management
Continuous Integration
Software maintenance
Software deployment
Lifecycle documentation
Support software enhancements, maintenance, and security updates for:
Java Runtime Environment
Enterprise software platforms
Hardware drivers
Custom applications
Commercial Off-The-Shelf (COTS) software
Support remediation of software vulnerabilities with:
CVSS v4 scores of 7.0 or higher
CISA Binding Operational Directives (BODs)
Audit findings
Penetration testing findings
Compliance and Governance
Support compliance with:
FISMA
NIST Cybersecurity Framework (CSF)
NIST Risk Management Framework (RMF)
NIST SP 800-53
NIH Information Security Policies
HHS Information Security Requirements
CISA Binding Operational Directives (BODs)
Secure Software Development Framework (SSDF)
Federal Secure Software Supply Chain requirements
Assist with:
Security documentation
Audit preparation
Risk assessments
Security control implementation
Continuous monitoring
Authority to Operate (ATO) activities
Education & Experience Education
Bachelor’s degree in Computer Science, Information Technology Management, or Engineering. Alternatively, four years of related experience may substitute for the educational requirement.
Experience
3-7 years of experience in Windows system administration in enterprise environments
Experience supporting large-scale Data Center operations
Experience supporting multi-platform environments (Windows, Linux, virtualization, storage, and database systems)
Certifications AWS Certified DevOps Engineer
Microsoft Azure DevOps Engineer Expert
Certifications such as CompTIA A+, Security+, Network+, or Microsoft certifications
ITIL certification preferred.
Security Clearance Applicants must be able to obtain a Public Trust clearance
Computer World Services is an affirmative action and equal employment opportunity employer. Current employees and/or qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, disability, protected veteran status, genetic information or any other characteristic protected by local, state, or federal laws, rules, or regulations. Computer World Services is committed to the full inclusion of all qualified individuals. As part of this commitment, Computer World Services will ensure that individuals with disabilities (IWD) are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact Human Resources at hr@cwsc.com.