DevSecOps Analyst
Listed on 2026-08-02
-
IT/Tech
Cybersecurity
Computer World Services (CWS) is seeking a highly motivated and technically skilled Dev Sec Ops Analyst to support the National Institute of Environmental Health Sciences (NIEHS) under the NSITES III contract. The Dev Sec Ops Analyst provides technical expertise in secure software delivery, infrastructure automation, cybersecurity operations, vulnerability management, and enterprise application security. This position combines traditional information security responsibilities with modern Dev Sec Ops practices to ensure security is integrated throughout the Software Development Lifecycle (SDLC), Infrastructure as Code (IaC), Continuous Integration/Continuous Deployment (CI/CD), and enterprise platform operations.
The successful candidate will possess hands‑on experience with vulnerability management platforms, Infrastructure as Code, CI/CD technologies, container platforms, and application security tools while supporting compliance with Federal cybersecurity standards and guidance, including FISMA, NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIH and HHS security policies, and Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directives (BODs).
Key Tasks & Responsibilities Enterprise Security Operations- Support planning, coordination, implementation, and maintenance of enterprise information security capabilities.
- Administer enterprise security infrastructure supporting LAN, WAN, cloud, and hybrid environments.
- Design, implement, and maintain network security controls.
- Develop, review, and maintain firewall policies, NAT rules, VPN configurations, security zones, and access control lists.
- Perform firewall software upgrades, patch management, and configuration maintenance.
- Administer Intrusion Detection and Prevention Systems (IDS/IPS).
- Administer centralized log aggregation and Security Information and Event Management (SIEM) platforms.
- Support web filtering and secure web gateway technologies.
- Maintain file integrity monitoring solutions.
- Investigate Data Loss Prevention (DLP) alerts and resolve DLP policy issues.
- Assist in incident response activities involving network, endpoint, and application security.
- Design, develop, maintain, and improve enterprise CI/CD pipelines.
- Implement automated build, test, security validation, packaging, and deployment workflows.
- Support enterprise CI/CD platforms including:
- Jenkins
- Git Lab CI/CD
- Git Hub Actions
- Automate application deployment across development, testing, staging, and production environments.
- Support Git-based source control management, branching strategies, and release management.
- Troubleshoot pipeline failures and deployment issues.
- Optimize pipeline performance and automation efficiency.
- Develop Infrastructure as Code (IaC) using Terraform.
- Develop system automation using Ansible.
- Automate infrastructure provisioning and configuration management.
- Build reusable infrastructure modules and deployment templates.
- Support enterprise platform modernization initiatives.
- Automate routine administrative and operational activities.
- Standardize infrastructure deployments across multiple environments.
- Support Docker-based application deployments.
- Administer Kubernetes clusters.
- Support Rancher‑managed Kubernetes environments.
- Manage enterprise container registries.
- Implement container security best practices.
- Perform image vulnerability scanning and remediation.
- Support runtime container security initiatives.
- Assist application teams with container migration and deployment.
- Troubleshoot containerized applications and orchestration environments.
- Integrate security testing throughout the SDLC.
- Configure and maintain:
- Open Text Fortify (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Secrets Scanning
- Review vulnerability scan findings.
- Collaborate with developers to remediate security findings.
- Implement automated security gates within CI/CD pipelines.
- Promote secure coding practices.
- Support software assurance initiatives.
- Assist with threat modeling and application risk assessments.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).