Computer World Services Corp. (CWS)

DevSecOps Analyst

Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's in Computer Science, IT Management, or Engineering; or equivalent experience.
  • 3-7 years of experience in enterprise Windows system administration.
  • Experience with large-scale Data Center operations.
  • Familiarity with multi-platform environments (Windows, Linux, etc.).
  • Certifications: AWS Certified DevOps Engineer, Azure DevOps Engineer Expert preferred; CompTIA A+, Security+, Network+ desired.
  • ITIL certification preferred.
  • Ability to obtain Public Trust clearance.

Responsibilities

  • Support enterprise information security capabilities planning and implementation.
  • Administer security infrastructure across LAN, WAN, cloud, and hybrid environments.
  • Design, implement, and maintain network security controls and policies.
  • Develop and review firewall configurations and access control lists.
  • Administer SIEM and log aggregation platforms for security monitoring.
  • Design and improve enterprise CI/CD pipelines for software delivery.
  • Automate infrastructure provisioning and maintain configuration management.

Benefits

  • Comprehensive health and wellness programs.
  • Professional development and training opportunities.
  • Flexible work arrangements including remote options.
  • Support for certifications and ongoing education.
  • Collaborative work environment with a focus on innovation.
Full Job Description
The DevSecOps Analyst provides technical expertise in secure software delivery, infrastructure automation, cybersecurity operations, vulnerability management, and enterprise application security. This position combines traditional information security responsibilities with modern DevSecOps practices to ensure security is integrated throughout the Software Development Lifecycle (SDLC), Infrastructure as Code (IaC), Continuous Integration/Continuous Deployment (CI/CD), and enterprise platform operations.

The successful candidate will possess hands-on experience with vulnerability management platforms, Infrastructure as Code, CI/CD technologies, container platforms, and application security tools while supporting compliance with Federal cybersecurity standards and guidance, including FISMA, NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIH and HHS security policies, and Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directives (BODs).

Key Tasks & Responsibilities

Enterprise Security Operations
  • Support planning, coordination, implementation, and maintenance of enterprise information security capabilities.
  • Administer enterprise security infrastructure supporting LAN, WAN, cloud, and hybrid environments.
  • Design, implement, and maintain network security controls.
  • Develop, review, and maintain firewall policies, NAT rules, VPN configurations, security zones, and access control lists.
  • Perform firewall software upgrades, patch management, and configuration maintenance.
  • Administer Intrusion Detection and Prevention Systems (IDS/IPS).
  • Administer centralized log aggregation and Security Information and Event Management (SIEM) platforms.
  • Support web filtering and secure web gateway technologies.
  • Maintain file integrity monitoring solutions.
  • Investigate Data Loss Prevention (DLP) alerts and resolve DLP policy issues.
  • Assist in incident response activities involving network, endpoint, and application security.


CI/CD Pipeline Engineering
  • Design, develop, maintain, and improve enterprise CI/CD pipelines.
  • Implement automated build, test, security validation, packaging, and deployment workflows.
  • Support enterprise CI/CD platforms including:
    • Jenkins
    • GitLab CI/CD
    • GitHub Actions
  • Automate application deployment across development, testing, staging, and production environments.
  • Support Git-based source control management, branching strategies, and release management.
  • Troubleshoot pipeline failures and deployment issues.
  • Optimize pipeline performance and automation efficiency.


Infrastructure Automation
  • Develop Infrastructure as Code (IaC) using Terraform.
  • Develop system automation using Ansible.
  • Automate infrastructure provisioning and configuration management.
  • Build reusable infrastructure modules and deployment templates.
  • Support enterprise platform modernization initiatives.
  • Automate routine administrative and operational activities.
  • Standardize infrastructure deployments across multiple environments.


Container Platform Administration
  • Support Docker-based application deployments.
  • Administer Kubernetes clusters.
  • Support Rancher-managed Kubernetes environments.
  • Manage enterprise container registries.
  • Implement container security best practices.
  • Perform image vulnerability scanning and remediation.
  • Support runtime container security initiatives.
  • Assist application teams with container migration and deployment.
  • Troubleshoot containerized applications and orchestration environments.


Application Security
  • Integrate security testing throughout the SDLC.
  • Configure and maintain:
    • OpenText Fortify (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Secrets Scanning
  • Review vulnerability scan findings.
  • Collaborate with developers to remediate security findings.
  • Implement automated security gates within CI/CD pipelines.
  • Promote secure coding practices.
  • Support software assurance initiatives.
  • Assist with threat modeling and application risk assessments.


Vulnerability Management
  • Administer Tenable Security Center (SC).
  • Administer Nessus vulnerability scanners.
  • Perform authenticated and unauthenticated vulnerability assessments.
  • Analyze vulnerability results.
  • Track remediation activities.
  • Conduct risk assessments.
  • Coordinate vulnerability remediation with infrastructure and application teams.
  • Support compliance reporting and continuous monitoring.
  • Support CISA Binding Operational Directives (BODs), CVEs, and vulnerability remediation efforts.
  • Assist with penetration testing remediation activities.


Software Lifecycle Management Support

Support software lifecycle management activities for:
  • NSITES III operational tools
  • Standard enterprise software deployments
  • Optional licensed software
  • Customer-requested software
  • Enterprise software platforms

Responsibilities include:
  • Software packaging
  • Software testing
  • Version control
  • Patch validation
  • Vulnerability remediation
  • Change management
  • Continuous Integration
  • Software maintenance
  • Software deployment
  • Lifecycle documentation

Support software enhancements, maintenance, and security updates for:
  • Java Runtime Environment
  • Enterprise software platforms
  • Hardware drivers
  • Custom applications
  • Commercial Off-The-Shelf (COTS) software

Support remediation of software vulnerabilities with:
  • CVSS v4 scores of 7.0 or higher
  • CISA Binding Operational Directives (BODs)
  • Audit findings
  • Penetration testing findings


Compliance and Governance

Support compliance with:
  • FISMA
  • NIST Cybersecurity Framework (CSF)
  • NIST Risk Management Framework (RMF)
  • NIST SP 800-53
  • NIH Information Security Policies
  • HHS Information Security Requirements
  • CISA Binding Operational Directives (BODs)
  • Secure Software Development Framework (SSDF)
  • Federal Secure Software Supply Chain requirements

Assist with:
  • Security documentation
  • Audit preparation
  • Risk assessments
  • Security control implementation
  • Continuous monitoring
  • Authority to Operate (ATO) activities


Education & Experience

Education
  • Bachelor's degree in Computer Science, Information Technology Management, or Engineering. Alternatively, four years of related experience may substitute for the educational requirement.

Experience
  • 3-7 years of experience in Windows system administration in enterprise environments
  • Experience supporting large-scale Data Center operations
  • Experience supporting multi-platform environments (Windows, Linux, virtualization, storage, and database systems)


Certifications

  • AWS Certified DevOps Engineer
  • Microsoft Azure DevOps Engineer Expert
  • Certifications such as CompTIA A+, Security+, Network+, or Microsoft certifications
  • ITIL certification preferred.


Security Clearance

  • Applicants must be able to obtain a Public Trust clearance

About Computer World Services Corp. (CWS)

**Computer World Services Corp. (CWS) Careers**

Join the dynamic team at Computer World Services Corp. (CWS), a leader in providing innovative IT solutions and services. At CWS, job opportunities abound for professionals eager to advance their careers in technology and consulting.

Work You’ll Do

At Computer World Services Corp. (CWS), professionals will find themselves at the forefront of digital transformation, helping to shape the future of technology across various industries. The company offers a unique position in the marketplace, combining industry expertise, leadership in innovation, and a commitment to digital advancement.

Explore Career Opportunities

Computer World Services Corp. (CWS) is actively hiring and offers a range of positions from entry-level to senior leadership roles. Explore job opportunities that match your skills and interests in an environment that fosters professional growth and development.

Innovative Work Environment

Engage in groundbreaking projects that push the boundaries of technology and consulting. Computer World Services Corp. (CWS) is dedicated to innovation and excellence, providing employees with the opportunity to work on challenging assignments that drive significant impact.

Join a Diverse and Inclusive Team

Computer World Services Corp. (CWS) believes in the power of diversity and inclusion. The company fosters a culture where differences are embraced, and everyone is given the platform to thrive. Join a team where diversity training and leadership are part of everyday growth and development.

Internship Programs and Employment Benefits

Start your career with Computer World Services Corp. (CWS) through robust internship programs designed to give you a competitive edge. Full-time positions offer substantial benefits, including professional development programs, networking opportunities, and a supportive work environment that champions career advancement and personal growth.

Future-Proof Your Career

With Computer World Services Corp. (CWS), advance your career to new heights with access to unmatched training, certification support, and leadership development programs. The company is committed to the professional growth of its team members, ensuring that each individual's career journey is both rewarding and fulfilling.

Stay Connected

Join the Computer World Services Corp. (CWS) Team

Search open positions that align with your career goals and expertise. Computer World Services Corp. (CWS) is looking for passionate, curious, and solution-driven team players ready to make a difference.

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals at Computer World Services Corp. (CWS).

Job Alert Emails

Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at Computer World Services Corp. (CWS).
Learn more about Computer World Services Corp. (CWS)
Size
251 employees
Industry

Similar Jobs

More Jobs at Computer World Services Corp. (CWS)

More Information Technology Jobs

Find similar DevSecOps Analyst jobs: