Position Overview:
*This position is contingent upon contract award*
The DevSecOps Lead is responsible for the CI/CD pipeline, infrastructure as code, and security scanning for the CMS Drug Data Processing System (DDPS) and Payment Reconciliation System (PRS). This individual owns the end-to-end DevSecOps capability, enabling continuous integration and delivery using CMS enterprise tools, maintaining the ATO compliance chain, and driving DevSecOps standardization across all sprint teams within the CMS Lean-Agile Release Train.
This is a remote position; however, Cognitive hires only in the following designated U.S. states based on contract and business requirements: VA, DC, MD, TN, FL, AZ, CO, OR, and TX.
Key Responsibilities:
- Own the CI/CD pipeline, infrastructure as code, and security scanning across all DDPS/PRS environments.
- Maintain andoptimize CI/CD pipelines using CMS enterprise tools: GitHub, Jenkins/CloudBees, JFrog Artifactory/XRay, SonarQube, and Snyk.
- Maintain infrastructure as code using AWS CloudFormation across multi-AZ Production and Non-Production VPCs including EC2, Lambda, and VPC configurations.
- Automate integration, testing, and deployments across environments; support BDD and TDD practices and post-implementation validation testing.
- Track real-time operational metrics like PDE volumes, error rates, reconciliation accuracy, & uptime via CloudWatch, Splunk, Splunk On-Call, New Relic, and DataDog.
- Coordinate security scanning and ATO compliance with Nessus, TrendMicro, CrowdStrike, AWS Inspector,SecurityHub, GuardDuty, and CloudTrail.
- Support CMS ATO compliance including SSP maintenance and vulnerability remediation within CMS-defined timelines.
- Lead coaching of development teams on DevSecOps practices; adhere to project schedule and submit Release Deliverables as required.
Qualifications:
- Bachelor's degree in Computer Scienceor related field; 8 or more years in DevOps orDevSecOps, including 4 or more years owning CI/CD for aproduction federal system.
- Hands-on expertise with Jenkins/CloudBees, JFrog Artifactory/XRay, SonarQube, Snyk, and GitHub.
- Hands-on AWS CloudFormation for infrastructure as code across multi-AZ production environments; experience with EC2, Lambda, Systems Manager, VPC, IAM, and Secrets Manager.
- Experience with monitoring tools: AWS CloudWatch, Splunk, Splunk On-Call/VictorOps, New Relic, andDataDog.
- Working knowledge of federal ATO, FISMA, and CMS ARS compliance processes including vulnerability remediation timelines.
- Experience with Bash, Groovy, and YAML scripting; Linux environments (RHEL, CentOS, Amazon Linux 2).
- Experience within a SAFe environment including PI Planning and Agile Release Train delivery.
- Ability to pass CMS and internal required background checks for public trust.
- Preferred certification - AWS Certified DevOps Engineer - Professional
Why Join Us?
- Be part of a mission-driven organization making a difference in healthcare IT.
- Collaborate with innovative and passionate professionals that are there to support you at every turn.
- Enjoy a supportive work/life balance with the flexibility of a 100% remote company.
- Benefit from opportunities for growth and development in a dynamic environment.