--- title: 'DevSecOps Analyst at Computer World Services' canonical: 'https://feeny.ai/job/devsecops-analyst-computer-world-services-morrisville-rq1shfwn0pgj' type: 'job' last_seen: '2026-09-07' --- # DevSecOps Analyst at Computer World Services - **Company:** Computer World Services - **Location:** Morrisville, NC - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-07-30 - **Last confirmed live:** 2026-09-07 - **Apply:** https://jobs.lever.co/cwsc/f9c38a21-bc4d-4cf3-bcea-2fb83e8a336b ## Job description Computer World Services (CWS) is seeking a highly motivated and technically skilled DevSecOps Analyst to support the National Institute of Environmental Health Sciences (NIEHS) under the NSITES III contract. The DevSecOps Analyst provides technical expertise in secure software delivery, infrastructure automation, cybersecurity operations, vulnerability management, and enterprise application security. This position combines traditional information security responsibilities with modern DevSecOps practices to ensure security is integrated throughout the Software Development Lifecycle (SDLC), Infrastructure as Code (IaC), Continuous Integration/Continuous Deployment (CI/CD), and enterprise platform operations. The successful candidate will possess hands-on experience with vulnerability management platforms, Infrastructure as Code, CI/CD technologies, container platforms, and application security tools while supporting compliance with Federal cybersecurity standards and guidance, including FISMA, NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIH and HHS security policies, and Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directives (BODs). ## Key Tasks & Responsibilities Enterprise Security Operations - Support planning, coordination, implementation, and maintenance of enterprise information security capabilities. - Administer enterprise security infrastructure supporting LAN, WAN, cloud, and hybrid environments. - Design, implement, and maintain network security controls. - Develop, review, and maintain firewall policies, NAT rules, VPN configurations, security zones, and access control lists. - Perform firewall software upgrades, patch management, and configuration maintenance. - Administer Intrusion Detection and Prevention Systems (IDS/IPS). - Administer centralized log aggregation and Security Information and Event Management (SIEM) platforms. - Support web filtering and secure web gateway technologies. - Maintain file integrity monitoring solutions. - Investigate Data Loss Prevention (DLP) alerts and resolve DLP policy issues. - Assist in incident response activities involving network, endpoint, and application security. CI/CD Pipeline Engineering - Design, develop, maintain, and improve enterprise CI/CD pipelines. - Implement automated build, test, security validation, packaging, and deployment workflows. - Support enterprise CI/CD platforms including: - Jenkins - GitLab CI/CD - GitHub Actions - Automate application deployment across development, testing, staging, and production environments. - Support Git-based source control management, branching strategies, and release management. - Troubleshoot pipeline failures and deployment issues. - Optimize pipeline performance and automation efficiency. Infrastructure Automation - Develop Infrastructure as Code (IaC) using Terraform. - Develop system automation using Ansible. - Automate infrastructure provisioning and configuration management. - Build reusable infrastructure modules and deployment templates. - Support enterprise platform modernization initiatives. - Automate routine administrative and operational activities. - Standardize infrastructure deployments across multiple environments. Container Platform Administration - Support Docker-based application deployments. - Administer Kubernetes clusters. - Support Rancher-managed Kubernetes environments. - Manage enterprise container registries. - Implement container security best practices. - Perform image vulnerability scanning and remediation. - Support runtime container security initiatives. - Assist application teams with container migration and deployment. - Troubleshoot containerized applications and orchestration environments. Application Security - Integrate security testing throughout the SDLC. - Configure and maintain: - OpenText Fortify (SAST) - Dynamic Application Security Testing (DAST) - Software Composition Analysis (SCA) - Secrets Scanning - Review vulnerability scan findings. - Collaborate with developers to remediate security findings. - Implement automated security gates within CI/CD pipelines. - Promote secure coding practices. - Support software assurance initiatives. - Assist with threat modeling and application risk assessments. Vulnerability Management - Administer Tenable Security Center (SC). - Administer Nessus vulnerability scanners. - Perform authenticated and unauthenticated vulnerability assessments. - Analyze vulnerability results. - Track remediation activities. - Conduct risk assessments. - Coordinate vulnerability remediation with infrastructure and application teams. - Support compliance reporting and continuous monitoring. - Support CISA Binding Operational Directives (BODs), CVEs, and vulnerability remediation efforts. - Assist with penetration testing remediation activities. Software Lifecycle Management Support Support software lifecycle management activities for: - NSITES III operational tools - Standard enterprise software deployments - Optional licensed software - Customer-requested software - Enterprise software platforms Responsibilities include: - Software packaging - Software testing - Version control - Patch validation - Vulnerability remediation - Change management - Continuous Integration - Software maintenance - Software deployment - Lifecycle documentation Support software enhancements, maintenance, and security updates for: - Java Runtime Environment - Enterprise software platforms - Hardware drivers - Custom applications - Commercial Off-The-Shelf (COTS) software Support remediation of software vulnerabilities with: - CVSS v4 scores of 7.0 or higher - CISA Binding Operational Directives (BODs) - Audit findings - Penetration testing findings Compliance and Governance Support compliance with: - FISMA - NIST Cybersecurity Framework (CSF) - NIST Risk Management Framework (RMF) - NIST SP 800-53 - NIH Information Security Policies - HHS Information Security Requirements - CISA Binding Operational Directives (BODs) - Secure Software Development Framework (SSDF) - Federal Secure Software Supply Chain requirements Assist with: - Security documentation - Audit preparation - Risk assessments - Security control implementation - Continuous monitoring - Authority to Operate (ATO) activities Education & Experience Education - Bachelor’s degree in Computer Science, Information Technology Management, or Engineering. Alternatively, four years of related experience may substitute for the educational requirement. ## Experience - 3-7 years of experience in Windows system administration in enterprise environments - Experience supporting large-scale Data Center operations - Experience supporting multi-platform environments (Windows, Linux, virtualization, storage, and database systems) Certifications - AWS Certified DevOps Engineer - Microsoft Azure DevOps Engineer Expert - Certifications such as CompTIA A+, Security+, Network+, or Microsoft certifications - ITIL certification preferred. Security Clearance - Applicants must be able to obtain a Public Trust clearance Computer World Services is an affirmative action and equal employment opportunity employer. Current employees and/or qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, disability, protected veteran status, genetic information or any other characteristic protected by local, state, or federal laws, rules, or regulations. Computer World Services is committed to the full inclusion of all qualified individuals. As part of this commitment, Computer World Services will ensure that individuals with disabilities (IWD) are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact Human Resources at hr@cwsc.com. ## About Computer World Services ## Company Overview - **One-liner**: Computer World Services Corp. (CWS) is a privately held IT services provider that delivers enterprise-wide solutions, digital transformation, and cybersecurity support to U.S. Defense and Civilian federal agencies. - **Entity Type**: Private (Bootstrapped) - **Headquarters**: Washington, D.C., USA (also has offices in Fairview Heights, IL; Falls Church, VA; St. Louis, MO; and Scott AFB, IL) - **Founded**: 1990 - **Founders**: Frank Hameed (President and CEO) ## Core Business - Primary industry/industries: Information Technology (IT) services, federal government contracting, cybersecurity, digital transformation. - Target customers: U.S. federal government (Defense and Civilian agencies) – strictly B2G (Business-to-Government). - Mission or purpose statement: Not explicitly stated, but the company emphasizes delivering “quality, value, and technological innovation” with a commitment to integrity and excellence in service delivery. ## Products & Services - **Enterprise IT Solutions**: Full lifecycle IT support including network operations, systems administration, help desk, and infrastructure management. - **Cybersecurity Services**: Cybersecurity operations, CSSP (Cybersecurity Service Provider) engineering and team leadership, threat monitoring, and compliance. - **Digital Transformation & Process Optimization**: Modernization of legacy systems, cloud migration, and business process re-engineering for federal clients. - **DevSecOps**: Integration of security into development and operations pipelines, including software development and application/web support. All offerings are delivered as services (IT services, managed services, consulting) rather than SaaS or hardware products. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company). - **Key Metric**: Total employees: ~400 (as of latest data). Revenue not publicly available. - **Notable Investors/Partners**: No external investors listed; the company was founded organically by Frank Hameed. Key partners are federal agencies (DoD, civilian departments). - **Growth Signals**: Talent footprint has expanded across 19 states and 140 cities. The company supports 100% remote and hybrid work models. Consistently high ratings in federal programs. ## Competitive Advantages - **30+ Years of Federal Experience**: Deep understanding of government contracting, compliance, and security requirements. - **Proven Track Record**: Recognized for consistent performance and high ratings in federal programs (e.g., past performance ratings). - **Flexible Workforce**: Ability to deploy talent across CONUS and OCONUS, with a mix of on-site, hybrid, and remote roles. - **Employee-Focused Benefits**: Competitive benefits package (see below) and a culture that supports work-life balance. ## Strategic Focus - **Current Priorities**: Continue serving Defense and Civilian federal customers by expanding IT, cybersecurity, and digital transformation capabilities. Leverage a remote/hybrid talent model to attract skilled professionals nationwide. - **Direction for Growth**: Likely organic growth through contract wins and recompete wins; no indication of M&A or external funding. ## Why Work Here - **Culture Highlights**: Collaborative, mission-driven environment supporting national security and federal operations. Emphasis on integrity and excellence. - **Remote/Hybrid/Office Policy**: Hybrid workspace – employees engage in a combination of remote and on-site work. Many roles are fully remote; on-site positions exist at government facilities (e.g., Scott AFB, IL; Washington, D.C.). - **Notable Perks & Benefits** (from [cwsc.com/employee-benefits](https://cwsc.com/employee-benefits/)): - Medical, dental, and vision plans (United Healthcare) - 15 days PTO accrued from day one + 11 company holidays - Tuition reimbursement up to $5,000 per year - 401(k) with 4% company match (Safe Harbor, 100% vested immediately) - Short & long-term disability (100% employer-paid) - Company-paid basic life and AD&D insurance - Flexible spending accounts (FSA) and Health Savings Accounts (HSA) - Commuter benefits (pre-tax transit and parking) - Employee Assistance Program - Generous parental leave (from Built In) - **Engineering Culture**: Focus on cybersecurity, network operations, DevSecOps, and systems engineering. Use of AI in hiring process (applicants are informed). Strong support for professional development via tuition reimbursement. ## Sources 1. [cwsc.com – Home](https://cwsc.com/) 2. [cwsc.com – Careers](https://cwsc.com/careers/) 3. [cwsc.com – Employee Benefits](https://cwsc.com/employee-benefits/) 4. [jobs.lever.co/cwsc – Current Openings](https://jobs.lever.co/cwsc) 5. [builtin.com – Computer World Services Corp. Profile](https://builtin.com/company/computer-world-services-corp) ## Other roles at Computer World Services - [Desktop Engineer - Windows](https://feeny.ai/job/desktop-engineer-windows-computer-world-services-morrisville-n07wjw4s3x7p) — Morrisville, NC - [Program Analyst](https://feeny.ai/job/program-analyst-computer-world-services-washington-5r5k53vn322a) — Washington, DC - [Security Administrator - Intermediate](https://feeny.ai/job/security-administrator-intermediate-computer-world-services-fort-meade-p39aynrtr1j4) — Fort Meade, MD - [IT Asset Manager](https://feeny.ai/job/it-asset-manager-computer-world-services-lackland-afb-ey9eyecqz5sf) — Lackland Afb, TX - [Configuration Analyst II (Service Transition) – SIPR Change Manager](https://feeny.ai/job/configuration-analyst-ii-service-transition-sipr-change-manager-computer-world-tqexbv6e8j2a) — Lackland Afb, TX - [Configuration Analyst II (Service Transition) – Service Transition Coordinator](https://feeny.ai/job/configuration-analyst-ii-service-transition-service-transition-coordinator-nks6fkx22w66) — Lackland Afb, TX - [IT Project Manager (CORA) Strategic Planner](https://feeny.ai/job/it-project-manager-cora-strategic-planner-computer-world-services-lackland-afb-74dw9pnrvzc0) — Lackland Afb, TX - [IS and Cyber Security Professional – Entry (AFIN Reporting Cell - NDCI - ESI)](https://feeny.ai/job/is-and-cyber-security-professional-entry-afin-reporting-cell-ndci-esi-computer-jc3ee5jr530h) — Lackland Afb, TX - [Systems Administrator / IT Support Specialist](https://feeny.ai/job/systems-administrator-it-support-specialist-computer-world-services-falls-church-1s47jdk50vsy) — Falls Church, VA - [Night Shift Incident Manager](https://feeny.ai/job/night-shift-incident-manager-computer-world-services-bethesda-6b5tww2aw5p1) — Bethesda, MD