About Cognitive:
Cognitive is an IT and software engineering services company dedicated to elevating the quality, speed and delivery of today’s US government healthcare programs. With a wealth of clinical expertise and hands-on experience, our team understands the significant challenges our government clients—and their customers—face every day. This real-world experience equips us to develop IT solutions that seamlessly connect all facets of healthcare delivery. At Cognitive, we’re guiding government agencies to the forefront of technology innovation in healthcare delivery.
Position Overview:
*This position is contingent upon contract award*
The DevSecOps Lead is responsible for the CI/CD pipeline, infrastructure as code, and security scanning for the CMS Drug Data Processing System (DDPS) and Payment Reconciliation System (PRS). This individual owns the end-to-end DevSecOps capability, enabling continuous integration and delivery using CMS enterprise tools, maintaining the ATO compliance chain, and driving DevSecOps standardization across all sprint teams within the CMS Lean-Agile Release Train.
This is a remote position; however, Cognitive hires only in the following designated U.S. states based on contract and business requirements: VA, DC, MD, TN, FL, AZ, CO, OR, and TX.
Key Responsibilities:
- Own the CI/CD pipeline, infrastructure as code, and security scanning across all DDPS/PRS environments.
- Maintain andoptimize CI/CD pipelines using CMS enterprise tools: GitHub, Jenkins/CloudBees, JFrog Artifactory/XRay, SonarQube, and Snyk.
- Maintain infrastructure as code using AWS CloudFormation across multi-AZ Production and Non-Production VPCs including EC2, Lambda, and VPC configurations.
- Automate integration, testing, and deployments across environments; support BDD and TDD practices and post-implementation validation testing.
- Track real-time operational metrics like PDE volumes, error rates, reconciliation accuracy, & uptime via CloudWatch, Splunk, Splunk On-Call, New Relic, and DataDog.
- Coordinate security scanning and ATO compliance with Nessus, TrendMicro, CrowdStrike, AWS Inspector,SecurityHub, GuardDuty, and CloudTrail.
- Support CMS ATO compliance including SSP maintenance and vulnerability remediation within CMS-defined timelines.
- Lead coaching of development teams on DevSecOps practices; adhere to project schedule and submit Release Deliverables as required.
Qualifications:
- Bachelor's degree in Computer Scienceor related field; 8 or more years in DevOps orDevSecOps, including 4 or more years owning CI/CD for aproduction federal system.
- Hands-on expertise with Jenkins/CloudBees, JFrog Artifactory/XRay, SonarQube, Snyk, and GitHub.
- Hands-on AWS CloudFormation for infrastructure as code across multi-AZ production environments; experience with EC2, Lambda, Systems Manager, VPC, IAM, and Secrets Manager.
- Experience with monitoring tools: AWS CloudWatch, Splunk, Splunk On-Call/VictorOps, New Relic, andDataDog.
- Working knowledge of federal ATO, FISMA, and CMS ARS compliance processes including vulnerability remediation timelines.
- Experience with Bash, Groovy, and YAML scripting; Linux environments (RHEL, CentOS, Amazon Linux 2).
- Experience within a SAFe environment including PI Planning and Agile Release Train delivery.
- Ability to pass CMS and internal required background checks for public trust.
- Preferred certification - AWS Certified DevOps Engineer – Professional
Why Join Us?
- Be part of a mission-driven organization making a difference in healthcare IT.
- Collaborate with innovative and passionate professionals that are there to support you at every turn.
- Enjoy a supportive work/life balance with the flexibility of a 100% remote company.
- Benefit from opportunities for growth and development in a dynamic environment.