Himalayas logo
EMW, Inc.EI

2025-0303 Support for DevSecOps Engineering (NS) - THU 11 Sep

EMW, Inc. is a global systems integration company providing lifecycle Systems Engineering and Technical Assistance (SETA), Engineering and Installation (E&I), Operations and Maintenance (O&M), and Force Protection technologies in Health IT, Cyber Security, Perimeter Security, and Telecommunications Infrastructure.

EMW, Inc.

Employee count: 51-200

Belgium only

Deadline Date: Thursday 11 September 2025

Requirement: Support for DevSecOps Engineering

Location: Off-Site

Note: Please refer to your Subcontract Agreement, article 6.4.1.a, which states “Off-Site Discount: 5% (this discount is applicable to all requirements, and applies when the assigned personnel are permitted to work Off-Site, such as at- home)". Please be sure to price this discount in your overall price proposal when submitting bids against off-site RFQs

Period of Performance: BASE period: As soon as possible but not later than 13th October 2025 – 31st December 2025

2026 Options: 1st January 2026 until 31st December 2026

2027 Options: 1st January 2027 until 31st December 2027

2028 Options: 1st January 2028 until 31st December 2028

Required Security Clearance: NATO SECRET

1 INTRODUCTION

Supporting NATO throughout all its geographical locations, the NCI Agency is looking for Support for DevSecOps Engineering, joining the journey of NATO’s modernization of IT services, through leveraging the public cloud (Microsoft Azure), delivering managed, protected, security-centric and reliable IT Services.

NCI Agency – Cloud Operations Team

The NATO Communications and Information Agency (NCI Agency) is dedicated to supporting NATO's strategic objectives, including the ambitious NATO 2030 agenda. As part of this commitment, we are spearheading the modernization and digital transformation of NATO’s IT services. Our focus is on leveraging public cloud technologies like Microsoft Azure, incorporating a security-by-design approach, and ensuring a seamless transition to a modern, collaborative workplace environment.

To achieve these goals, we are building a Cloud Operations Center team under the Cloud Portfolio, operating under the NATO Enterprise Cloud Operating Model (NECOM) and under the guidance of the Cloud Center of Excellence (CCoE). The NECOM framework provides a standardized approach for cloud service management, ensuring interoperability, scalability, and security across NATO's IT infrastructure. The Cloud Center of Excellence will serve as a hub for best practices, innovation, and expertise, driving the adoption and optimization of cloud technologies within NATO. This team will play a crucial role in our journey towards providing managed, protected, and reliable End User Services.

Embracing the latest technological advancements, this initiative will foster innovation and ensure NATO remains at the cutting edge of IT capabilities. By continuously evolving and integrating new technologies, we aim to enhance operational efficiency and readiness for future challenges. This remote position offers an exciting opportunity to be at the forefront of NATO's technological evolution and contribute to the security and efficiency of our operations.

NCI Agency – Cloud Centre of Excellence (CCoE)

The Cloud Centre of Excellence (CCoE) within the NCI Agency is focused on driving successful cloud adoption and maximizing the potential of cloud technologies across the organization. It serves as a central governing body, promoting best practices, enabling knowledge sharing, and ensuring alignment between business objectives and cloud initiatives. The CCoE supports various cloud-based solutions, ensuring their effective and efficient implementation and management. By fostering a culture of continuous improvement and innovation, the CCoE helps the NCI Agency leverage cloud technologies to enhance operational efficiency, scalability, and agility.

The ideal service will offer expertise in managing resources in Microsoft Azure Cloud by leveraging DevSecOps practices. Strong analytical, problem-solving, and organizational skills are required, along with the ability to document processes on Microsoft Azure services and DevSecOps tools and practices.

This service is critical for maintaining a secure and efficient cloud environment, supporting internal users and external collaborators.

2 OBJECTIVES

The NCI Agency is embracing cloud services by transitioning to Microsoft Azure with a security-centric design. This shift aims to enhance operational efficiency, collaboration, and security across the organization.

The objective of this statement of work is to establish a support and operating model for End User Services operating in the Public Cloud.

3 SCOPE OF WORK

The contractor will be part of a team providing Technical Level 2 and 3 support, ensuring the secure, available, managed and compliant delivery of Public Cloud Services to NATO and its Strategic Commands.

Under the direction / guidance of the IaaS/PaaS Team technical lead or the Cloud Operations Center Manager, the contractor will perform the following activities:

1) Operation of cloud infrastructure in Microsoft Azure by leveraging DevSecOps practices:

a) Deploy and manage landing zones by utilizing DevSecOps practices to ensure a secure, scalable foundation for cloud workloads;

b) Deploy and manage cloud workloads on top of the landing zones in an automated fashion;

c) Utilize Infrastructure as Code and CI/CD pipelines through Azure Devops;

d) Build, deploy and maintain containerized workloads using Azure Kubernetes Services (AKS);

e) Deploy and monitor Azure Virtual Machines (VMs), including sizing, patching, backup, performance tuning and cost optimization;

f) Build and maintain automated disaster recovery and backup solutions using services like Azure Backup, Site Recovery and storage replication;

g) Monitor the performance and effectiveness of landing zones and cloud workloads;

h) Identify opportunities for improvement and implement optimizations to enhance security and efficiency.

2) Support for application deployment and troubleshooting:

a) Manage secure and reliable access to applications for end-users including configuration of Azure Application Gateways, Azure load-balancers and custom domains;

b) Monitor Application availability, performance and security using services such as Azure Monitor, Log Analytics, Application insights and configure automated alerts;

c) Provide support for Microsoft Azure Services - related issues, including troubleshooting access, networking and cloud resource specific issues;

d) Maintain comprehensive documentation for Microsoft Azure Services processes, configurations, and workflows;

3) Security and Compliance:

a) Implement and manage governance controls such as Azure policies to ensure compliance with organizational standards;

b) Ensure all deployed workloads and services adhere to Zero trust security principles, including proper network segmentation, identity-base access control and logging;

c) Conduct regular audits and reviews of access controls and permissions.

4) Collaboration and Communication:

a) Collaborate with IT security, compliance, and other relevant teams to ensure cohesive cloud resources management strategies.

b) Contribute to the lifecycle of cloud secure products in collaboration with the CTO CCOE to ensure reusable, secure and automated infrastructure modules

c) Communicate effectively with stakeholders to understand IaaS and Paas requirements and address concerns.

5) Automation and Efficiency:

a) Identify opportunities to enhance efficiency through automation and proactively implement solutions.

b) Champion continuous improvement by evaluating new Azure capabilities, DevOps tools and security practices and integrate them into operations.

c) Lead operational readiness for new cloud solutions, by establishing runbooks, knowledge base transfer sessions and handover to support teams

The services related to the activities above will be delivered in Sprints, and each sprint will have the duration 5 working days.

The content and scope of each sprint will be agreed during the sprint‐planning meetings as covered in the section 4.

4 SPRINTS PLANNING, EXECUTION, REVIEW AND PAYMENT

Due to the AGILE approach of this project, the specific deliverables and associated acceptance criteria will be defined for each sprint between the NCI Agency and the contractor. This includes sprint planning, execution and review processes, which are detailed below:

1. Sprint Planning:

Objective: Plan the objectives for the upcoming sprint

Kick-off meeting: NCI Agency to conduct a monthly meeting with the contractor to plan the objectives of upcoming sprints and review contractor`s manpower to meet the agreed deliverables.

Set sprint goals: Define clear, achievable goals for the sprint and associated acceptance criteria, including specific delivery targets, Quality standards as well as Key Performance Indicators (KPIs) for each task to be recorded in the sprint meeting minutes.

Agree on the required level of effort for the various sprint tasks.

Backlog Review: Review and prioritise the backlog of tasks, issues, and improvements from previous sprints.

Assess each payment milestone cycle duration of one calendar month.

State of completion and validation of each sprint status and sign off sprints to be submitted for payment as covered in Section 5.

2. Sprint Execution

Objective: Contractor to execute the agreed “sprint plans” with continuous monitoring and adjustments.

Regular meetings between NCI Agency and the contractor to review sprint progress, address issues, and make necessary adjustments to the processes or production methodology. The Meetings will be physically in the office, or in person via electronic means using Conference Call capabilities, according to the NCI Agency staff instructions.

Continuous improvement: Contractor to establish a continuous feedback loop to gather input from all stakeholders for ongoing improvements and their subsequent implementation depending on NCIA approval.

Progress Tracking: Contractor to use a shared dashboard or tool to track the status of the sprint deliveries and any issues.

Quality Assurance/Quality Check: Contractor shall ensure that the quality standards agreed for the sprint deliverables are maintained throughout the sprint.

Quality Control: NCIA to perform the Final Quality Control of the agreed deliverables and provide feedback on any issues.

3. Sprint Review

Objective: Review the sprint performance and identify areas for improvement.

At the end of each sprint, there will be a meeting between the NCI Agency and the Contractor to review the outcomes against the acceptance criteria comprising sprint goals, agreed quality criteria and Key Performance Indicators (KPIs).

Define specific actions to address issues and enhance the next sprint.

4. Sprint Payment

Payments will be made monthly for the sprints that are completed and approved during that month

For each sprint to be considered as complete and payable, the contractor must report the outcome of their service during the sprint, first verbally during the retrospective sprint review meeting and then in writing within three days after the sprint’s end date. A report must be sent by email to the NCI Agency manager, highlighting all service performed against the agreed tasking list set for the sprint.

The contractor's payment for each sprint will be depending upon the achievement of agreed Acceptance Criteria for each task, defined at the sprint planning stage. This will include specific delivery targets, quality standards as well as Key Performance Indicators (KPIs) for each task.

The payment shall be dependent upon successful acceptance as set in the above planning/review meetings. This will follow the payment milestones that shall include a completed Delivery Acceptance Sheet (DAS) - (Annex B)

Invoices shall be accompanied with a Delivery Acceptance Sheet (DAS) - (Annex B) signed by the Contractor and project authority.

If the contractor fails to meet the agreed Acceptance criteria for any task, the NCI Agency reserves the right to withhold payment for that task/sprint.

5 DELIVERABLES AND PAYMENT MILESTONES

The following deliverables are expected from this statement of work:

1. Complete the activities/tasks agreed in each sprint meeting as per sections 3 and 4 above.

2. Produce sprint completion reports (format: e-mail update) or the formal documentation required per specific task;

3. The Contractor will participate in the daily reporting and planning activities (daily stand-ups) as well as the required participation in workshops, events and conferences related to the supported services, as requested by the Senior Service Delivery Manager.

4. Payments shall be made in accordance with the agreed milestones, subject to the completion and validation of each sprint and contingent upon acceptance of the monthly sprint report following every four consecutive sprints.

5. The Purchaser (NCIA) reserves the right to exercise a number of options of one or more sprints based on the same scrum deliverables, at a later time, depending on the project priorities and requirements, at the following cost: for base year (2025) at the same cost, for outer years (2026-2028) the Price Adjustment Formula will be applied in accordance with paragraph 6.5 of the Framework Contract Special Provisions.

6. The payment shall be dependent upon successful acceptance of the Delivery Acceptance Sheet (DAS) – (Annex B)

7. Invoices shall be accompanied with a Delivery Acceptance Sheet (Annex B) signed by the Contractor and the NCIA PoC.

The following deliverables are expected from the service on this statement of work:

2025 BASE: 13 OCTOBER 2025 TO 31 DECEMBER 2025

Deliverable: 12 sprints

Payment Milestones: Upon completion of each fourth sprint and at the end of the work. Completion of each sprint shall be documented in the Delivery Acceptance Sheet (DAS) – (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor.

2026 OPTIONS: 01 January 2026 to 31 December 2026

Deliverable: Up to 46 sprints

Cost Ceiling: Price will be determined by applying the price adjustment formula as outlined in CO‐115786‐ AAS+ Special Provisions article 6.5.

Payment Milestones: Upon completion of each fourth sprint and at the end of the work. Completion of each sprint shall be documented in the Delivery Acceptance Sheet (DAS) – (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor.

2027 OPTIONS: 01 January 2027 to 31 December 2027

Deliverable: Up to 46 sprints

Cost Ceiling: Price will be determined by applying the price adjustment formula as outlined in CO‐115786‐ AAS+ Special Provisions article 6.5.

Payment Milestones: Upon completion of each fourth sprint and at the end of the work. Completion of each sprint shall be documented in the Delivery Acceptance Sheet (DAS) – (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor.

2028 OPTIONS: 01 January 2028 to 31 December 2028

Deliverable: Up to 46 sprints

Cost Ceiling: Price will be determined by applying the price adjustment formula as outlined in CO‐115786‐ AAS+ Special Provisions article 6.5.

Payment Milestones: Upon completion of each fourth sprint and at the end of the work. Completion of each sprint shall be documented in the Delivery Acceptance Sheet (DAS) – (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor.

6 COORDINATION AND REPORTING

The contractor shall participate in daily status update meetings, activity planning and other meetings as instructed, via electronic means using Conference Call capabilities, according to the Cloud Operation Center Manager / Team Leaders instructions.

This contractor hired for this position will be part of the NCIA Cloud Operations Center Team.

7 SCHEDULE

This task order will be active immediately after signing of the contract by both parties

The BASE period of performance is as soon as possible but not later than 13th October 2025 and will end no later than 31st December 2025.

If the 2026 option is exercised, the period of performance is 01st January 2026 to 31st December 2026.

If the 2027 option is exercised, the period of performance is 01st January 2027 to 31st December 2027.

If the 2028 option is exercised, the period of performance is 01st January 2028 to 31st December 2028.

8 CONSTRAINTS

All the deliverables provided under this statement of work will be based on NCI Agency templates or agreed with the project point of contact.

All code, scripts, documentation, etc. will be stored under configuration management and/or in the provided NCI Agency tools.

9 SECURITY

To deliver services under this SoW a valid NATO SECRET security clearance is required.

All the deliverables of this project will be considered NATO UNCLASSIFIED, while access to networks exceeding this classification level is required.

With this role being of technical nature providing administrative support, a security clearance at the NATO Secret level is required prior to the start of the engagement.

10 PRACTICAL ARRANGEMENTS

Place of Performance: The contractor will be required to provide the service 100% off site NCI Agency.

The contractor will be required to provide the service within a NATO country, following the rules and regulations applicable for the operations of NATO CIS.

NCIA Recognised Business hours/Holidays: NCIA-Braine L’Alleud (BLA) official holiday schedule applies and will be provided to the contractor.

NCIA Hours of Operations: Monday to Thursday 0830 – 1730 and Friday 0830 – 1530 (CET)

Contractor Furnished Services: Contractor shall furnish everything required to perform the contract except for the items specified and covered under NCIA Furnished Property and Services below.

NCIA Furnished Property and Services: End-device (laptop); Access to relevant networks and environments will be provided by NCIA

Travel: The contractor is required to travel for the on-boarding and off-boarding to NATO offices in NATO HQ or Braine-l'Alleud as part of this role, for periods not exceeding 1 week.

The contractor might be required to travel to NATO offices in NATO HQ or Braine-l'Alleud every 6 months for periods not exceeding 1 week.

Travel will be the responsibility of the contractor and the expenses will be reimbursed in accordance with Article 5.5 of AAS Framework Contract and within the limits of the NCIA Travel Directive. The service provider, in accordance with the terms and conditions of the framework agreement, will invoice them separately to the purchaser. These additional travel costs are considered an extra charge to the overall bid price.

Others: The service depicted in this SOW is expected to be carried by a SINGLE PERSON.

11 QUALIFICATIONS

[See Requirements]

Requirements

9 SECURITY

  • To deliver services under this SoW a valid NATO SECRET security clearance is required. With this role being of technical nature providing administrative support, a security clearance at the NATO Secret level is required prior to the start of the engagement.

11 QUALIFICATIONS

The Support for DevSecOps Engineering requires an experienced DevSecOps Engineer with the following qualifications:

1) Technical Expertise:

  • In-depth knowledge of Microsoft Azure Cloud IaaS/PaaS Services;
  • Proficiency in designing, deploying and managing landing zones in Microsoft Azure by leveraging IaC and CI/CD pipelines;
  • Expertise in managing governance controls such as Azure Policy;
  • Experience in building, deploying and maintaining containerized workloads using Azure Kubernetes Services (AKS);
  • Experience in managing deploying and monitoring Azure Virtual Machines (VMs);
  • Expertise in enabling secure and reliable access to applications for end- users.

2) Analytical and Problem-Solving Skills:

  • Strong analytical skills to assess and improve DevSecOps processes and workflows;
  • Ability to troubleshoot complex Microsoft Azure Services issues and implement effective solutions.

3) Security and Compliance Knowledge:

  • Understanding of security best practices and compliance requirements related to Microsoft Azure services and DevSecOps practices;
  • Experience conducting audits and ensuring adherence to regulatory standards.

4) Communication and Collaboration:

  • Excellent communication skills to effectively collaborate with IT teams, stakeholders, and end-users;
  • Ability to document processes clearly and provide training on Microsoft Azure Services and DevSecOps practices.

5) Organizational Skills:

  • Strong organizational skills to manage multiple tasks and priorities effectively;
  • Attention to detail in managing user accounts, groups, and access controls.

6) Team Collaboration:

  • Ability to work effectively as part of a team and share knowledge and resources;
  • Willingness to collaborate with colleagues to solve complex issues.

7) Others:

  • The Contractor has strong customer relationship skills, including negotiating complex and sensitive situations under pressure;
  • Full proficiency in the English language. French language proficiency is of advantage.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Location requirements

Hiring timezones

Belgium +/- 0 hours

About EMW, Inc.

Learn more about EMW, Inc. and their company culture.

View company profile

EMW, Inc. stands at the forefront of systems integration, pioneering advanced solutions across critical sectors since its establishment in 1995. Through groundbreaking approaches, EMW is revolutionizing Health Information Technology (HIT), Cyber Security and Information Assurance, Perimeter Security, and Telecommunications Infrastructure. The company's innovative spirit is evident in its history of achievements, such as being the first to deploy a converged multi-service enterprise for 40,000 ports of data, voice over ATM, and video to support the Defense Information Systems Agency (DISA) in Eastern Europe. Furthermore, EMW led the way in deploying click-to-meet collaboration software for coalition forces, enhancing operational capabilities worldwide. This commitment to innovation ensures that EMW provides secure, cutting-edge connectivity solutions to both private and public sector organizations globally, adapting to complex and challenging environments with agility and expertise. EMW's dedication to quality is underscored by its certifications in ISO 9001:2015, ISO 20001-1:2011, and ISO 27001:2013, ensuring a full range of processes and procedures are in place to deliver superior products and services.

At EMW, the drive for technological advancement is embedded in its core. The company leverages its deep understanding of lifecycle Systems Engineering and Technical Assistance (SETA), Engineering and Installation (E&I), and Operations and Maintenance (O&M) to deliver robust and future-proof solutions. EMW's team, comprising seasoned professionals from leading systems integration, telecommunications, and R&D entities like Northrop Grumman, Lucent, Sprint, AT&T, and Bell Labs, consistently pushes the boundaries of what's possible. Their expertise spans the design, integration, deployment, and management of a full spectrum of sensors, access control systems, and countermeasure systems. By staying abreast of emerging technologies and maintaining a vigilant eye on future trends, EMW ensures its solutions not only meet current demands but are also prepared for the challenges of tomorrow. This proactive stance solidifies its reputation as a 'go-to' organization for rapid response requirements in support of expeditionary needs for US Department of Defense (DoD), NATO, and US Federal Civilian organizations across multiple continents. EMW's sound organizational infrastructure, encompassing human resources, contract management, finance, and project control, further enables its global responsiveness and adaptability.

Claim this profileEMW, Inc. logoEI

EMW, Inc.

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

4 remote jobs at EMW, Inc.

Explore the variety of open remote roles at EMW, Inc., offering flexible work options across multiple disciplines and skill levels.

View all jobs at EMW, Inc.

Remote companies like EMW, Inc.

Find your next opportunity by exploring profiles of companies that are similar to EMW, Inc.. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
EMW, Inc. hiring 2025-0303 Support for DevSecOps Engineering (NS) - THU 11 Sep • Remote (Work from Home) | Himalayas