NCS Australia

Technical Business Analyst (DevSecOps) - Contract

NCS Australia Sydney, New South Wales, Australia

Outsourcing and Offshoring Consulting · 201-500 employees

6 h ago
business-analyst Senior (5-10 yrs) Contractor Full-time Australia
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Technical Business Analyst will bridge the gap between security, engineering, and governance by translating enterprise security requirements into actionable technical specifications. They will also facilitate workshops and document DevSecOps frameworks to ensure seamless integration of security controls into CI/CD pipelines.

What they look for

DevSecOps Business Analysis CI/CD Application Security SAST SCA DAST Agile Scrum Stakeholder Management Cloud Cybersecurity Technical Documentation Governance Software Engineering OWASP Top 10

Requirements

Candidates must have a proven track record as a Business Analyst in complex software engineering or cybersecurity environments with strong knowledge of DevSecOps principles. Practical familiarity with application security standards like OWASP Top 10 and experience in Agile delivery are essential.

Benefits

Professional development Career growth opportunities Inclusive workplace

Full description

Company Description

At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.

We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.

Job Description

We are seeking a Technical Business Analyst with deep DevSecOps experience for an initial 6-month contract in Sydney to bridge the gap between application security, software engineering squads, and enterprise governance.

In this high-visibility delivery role, you will work embedded within engineering and security teams to translate enterprise security requirements into clear, actionable technical specifications. You will play a key role in integrating security controls, code scanning standards, and automated compliance directly into modern CI/CD software delivery pipelines.

Key Responsibilities

  • DevSecOps Process Mapping: Analyze current software development workflows to identify security bottlenecks, gaps, and opportunities to "shift left" security controls into the SDLC.
  • Requirements & User Stories: Translate complex application security policies, vulnerability management SLAs, and compliance standards into technical user stories, engineering epics, and acceptance criteria.
  • Security Tooling Integration: Partner with DevSecOps Engineers to scope and support the implementation of automated code scanning (SAST, SCA, DAST) and pipeline security gatekeepers.
  • Governance & Runbooks: Document DevSecOps frameworks, technical runbooks, operational support models, and developer guidance materials to ensure seamless platform adoption.
  • Stakeholder Alignment: Facilitate workshops between Security Architects, DevOps leads, Product Owners, and engineering squads to align delivery roadmaps with security posture goals.

Qualifications

Essential Experience:

  • Technical BA Background: Proven track record as a Business Analyst working within complex software engineering, cloud, or cybersecurity environments.
  • DevSecOps Knowledge: Strong understanding of DevSecOps principles, CI/CD pipelines, automated testing, and software security concepts.
  • AppSec Exposure: Practical familiarity with application security standards (e.g., OWASP Top 10) and code security scanning tools (SAST, SCA, DAST).
  • Agile Delivery: Experience writing technical user stories, managing backlogs, and working inside cross-functional Agile/Scrum delivery squads.
  • Communication & Collaboration: Outstanding stakeholder management skills with the ability to articulate technical security risks to non-technical business partners.

Additional Information

Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career.  Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own.  We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We'd love to hear from you.

We celebrate diversity and inclusion

We value different perspectives, experiences and strengths our people bring.  We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

  • Department: Digital Resilience

Similar roles