DevSecOps Lead / Sr Engineer

Role Summary

Hands-on engineer responsible for reviewing individual application repositories, understanding their build and deployment requirements, and implementing CI/CD pipelines against the approved reference architecture. Works directly in the organization's repositories to build, test, and roll out pipelines across both the containerized and on-premises/VM-hosted portions of the portfolio.

Key Responsibilities

Manually review each application's codebase to determine its build requirements: language/framework version, dependency structure, existing build scripts, and deployment target.

Hand-author CI workflows per application (GitHub Actions): build, automated test execution, SonarQube analysis, and the required security scanning stages.

Integrate Fortify (SAST), Sonatype (SCA), and Fortify WebInspect (DAST) into pipelines as parallel jobs/Sequential, and Wiz for container image scanning.

Build the Docker image and Helm chart update steps for containerized applications; build the equivalent installer/binary packaging and artifact steps for on-premises/VM-hosted applications.

Generate and publish a software bill of materials (SBOM) for each build and publish build artifacts and container images to Nexus, using the correct upload mechanism for each artifact type (Docker registry push vs. raw file upload).

Build and test Harness CD pipelines: progressive/blue-green rollout for containerized applications, and deployment for on-premises/VM-hosted applications.

Integrate automated test into CD pipelines.

Build ephemeral Kubernetes clusters (Azure) and Integrate IAC into pipelines.

Apply the approved reference pipeline template consistently across many repositories, adapting it where an application's structure genuinely requires a variance.

Troubleshoot build and pipeline failures - dependency conflicts, toolchain version mismatches, failing security gates - and resolve them application by application.

Document per-application pipeline decisions

Required Skills

5+ years in DevOps/DevSecOps engineering, with hands-on GitHub Actions experience at multi-repository scale.

Demonstrated ability to work across multiple languages, frameworks, and build systems - comfortable picking up an unfamiliar codebase's build tooling without requiring prior expertise in that specific stack.

Working knowledge of both modern, SDK/package-manager-driven build tooling and traditional/legacy build tooling, and the ability to diagnose toolchain version-related build failures in either.

Practical, hands-on experience integrating Fortify (SAST), Sonatype (SCA), and Fortify WebInspect (DAST) into CI pipelines.

Container image scanning experience with Wiz or a directly comparable tool.

Docker and Helm chart authoring; solid working knowledge of Kubernetes/AKS deployment.

SBOM generation (Syft, CycloneDX/SPDX) and artifact/container registry operations in Nexus, including both raw-file uploads and Docker registry pushes.

Experience in terraform or other Iac tools

Hands-on Harness pipeline configuration, and Ansible playbook experience for on-premises/VM deployment targets.

Strong YAML fluency and general-purpose scripting ability (Bash and/or PowerShell).

Comfortable reading unfamiliar or partially-documented codebases and determining their build/deployment requirements without relying on existing documentation.

Solid Git/GitHub proficiency, including PR-based workflows and code review practices.

Preferred

Prior hands-on use of SonarQube quality gates , Fortify, Automating Regression Test.

On-premises/VM-based server administration experience (e.g., IIS or equivalent).

Experience standardizing CI/CD templates across a large, multi-language application portfolio.

Knowledge of .Net core /.Net FX 4.8 Frameworks


DevSecOps Lead / Sr Engineer

Apply Now
Back to search page