Role summary
Build and standardize enterprise CI/CD and platform automation using Azure DevOps Server, integrating security scanning, artifact management, IaC, GitOps delivery to OpenShift/Kubernetes, and monitoring readiness.
Key responsibilities
• Configure project boards to track security vulnerabilities as work items, ensuring compliance is part of the sprint backlog and SDLC.
• Manage secure Git repositories, enforce branch policies (e.g., mandatory pull request reviews), and monitor for secret leakage.
• Implement reusable pipeline templates and shared libraries in Azure DevOps Server.
• Integrate JFrog Artifactory for NuGet/Maven/NPM/Gradle/Docker artifacts.
• Embed Fortify SAST/DAST scanning stages and policy-based gating.
• Implement secrets integration using HashiCorp Vault and access patterns aligned with SecurEnvoy MFA.
• Expertise in containerization and orchestration technologies, specifically Kubernetes and Docker.
• Provision environments using Terraform (IaC) and configuration via Ansible.
• Familiarity with scripting/programming languages (e.g., Python, Bash, PowerShell) for automation tasks.
• Enable GitOps deployment using Argo CD to OpenShift/Kubernetes.
• Integrate monitoring hooks (AppDynamics/BMC/Azure Monitoring) and contribute to runbooks.
Requirements
Required experience
6–10+ years DevOps/SRE experience with enterprise CI/CD. Government/regulatory sector experience is a plus. Strong hands-on production delivery exposure (not only labs).
Technical skills
CI/CD pipeline engineering, agent pools, branching strategies, secure pipeline patterns, containerization (Docker), K8s/OpenShift, IaC, Linux, and scripting. Integrate with Open Text Security tools, manage third-party libraries, integrate with testing automation tools.
Soft skills
Cross-team collaboration with developers, security, and QA; coaching mindset; strong documentation and ownership.
Core skills / tooling
Azure DevOps Server, JFrog Artifactory, Fortify SCA, HashiCorp Vault, Terraform, Ansible, OpenShift/Kubernetes, Argo CD, Sigstore/Envoy MFA (plus), and monitoring (AppDynamics/BMC/Azure Monitoring).