DevOps Track Sr.Engineer
Summary
Design and maintain CI/CD pipelines in Azure DevOps, integrating security scanning (Snyk, WIZ, DAST) and code quality tools (SonarQube) to automate builds, tests, and deployments across environments.
Own server and platform patching cycles across environments Key Responsibilities 1. CI/CD Strategy and Framework · Define and implement a standardized CI/CD framework aligned to trunk-first development and immutable deployment principles · Establish maturity model for pipelines, including progressive adoption of automation and controls (L0 to L3) · Define and enforce branching strategy, PR standards, and pipeline governance · Design reusable pipeline templates to ensure consistency across all applications · Introduce and operationalize soft gates and hard gates, aligned to release confidence and risk levels 2. Engineering Standards and Controls · Embed engineering standards into CI/CD pipelines, including: o Code quality and maintainability (SonarQube) o Security scanning (Snyk, WIZ, DAST) o Dependency and vulnerability management · Ensure all pipelines enforce required controls before merge and release · Define release candidate criteria and gating expectations · Drive “build once, promote” discipline across environment 3. Toolchain Integration and Automation · Lead integration of core engineering tools into pipelines, including: o Azure DevOps (repos, pipelines, branch policies) o Git-based workflows and PR enforcement o SonarQube quality gates o Snyk for SCA/SAST o WIZ for secrets and security posture o DAST for runtime vulnerability scanning · Automate workflows to reduce manual effort and improve reliability · Build reusable “skills” and automation patterns to support PR validation, documentation as code, and compliance checks 4. Hands-on Pipeline Engineering · Design and implement CI/CD pipelines using Azure DevOps · Create modular, reusable YAML templates for build, test, and release pipelines · Implement automated testing integration, including unit, integration, and security testing · Ensure observability is built into pipelines, including logging, metrics, and failure diagnostics · Troubleshoot pipeline issues and optimize performance