DevSecOps Engineer
Summary
Design and maintain secure CI/CD pipelines, integrating security controls and scanning tools to ensure compliance and protect software delivery.
Introduction & Summary:
This role requires a dedicated DevSecOps Engineer with extensive expertise in CI/CD processes and security integration. The ideal candidate will demonstrate solid experience in developing and maintaining CI/CD pipelines, while ensuring security measures are embedded throughout the software development lifecycle.
Main Responsibilities:
The primary responsibility of this role is to design and optimize CI/CD pipelines while integrating necessary security protocols.
Design and maintain industrial CI/CD pipelines across multiple projects.
Implement security controls within CI/CD frameworks.
Manage dependency repositories effectively.
Ensure compliance with security standards.
Execute thorough security scanning of applications.
Key Requirements:
Strong experience in CI/CD (GitLab CI, Azure DevOps, Jenkins, or equivalent).
Ability to design and maintain industrial CI/CD pipelines.
Solid knowledge of dependency management and repositories (Artifactory or equivalent).
Experience integrating security controls into CI/CD pipelines.
Good knowledge or hands-on experience with SBOM (CycloneDX, SPDX, etc.).
Experience with JFrog Xray or similar security scanning tools.
Nice to Have:
Familiarity with GitHub.