- Company Name
- AllSTEM Connections
- Job Title
- Senior DevOps Engineer
- Job Description
-
Job title: Senior DevSecOps Engineer
Role Summary:
Lead and mentor a DevSecOps team responsible for building, securing, and maintaining cloud-based CI/CD pipelines that support firmware and software delivery for high‑tech scientific monitoring equipment. Integrate automated security testing, vulnerability management, and compliance controls across the development lifecycle, ensuring secure and reliable product releases.
Expactations:
- Deliver secure cloud environments and CI/CD pipelines for firmware and software.
- Implement and enforce security and compliance practices, including vulnerability scanning, SBOM management, and threat modeling.
- Automate infrastructure provisioning and configuration using IaC and configuration‑management tools.
- Monitor pipeline health, manage binary repositories, and maintain logging/monitoring systems.
- Lead vulnerability management lifecycle and incident response within CI/CD and product releases.
- Engage cross‑functional teams to embed security into development, release strategies, and workflow improvements.
- Evaluate, procure, and upgrade DevOps/security tools, manage licensing, and negotiate vendor contracts.
- Build and expand a strong DevSecOps team through defining interview criteria, recruiting, mentoring, and continuous process improvement.
Key Responsibilities:
- Head a DevSecOps team focused on secure cloud and CI/CD pipeline development.
- Integrate SAST, DAST, SCA, SBOM, and other security tools into pipelines.
- Automate server, container, and infrastructure provisioning via IaC.
- Administer binary repositories and maintain CI/CD artifact integrity.
- Implement and manage Prometheus, Grafana, or equivalent monitoring and logging solutions.
- Conduct vulnerability investigations, remediation, and incident response.
- Optimize development workflows, release cycles, and automated testing environments.
- Ensure product releases meet internal and regulatory cyber‑security standards.
- Stay current on emerging security technologies, frameworks, and supply chain best practices.
- Source, evaluate, and negotiate costs of DevOps/security tools and vendors.
- Conduct technical interviews and build a cohesive, high‑performance DevSecOps team.
Required Skills:
- Deep knowledge of AWS or comparable cloud platforms.
- Proficiency in IaC (e.g., Terraform, CloudFormation) and configuration‑management tools (e.g., Ansible, Puppet).
- Strong scripting in Bash, Python, or PowerShell.
- Experience with containerization (Docker) and build tools (CMake, Make).
- Hands‑on CI/CD tools: Jenkins, GitHub Actions, Bitbucket Pipelines.
- Familiarity with monitoring/logging tools: Prometheus, Grafana.
- Implemented shift‑left security across product life cycles.
- Comprehensive understanding of cyber‑security principles, vulnerability management, and DevSecOps practices.
- Expertise in integrating security tools into pipelines (SAST, DAST, SCA, SBOM).
- Ability to analyze complex systems, troubleshoot, and root‑cause issues.
- Strong communication, collaboration, and team‑leadership skills.
- Experience interviewing and hiring engineering talent.
Required Education & Certifications:
- Bachelor of Science in Computer Science, Engineering, or related field.
- 5+ years as a DevSecOps or security‑focused DevOps Engineer, with ≥2 years in a technical lead role.
- Qualifications in embedded firmware or software development.
- Relevant certifications (e.g., AWS Certified DevOps Engineer, Certified DevSecOps Professional, CISSP, CISM) are preferred but not mandatory.