JOB PURPOSE
• Operate and maintain DevSecOps toolchain platforms supporting software development, security scanning, CI/CD automation, and delivery pipeline operations within the enterprise BSS managed services environment.
• Ensure continuous availability and operational effectiveness of DevSecOps tools used by BSS delivery and operations teams.
DUTIES AND RESPONSIBILITIES
• Operate and maintain DevSecOps toolchain: GitLab, Jenkins, Nexus, SonarQube, Anchore/Trivy, OWASP ZAP, Snyk, or equivalent.
• Administer CI/CD pipelines used for BSS application build, test, and deployment automation.
• Manage container image registries (Harbor, Quay, DockerHub) and artifact repositories (Nexus, JFrog Artifactory).
• Monitor DevSecOps platform health, pipeline execution success rates, and tool availability.
• Troubleshoot CI/CD pipeline failures, build errors, test execution issues, and deployment failures.
• Manage and maintain code quality gates and security scan policies in the pipeline.
• Operate vulnerability management tools: prioritize findings from SAST, DAST, SCA scans.
• Administer source code management (SCM) platform: GitLab/GitHub repository access, branch policies, merge request rules.
• Support integration of DevSecOps toolchain with ITSM, monitoring, and collaboration platforms.
• Perform toolchain upgrades, patches, and configuration changes under Change Management.
• Maintain DevSecOps toolchain documentation, pipeline run-books, and onboarding guides.
• Report on pipeline metrics: build success rate, deployment frequency, change failure rate, MTTR.
• Ensure DevSecOps tool access is governed per IAM and security policies.
SKILLS & EXPERIENCE
• 5–8 years of experience in DevOps/DevSecOps engineering.
• Expert knowledge of CI/CD platforms: Jenkins, GitLab CI, GitHub Actions, or Tekton.
• Experience with security tooling: SonarQube, OWASP ZAP, Snyk, Trivy, or equivalent SAST/DAST/SCA tools.
• Container and Kubernetes expertise: Docker, Podman, Kubernetes, OpenShift.
• Experience with artifact management: Nexus, JFrog Artifactory.
• Scripting skills: Python, Bash, Groovy (Jenkins pipelines).
• Knowledge of infrastructure-as-code: Ansible, Terraform, Helm.
• Understanding of OWASP security principles and DevSecOps best practices.
• ITIL change management awareness for toolchain modifications.
• English skills – oral and written.