06 Aug
|
SWITS DIGITAL Private
|
Chennai
06 Aug
SWITS DIGITAL Private
Chennai
Job Title: Senior DevSecOps Engineer Location: Chennai, India Education Level: Bachelor s degree or equivalent Experience: 7+ Years Role Overview We are looking for a Senior DevSecOps Engineer to design, build, and continuously improve our CI/CD pipelines with a strong emphasis on security, quality, and automation. In this role, you will be the driving force behind integrating security scanning, vulnerability management, and quality enforcement directly into the software delivery lifecycle. You will collaborate closely with development, architecture, and security teams to ensure that every release meets the highest standards of quality and compliance.
Key Responsibilities CI/CD Pipeline Management: Design, implement, and maintain end-to-end CI/CD pipelines in GitLab CI, ensuring reliability, performance, and security at every stage.
Artifact Management: Integrate and manage artifact repositories using JFrog Artifactory, including artifact staging, promotion workflows, and lifecycle policies. Define and manage artifact staging strategies to ensure controlled and traceable promotion of build artifacts from development through to production.
Code Quality & Testing: Configure and maintain SonarQube for static code analysis, enforcing quality gates that block non-compliant code from progressing through the pipeline. Implement and optimize unit test automation frameworks while ensuring seamless integration of test execution and reporting within CI/CD pipelines.
Quality & Security Enforcement: Build and enforce quality gates across all pipeline stages, incorporating code coverage thresholds, code smell limits, security vulnerability checks, and architectural compliance.
Vulnerability Management:
Integrate vulnerability management tooling such as Nexus IQ (Software Composition Analysis) and Fortify (Static Application Security Testing) into pipelines and quality gates.
Collaboration & Continuous Improvement: Collaborate with development and architecture teams to establish and enforce DevSecOps best practices across the organization. Monitor, troubleshoot, and continuously improve pipeline performance, reliability, and security posture.
Documentation: Document pipeline architectures, runbooks, and operational procedures to ensure knowledge sharing and team enablement.
Qualifications & Experience Requirements Work Experience: 7+ years of professional experience in DevOps, DevSecOps, or a related infrastructure/platform engineering role.
CI/CD & Artifact Management: Strong hands-on experience with GitLab CI/CD (pipeline design, optimization, and administration) and proven experience with JFrog Artifactory (repository configuration, artifact staging, and promotion workflows).
Static Analysis & Testing: In-depth knowledge of SonarQube (rule configuration, quality profiles, and quality gate definition) and solid experience in unit test automation and test framework integration (e.g., JUnit, NUnit, Jest) with automated reporting.
Vulnerability & Security Management: Hands-on experience integrating vulnerability management tools into pipelines specifically Sonatype Nexus IQ (SCA) and Micro Focus / OpenText Fortify (SAST).
DevSecOps Core Practices: Demonstrated experience enforcing quality gates (code quality, coverage, security thresholds), deep understanding of artifact staging concepts/controlled promotion across environments (Dev, QA, Staging, Production), and strong understanding of shift-left security and Secure Software Development Lifecycle (SSDLC) practices.
Scripting: Strong scripting and automation skills (e.g., Bash, Python, or Groovy). Technical & Behavioral Competencies Preferred Technical Skills Release Orchestration: Experience with platforms such as Digital.ai Release (formerly XL Release), including pipeline modeling, release tracking, and workplace management.
Architectural Compliance: Familiarity with quality enforcement tools and architectural compliance methods in pipelines (e.g., ArchLint, SonarLint, or custom linting rules integrated into IDE and CI workflows).
Containerization & IaC: Experience with container orchestration platforms (e.g., Kubernetes, OpenShift) and Infrastructure-as-Code tools (e.g., Terraform, Ansible).
Compliance & Observability: Knowledge of compliance frameworks (e.g., ISO 27001, SOC 2) for automated pipeline embedding, as well as monitoring tools (e.g., Prometheus, Grafana, ELK Stack) for pipeline and infrastructure health.
Certifications: Relevant certifications such as GitLab Certified CI/CD Associate, Certified Kubernetes Administrator (CKA), or security certifications (e.g., CompTIA Security+, CISSP) are a plus.
Key Behavioral Skills Collaboration: Excellent communication and ability to work effectively across cross-functional teams. Results-Driven: Strong focus on delivery, reliability, and maintaining high performance standards.
📌 Senior DevSecOps Engineer (Chennai)
🏢 SWITS DIGITAL Private
📍 Chennai