17 Aug
|
Tuitions Tree
|
Mumbai
17 Aug
Tuitions Tree
Mumbai
Role: Azure DevSecOps Specialist with a Focus on Fortify and SonarQubeLocation: Vashi, Mumbai ( Work From Office )Experience: Minimum 10 Years of Experience in the IT industry and 3 to 5 years as an Azure DevOps EngineerNotice Period - 0 to 10 Days Maximum
Key Responsibilities:1.
Azure App
Service: o Web App Deployment: § Deploying web applications (ASP.NET, Node.js, Python, etc.). § Configuring custom domains and SSL certificates. § Scaling app service plans. o Continuous Integration/Continuous Deployment (CI/CD): § Setting up CI/CD pipelines using Azure DevOps or GitHub Actions. § Automating app deployments. o Deployment and Scaling: § Deploy code updates using deployment slots. § Scale out/in based on demand (manual or auto-scaling). § Monitor resource utilization and adjust accordingly. o Configuration Management: § Manage app settings, connection strings, and environment variables. § Set up custom domains and SSL certificates. § Configure authentication and authorization. 2.
Log Analytics: o Data Collection and Queries: § Set up data collection from Azure resources. § Write custom queries to analyze logs. § Create alerts based on query results. o Workspace Management: § Manage Log Analytics workspaces. § Adjust retention settings for log data. 3.
Logic
Apps: o Workflow Design and Deployment: § Create logic app workflows using connectors. § Configure triggers and actions. § Monitor workflow runs and troubleshoot failures.
4.
Reporting
Tasks: o Monthly Security Summary Report: § Generate a monthly report summarizing security posture. § Include details on vulnerabilities, incidents, and compliance. § Share with relevant stakeholders (security teams, management).
o Custom Dashboards: § Create custom dashboards in Azure Monitor. § Visualize security metrics, threat trends, and compliance status. 5.
Process
Automation: o Runbook Creation and Execution: § Design and deploy automation runbooks. § Schedule and trigger runbook executions. § Monitor job status and logs. 6. Automation using Azure Resource Manager (ARM):
o ARM Template Development and Maintenance: § Create and Update Templates: Develop ARM templates for your infrastructure components (VMs, networks, storage, etc.). § Version Control: Store templates in a version-controlled repository (e.g., Git). § Review and Refactor: Regularly review and refactor templates to ensure consistency and best practices. o Azure DevOps Pipeline Configuration: § Pipeline Creation: Set up an Azure DevOps pipeline for your project. § Pipeline Variables: Define variables for template parameters (e.g., resource names, locations). § Environment-Specific Pipelines: Create separate pipelines for different environments (dev, test, prod). o Deployment Testing: § Test Deployments: Run test deployments using the pipeline. § Validation Checks: Validate that deployed resources match the expected state. § Rollback Testing: Test rollback scenarios to ensure a successful recovery. Monitoring Tasks: o Pipeline Execution Monitoring: § Pipeline Runs: Monitor pipeline runs for successful execution. § Logs and Artifacts: Review logs and artifacts generated during deployments.
§ Pipeline Triggers: Monitor triggers (manual, scheduled, or CI/CD). o Resource Monitoring: § Azure Monitor Integration: Set up monitoring for deployed resources. § Metrics and Alerts: Monitor resource health, performance, and usage. § Alert Rules: Configure alerts for critical events (e.g., resource failures).
Reporting Tasks: o Deployment Reports: § Deployment History: Maintain a record of successful and failed deployments. § Deployment Summary: Generate a summary report showing the resources deployed in each environment. o Compliance Reports: § Policy Compliance: Validate that deployed resources adhere to organizational policies. § Security Baselines: Check compliance with security baselines (e.g., CIS, NIST). 7.
Azure
Devops, Fortify and Sonarqube Azure DevOps: Operational Tasks: o Pipeline Configuration: o Set up CI/CD pipelines for your projects. o Define build and release stages. o Configure triggers (manual, scheduled, or based on code changes). o Artifact Management: o Publish and manage build artifacts (e.g., binaries, packages). o Set retention policies for artifacts. o Environment Provisioning: o Automate environment provisioning using Infrastructure as Code (IaC) tools (e.g., ARM templates, Terraform). o Ensure consistency across environments (dev, test, prod).
Monitoring Tasks: o Pipeline Execution Monitoring: o Monitor pipeline runs for successful execution. o Review logs, artifacts, and test results. o Set up alerts for pipeline failures. o Code Quality and Testing: o Integrate static code analysis tools (e.g., SonarQube) into your pipelines. o Monitor code quality metrics (e.g., code smells, security vulnerabilities). Fortify:
Operational Tasks: o Static Application Security Testing (SAST): o Set up Fortify scans for your codebase. o Define scan policies (e.g., rulesets, severity thresholds). o Schedule regular scans (e.g., nightly builds). o ��Results Management: o Review Fortify scan results. o Prioritize and triage findings. o Assign remediation tasks to developers.
Monitoring Tasks: o Scan Execution Monitoring: o Monitor scan execution times. o Detect any failures or issues during scans. o Set up alerts for critical findings. o Trend Analysis: o Track code quality improvements over time. o Monitor reduction in vulnerabilities.
SonarQube
Operational Tasks: o Static Code Analysis: o Set up SonarQube to analyze your codebase. o Configure quality profiles and rules. o Integrate SonarQube into your CI/CD pipelines. o Quality Gate Configuration: o Define quality gate conditions (e.g., code coverage, code smells, security issues). o Set thresholds for pass/fail criteria.
Monitoring Tasks: o Quality Gate Monitoring: o Monitor quality gate status for each build. o Detect regressions or violations.
o Set up notifications for failed quality gates. o Resource Utilization: o Monitor SonarQube server memory, CPU, and disk usage. o Adjust memory settings if needed. 8. Reporting: o Daily Operational Reports: o Azure Monitor Reports: § Review daily health, performance, and usage metrics for your Azure resources. § Check for any critical alerts or anomalies. § Investigate and address issues promptly. o Azure Service Health: § Check for active issues or planned maintenance affecting your services. § Stay informed about any service disruptions. o Custom Dashboards: § Create daily dashboards with real-time data for quick insights. § Monitor key metrics relevant to your business operations. o Weekly Operational Reports: o Azure Advisor Recommendations: § Analyze weekly recommendations for optimizing your Azure environment. § Implement suggested changes to improve efficiency and cost savings. o Application Insights Reports: § Review weekly application availability, response times, and error rates. § Identify areas for improvement in your applications. o Security Center Alerts: § Check for security alerts related to your resources. § Investigate any suspicious activities. o Monthly Operational Reports: o Cost Management Reports: § Analyze monthly spending patterns. § Identify cost-saving opportunities. § Review budget adherence. o Resource Usage Reports: § Evaluate resource utilization over the month. § Adjust resource allocations as needed. § Plan for scaling or optimization. o Service Health History: § Look back at any historical service disruptions. § Understand their impact on your operations. § Learn from past incidents.
Key Qualifications: 1. Certifications: o Microsoft Certified: Azure DevOps Engineer Expert. o Certified Information Systems Security Professional (CISSP) or equivalent. o Relevant certifications for Fortify and SonarQube (if available). 2.
Technical
Skills: o Azure DevOps: § Proficiency in Azure DevOps, including pipelines, repositories, and artifacts. § Experience with Infrastructure as Code (IaC) using tools like Terraform or Azure Resource Manager (ARM) templates. o Fortify: § Hands-on experience with Fortify SAST tools and security scanning. § Knowledge of vulnerability management and remediation techniques. o SonarQube: § Experience integrating and managing SonarQube for code analysis. § Understanding of code quality metrics and security 3.
Security and Development Expertise: o Secure Coding Practices: § Strong understanding of secure coding principles and practices. § Knowledge of common security vulnerabilities (e.g., OWASP Top Ten). o DevSecOps Practices: § Experience implementing DevSecOps practices in a CI/CD environment. § Familiarity with security tools and technologies used in DevSecOps. 4.
Communication and Collaboration: o Team Collaboration: § Solid collaboration skills to work effectively with cross-functional teams. § Ability to communicate security requirements and issues clearly to developers and stakeholders. o Documentation Skills: § Excellent documentation skills for creating detailed security reports, policies, and procedures.
📌 Azure DevSecOps Specialist (Mumbai)
🏢 Tuitions Tree
📍 Mumbai