Azure DevSecOps Specialist (Mumbai)

Azure DevSecOps Specialist (Mumbai)

17 Aug
|
Tuitions Tree
|
Mumbai

17 Aug

Tuitions Tree

Mumbai

Role: Azure DevSecOps Specialist with a Focus on Fortify and SonarQubeLocation: Vashi, Mumbai ( Work From Office )Experience: Minimum 10 Years of Experience in the IT industry and 3 to 5 years as an Azure DevOps EngineerNotice Period - 0 to 10 Days Maximum

Key Responsibilities:1.

Azure App

Service: o Web App Deployment: § Deploying web applications (ASP.NET, Node.js, Python, etc.). § Configuring custom domains and SSL certificates. § Scaling app service plans. o Continuous Integration/Continuous Deployment (CI/CD): § Setting up CI/CD pipelines using Azure DevOps or GitHub Actions. § Automating app deployments. o Deployment and Scaling: § Deploy code updates using deployment slots. § Scale out/in based on demand (manual or auto-scaling). § Monitor resource utilization and adjust accordingly. o Configuration Management: § Manage app settings, connection strings, and environment variables. § Set up custom domains and SSL certificates. § Configure authentication and authorization. 2.

Log Analytics: o Data Collection and Queries: § Set up data collection from Azure resources. § Write custom queries to analyze logs. § Create alerts based on query results. o Workspace Management: § Manage Log Analytics workspaces. § Adjust retention settings for log data. 3.

Logic

Apps: o Workflow Design and Deployment: § Create logic app workflows using connectors. § Configure triggers and actions. § Monitor workflow runs and troubleshoot failures.

4.

Reporting

Tasks: o Monthly Security Summary Report: § Generate a monthly report summarizing security posture. § Include details on vulnerabilities, incidents, and compliance. § Share with relevant stakeholders (security teams, management).

o Custom Dashboards: § Create custom dashboards in Azure Monitor. § Visualize security metrics, threat trends, and compliance status. 5.

Process

Automation: o Runbook Creation and Execution: § Design and deploy automation runbooks. § Schedule and trigger runbook executions. § Monitor job status and logs. 6. Automation using Azure Resource Manager (ARM):

o ARM Template Development and Maintenance: § Create and Update Templates: Develop ARM templates for your infrastructure components (VMs, networks, storage, etc.). § Version Control: Store templates in a version-controlled repository (e.g., Git). § Review and Refactor: Regularly review and refactor templates to ensure consistency and best practices. o Azure DevOps Pipeline Configuration: § Pipeline Creation: Set up an Azure DevOps pipeline for your project. § Pipeline Variables: Define variables for template parameters (e.g., resource names, locations). § Environment-Specific Pipelines: Create separate pipelines for different environments (dev, test, prod). o Deployment Testing: § Test Deployments: Run test deployments using the pipeline. § Validation Checks: Validate that deployed resources match the expected state. § Rollback Testing: Test rollback scenarios to ensure a successful recovery. Monitoring Tasks: o Pipeline Execution Monitoring: § Pipeline Runs: Monitor pipeline runs for successful execution. § Logs and Artifacts: Review logs and artifacts generated during deployments.



§ Pipeline Triggers: Monitor triggers (manual, scheduled, or CI/CD). o Resource Monitoring: § Azure Monitor Integration: Set up monitoring for deployed resources. § Metrics and Alerts: Monitor resource health, performance, and usage. § Alert Rules: Configure alerts for critical events (e.g., resource failures).

Reporting Tasks: o Deployment Reports: § Deployment History: Maintain a record of successful and failed deployments. § Deployment Summary: Generate a summary report showing the resources deployed in each environment. o Compliance Reports: § Policy Compliance: Validate that deployed resources adhere to organizational policies. § Security Baselines: Check compliance with security baselines (e.g., CIS, NIST). 7.

Azure

Devops, Fortify and Sonarqube Azure DevOps: Operational Tasks: o Pipeline Configuration: o Set up CI/CD pipelines for your projects. o Define build and release stages. o Configure triggers (manual, scheduled, or based on code changes). o Artifact Management: o Publish and manage build artifacts (e.g., binaries, packages). o Set retention policies for artifacts. o Environment Provisioning: o Automate environment provisioning using Infrastructure as Code (IaC) tools (e.g., ARM templates, Terraform). o Ensure consistency across environments (dev, test, prod).

Monitoring Tasks: o Pipeline Execution Monitoring: o Monitor pipeline runs for successful execution. o Review logs, artifacts, and test results. o Set up alerts for pipeline failures. o Code Quality and Testing: o Integrate static code analysis tools (e.g., SonarQube) into your pipelines. o Monitor code quality metrics (e.g., code smells, security vulnerabilities). Fortify:

Operational Tasks: o Static Application Security Testing (SAST): o Set up Fortify scans for your codebase. o Define scan policies (e.g., rulesets, severity thresholds). o Schedule regular scans (e.g., nightly builds). o ��Results Management: o Review Fortify scan results. o Prioritize and triage findings. o Assign remediation tasks to developers.

Monitoring Tasks: o Scan Execution Monitoring: o Monitor scan execution times. o Detect any failures or issues during scans. o Set up alerts for critical findings. o Trend Analysis: o Track code quality improvements over time. o Monitor reduction in vulnerabilities.

SonarQube

Operational Tasks: o Static Code Analysis: o Set up SonarQube to analyze your codebase. o Configure quality profiles and rules. o Integrate SonarQube into your CI/CD pipelines. o Quality Gate Configuration: o Define quality gate conditions (e.g., code coverage, code smells, security issues). o Set thresholds for pass/fail criteria.

Monitoring Tasks: o Quality Gate Monitoring: o Monitor quality gate status for each build. o Detect regressions or violations.



o Set up notifications for failed quality gates. o Resource Utilization: o Monitor SonarQube server memory, CPU, and disk usage. o Adjust memory settings if needed. 8. Reporting: o Daily Operational Reports: o Azure Monitor Reports: § Review daily health, performance, and usage metrics for your Azure resources. § Check for any critical alerts or anomalies. § Investigate and address issues promptly. o Azure Service Health: § Check for active issues or planned maintenance affecting your services. § Stay informed about any service disruptions. o Custom Dashboards: § Create daily dashboards with real-time data for quick insights. § Monitor key metrics relevant to your business operations. o Weekly Operational Reports: o Azure Advisor Recommendations: § Analyze weekly recommendations for optimizing your Azure environment. § Implement suggested changes to improve efficiency and cost savings. o Application Insights Reports: § Review weekly application availability, response times, and error rates. § Identify areas for improvement in your applications. o Security Center Alerts: § Check for security alerts related to your resources. § Investigate any suspicious activities. o Monthly Operational Reports: o Cost Management Reports: § Analyze monthly spending patterns. § Identify cost-saving opportunities. § Review budget adherence. o Resource Usage Reports: § Evaluate resource utilization over the month. § Adjust resource allocations as needed. § Plan for scaling or optimization. o Service Health History: § Look back at any historical service disruptions. § Understand their impact on your operations. § Learn from past incidents.

Key Qualifications: 1. Certifications: o Microsoft Certified: Azure DevOps Engineer Expert. o Certified Information Systems Security Professional (CISSP) or equivalent. o Relevant certifications for Fortify and SonarQube (if available). 2.

Technical

Skills: o Azure DevOps: § Proficiency in Azure DevOps, including pipelines, repositories, and artifacts. § Experience with Infrastructure as Code (IaC) using tools like Terraform or Azure Resource Manager (ARM) templates. o Fortify: § Hands-on experience with Fortify SAST tools and security scanning. § Knowledge of vulnerability management and remediation techniques. o SonarQube: § Experience integrating and managing SonarQube for code analysis. § Understanding of code quality metrics and security 3.

Security and Development Expertise: o Secure Coding Practices: § Strong understanding of secure coding principles and practices. § Knowledge of common security vulnerabilities (e.g., OWASP Top Ten). o DevSecOps Practices: § Experience implementing DevSecOps practices in a CI/CD environment. § Familiarity with security tools and technologies used in DevSecOps. 4.

Communication and Collaboration: o Team Collaboration: § Solid collaboration skills to work effectively with cross-functional teams. § Ability to communicate security requirements and issues clearly to developers and stakeholders. o Documentation Skills: § Excellent documentation skills for creating detailed security reports, policies, and procedures.

📌 Azure DevSecOps Specialist (Mumbai)
🏢 Tuitions Tree
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: azure devsecops specialist (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: azure devsecops specialist (mumbai) / mumbai