We are looking for a DevSecOps Engineer (Lead level) to establish and manage the CI/CD infrastructure and DevSecOps practices for a large-scale ESB-to-AWS-native migration. The role involves building automated pipelines using Bitbucket, AWS CodeBuild, CodePipeline, ECR, and ArgoCD to deploy Apache Camel routes on EKS, Lambda functions, Step Functions, CDK stacks, and EventBridge configurations across environments. The candidate will embed security scanning, vulnerability assessment, and compliance checks into the pipeline. Experience with containerized deployments on EKS, GitOps (ArgoCD), and AWS-native CI/CD tooling is essential.
CI/CD Pipeline Design & Implementation
- Build and maintain CI/CD pipelines using Bitbucket → CodeBuild → CodePipeline → ECR → ArgoCD for EKS-based Camel/Spring Boot deployments.
- Automate deployment of CDK stacks for API Gateway, EventBridge, SQS, S3, Transfer Family, and Lambda resources.
- Enable multi-environment promotion with gated approvals.
Security & Compliance Integration
- Integrate AWS Inspector for container vulnerability scanning and dependency checks.
- Implement secrets management (AWS Secrets Manager), certificate management (ACM Public/Private CA for mTLS), and KMS encryption.
- Enforce IAM least-privilege policies and security guardrails across all deployment pipelines.
Infrastructure as Code & Drift Detection
- Manage AWS CDK stacks for all infrastructure provisioning — ensure version-controlled, repeatable deployments.
- Implement AWS Config drift detection to prevent configuration inconsistencies across environments.
Platform Operations & Observability
- Set up pipeline monitoring and alerting using CloudWatch metrics and alarms.
- Support integration of OpenTelemetry instrumentation into build pipelines for automated observability setup.
Required Skills & Competencies
- 8–12 years of IT experience with at least 4–5 years in DevOps/DevSecOps roles on AWS
- Solid hands-on experience with AWS CI/CD services
- Exp