Focus: Hands-on pipeline migration from Jenkins to GitHub Actions, complex Java/OSGi build refactoring, JFrog artifact management, and embedded security enforcement.
Key Responsibilities
- Refactor and migrate complex legacy Jenkins pipelines (including Groovy scripts and shared libraries) into modular, reusable GitHub Actions workflows with native JFrog integration.
- Resolve intricate Java OSGi dependency graphs, Manifest header configurations, package import/export relationships, and multi-Release Unit (RU) artifact resolution within automated pipelines.
- Configure JFrog Artifactory repositories, build-info metadata publishing, and automated artifact promotion pipelines for OSGi bundles and container images.
- Embed automated shift-left security controls—including static code checks, software composition analysis (SCA), container vulnerability scanning, and secret detection—directly into GitHub pull request gates.
- Provision, configure,
and optimize high-performance self-hosted or ephemeral GitHub runner fleets specifically tuned for heavy multi-package Java/OSGi compilation and dependency caching.
- Implement pipeline telemetry, build cache optimization via JFrog, and audit logging to maximize developer velocity and regulatory compliance.
Key Qualifications
- 4+ years in DevSecOps with deep, hands-on experience in both legacy Jenkins pipeline management and modern GitHub Actions workflow creation.
- Solid technical background in Java build orchestration (Maven), OSGi bundle mechanics (Manifest headers, package exports/imports, bundle resolution), and complex multi-module dependency graphs.
- Hands-on proficiency with JFrog Artifactory for enterprise artifact management, dependency resolution, and release lifecycle promotion.
- Direct experience executing Jenkins-to-GitHub Actions migrations while embedding security controls without blocking developer velocity.