- Evaluate, build, and maintain GitHub Actions pipelines to compile C/C++/JAVA projects and run CodeQL + Coverity scans (PR gates and scheduled).
- Tune CodeQL queries and Coverity rules, reduce false positives, and create custom detections where needed.
- Automate triage, reporting, and remediation flows (PR checks, ticketing, dashboards).
- Operate scan infrastructure (runners/containers/cloud), secure CI secrets, and optimize run time to meet shift left strategy goals.
- Engage with cross team engineers on secure coding and enable shift-left practices; deliver documentation and onboarding playbooks.
- Troubleshoot analyzer/CI failures and hand off stable processes to the platform team.
Must-have (contract requirements):
- Senior-level experience with moderate to strong C++ (modern) debug skills.
- Proven hands-on experience with CodeQL(must) and/or Coverity in production.
- Deep GitHub Actions (or similar CI) automation experience with GHAS familiarity.
- Scripting (bash/Python), Docker, Kubernetes, and basic cloud competency.
- Explicit communicator able to drive cross-team remediation.
- Self-driven and motivated on driving org wide security and quality improvement solutions and strategies aligning with the leadership.
Nice-to-have:
- Experience authoring custom CodeQL queries and Coverity rules.
- Enterprise CI optimization (caching, distributed builds).
- Familiarity with observability/metrics.
- Build systems(Gradle build system, make, cmake, bazel, nmake etc), Compilers(GCC, Protoc, Visual studio CL) etc.
📌 Devops Developer (Hyderabad)
🏢 NR Consulting
📍 Hyderabad
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.