10 Oct
|
Artech Infosystems
|
India
10 Oct
Artech Infosystems
India
Description: Skills: Dev Ops Engineer (Dev SecOps / Secure Software Delivery)
Required Technical Skill Set Secure CI/CD Pipelines, SAST & DAST Tooling, Dependency & Software Composition Analysis (SCA), Secrets Detection, Policy as Code & Automated Quality Gates (OPA / Rego / Checkov), Secure Software Delivery Lifecycle (SSDLC), Container & Cloud Security, Python / Bash / Scripting, Infrastructure as Code (Terraform)
Desired Experience Range: 7 – 12 Years (with strong focus on CI/CD engineering, pipeline security controls, automated testing gates, and Policy as Code)
Role Descriptions:
Must-Have (Candidates must demonstrate depth in core Dev Ops engineering and a blend/combination of the following specialisms)
• Secure CI/CD Pipeline Engineering: Extensive hands-on experience designing, automating, and maintaining resilient CI/CD pipelines across enterprise platforms (Git Hub Actions, Git Lab CI, Azure Dev Ops, Jenkins, Harness).
• Application Security Testing (SAST / DAST / SCA): Practical experience embedding and operationalising automated security scanners natively into pipeline workflows: Static Application Security Testing (Sonar Qube, Checkmarx, Snyk Code, Veracode), Dynamic Application Security Testing (ZAP, Burp Suite, Rapid7, Stack Hawk), and Software Composition Analysis / Dependency Scanning (Snyk Open Source, Black Duck, Dependabot, Nexus Lifecycle).
• Policy as Code & Automated Quality Gates: Proven track record authoring and enforcing declarative compliance policies and release gates using Open Policy Agent (OPA), Rego, Checkov, tfsec, Terrascan, or Kyverno to block non-compliant code before deployment.
• Secrets Detection & Management:
Experience implementing automated pre-commit and pipeline secrets detection (Git Guardian, Truffle Hog, Gitleaks) and integrating enterprise secrets management systems (Hashi Corp Vault, Azure Key Vault, AWS Secrets Manager, GCP Secret Manager).
• Secure Software Delivery & Container Security: Deep understanding of container image scanning, vulnerability triage, runtime security baselines, and artifact signing (Trivy, Grype, Prisma Cloud, Cosign / Sigstore).
• Scripting & Infrastructure as Code: Strong proficiency in Python, Bash, or Go for automation scripting, coupled with hands-on Terraform / Ansible experience for reproducible infrastructure provisioning.
Valuable-to-Have
• Understanding of enterprise Secure Software Development Lifecycle (SSDLC) operating models, specifically Inner Loop (developer workstation/IDE feedback) vs. Outer Loop (governed platform gates and continuous compliance) paradigms.
• Knowledge of Software Bill of Materials (SBOM) generation, supply chain integrity frameworks (SLSA, NIST SSDF), and artifact provenance tracking.
• Exposure to multi-cloud landing zones and Kubernetes orchestration (GKE, AKS, EKS).
• Certifications: Certified Dev SecOps Professional (CDP), Git Hub Actions / Azure Dev Ops Certified, Hashi Corp Certified Terraform Associate, or AWS/Azure/GCP Security Specialty.
Custom Fields:
Name: Work Assignment Location
Value: Onsite
Name: Business Vertical
Value: CL-BFSI-UK-EMEA-APAC
Name: Child
Value: IS-BFSI-UK1-1.1
Name: Type of Asset
Value: None
Name: Work Location CDF
Value: ~TRIL - Infopark - SEZ~
Name: Parent
Value: IS-BFSI-UK1-Parent
📌 IND_Technical Architect (India)
🏢 Artech Infosystems
📍 India