Responsibilities
- Guide a group of DevSecOps engineers through mentoring, managing backlogs and priorities, conducting code reviews, and enforcing standards.
- Collaborate with delivery leaders, product owners, security, and infrastructure teams to interpret requirements, align roadmaps, and manage expectations.
- Conduct incident and post-incident reviews, perform root cause analysis, manage risks, and develop proactive improvement plans.
- Design, implement, and maintain AWS infrastructure components (EKS, RDS, EC2, IAM, VPC, CloudFormation, EBS) and contribute to the expansion of Azure workloads (AKS, IAM/Entra ID fundamentals, networking).
- Manage Kubernetes (EKS/AKS) at scale, including deployments, ingress, Helm, performance, cost, and capacity.
- Oversee the lifecycle of the DevSecOps toolchain, including Artifactory, SonarQube, Fortify, Confluence, GitGuardian, and Sonatype, with a focus on deployment, upgrades, hardening, monitoring, and disaster recovery.
- Operate self-hosted agents on AWS for Azure DevOps Pipelines and extend CI/CD with GitHub (Actions, Advanced Security), promoting the adoption and guardrails of GitHub Copilot.
- Integrate security measures into pipelines, manage TLS certificates and secrets, and implement SAST, SCA, and secret scanning.
- Standardize Datadog dashboards, alerts, traces, and logs, and phase out legacy Prometheus and Grafana systems.
- Create secure access solutions using LDAP, SAML, SCIM, Azure AD (Entra ID), and SSO.
- Develop and execute backup and disaster recovery strategies for critical applications.
Work Arrangement
Remote (Worldwide)
Team
null
Responsibilities
- Lead a team of DevSecOps engineers (mentoring, backlog/priority, code reviews, standards).
- Engage with delivery leadership, product owners, security, and infra teams; translate requirements, align roadmaps, and manage expectations.
- Drive incident/post-incident reviews, RCA, risk management, and proactive improvement plans.
- Architect, implement, and maintain AWS infrastructure (EKS, RDS, EC2, IAM, VPC, CloudFormation, EBS) and contribute to growing Azure workloads (AKS, IAM/Entra ID fundamentals, networking).
- Operate Kubernetes (EKS/AKS) at scale: deployments, ingress, Helm, performance, cost & capacity.
- Own the DevSecOps toolchain lifecycle: Artifactory, SonarQube, Fortify, Confluence, GitGuardian, Sonatype (deploy/upgrade, hardening, monitoring, DR).
- Run self-hosted agents on AWS for Azure DevOps Pipelines; extend CI/CD with GitHub (Actions, Advanced Security) and champion GitHub Copilot adoption & guardrails.
- Integrate security in pipelines (SAST/SCA/secret scanning), manage TLS certs and secrets.
- Standardize Datadog dashboards/alerts/traces/logs; remove legacy Prometheus/Grafana.
- Design secure access with LDAP, SAML, SCIM, Azure AD (Entra ID), SSO.
- Define/execute backup & disaster recovery strategies for critical apps.
null


