Summary
✨ AI‑Generated
An enterprise technology organization is seeking a Senior DevSecOps Architect with 10+ years of experience to lead architecture, governance, and evolution of secure software delivery platforms. You will define CI/CD standards, govern container image security and software artifacts, and establish secure Kubernetes deployment patterns using Helm and GitOps, while validating solutions through hands-on proofs of concept.
Highlights
Lead enterprise DevSecOps architecture and governance while remaining hands-on with proofs of concept and solution delivery. The role provides broad influence over secure software delivery, Kubernetes, CI/CD, container security, and engineering standards.
Description
Total Experience: 10 & Above years
Role Description:
• Enterprise architecture: Lead the architecture, governance, and evolution of enterprise DevSecOps platforms, practices, and software delivery pipelines across Agile Release Trains.
• Hands-on solution delivery: Design, document, validate, and demonstrate DevSecOps solutions through personally built proofs of concept before enterprise rollout.
• CI/CD governance: Define standards for source control, branching, pull requests, releases, reusable multi-stage YAML pipelines, approvals, and embedded security controls.
• Container image security: Govern image registries and lifecycle controls, including scanning, signing, SBOM generation, provenance, promotion, vulnerability management, and immutability.
• Kubernetes and GKE integration: Partner with Cloud Architecture to implement secure deployment patterns, admission controls, Helm and GitOps practices, workload identity, and pipeline integration.
• Artifact and dependency management: Design and govern Sonatype Nexus usage to support secure repository access, dependency controls, lifecycle management, and end-to-end artifact traceability.
• Software supply chain security: Integrate SAST, SCA, secret scanning, IaC scanning, container scanning, attestations, signing, and policy enforcement into delivery workflows.
• Risk, compliance, and audit: Support architecture reviews, control design, risk assessments, audit evidence, remediation activities, and alignment with cybersecurity and enterprise standards.
• Applied AI for DevSecOps: Evaluate and use AI-assisted tools to improve pipeline development, documentation, testing, compliance validation, vulnerability triage, and operational support while protecting enterprise data.
• Automation and platform engineering: Build reusable pipeline templates, scripts, integrations, secrets-management workflows, and service-management automation at enterprise scale.
• Technical leadership: Guide and mentor application teams, DSO Champions, platform teams, and junior resources through standards.