Senior DevSecOps Architect

Zodiac Solutions Inc — Canada · Posted ~3 hours ago

Senior Full-time

Skills

DevSecOps architecture CI/CD Git YAML pipelines Container security Kubernetes Google Kubernetes Engine Helm GitOps Cloud security Artifact management Dependency management Agile Release Trains DevSecOps YAML SBOM

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An enterprise technology organization is seeking a Senior DevSecOps Architect with 10+ years of experience to lead architecture, governance, and evolution of secure software delivery platforms. You will define CI/CD standards, govern container image security and software artifacts, and establish secure Kubernetes deployment patterns using Helm and GitOps, while validating solutions through hands-on proofs of concept.

Highlights

Lead enterprise DevSecOps architecture and governance while remaining hands-on with proofs of concept and solution delivery. The role provides broad influence over secure software delivery, Kubernetes, CI/CD, container security, and engineering standards.

Description

Total Experience: 10 & Above years Role Description: • Enterprise architecture: Lead the architecture, governance, and evolution of enterprise DevSecOps platforms, practices, and software delivery pipelines across Agile Release Trains. • Hands-on solution delivery: Design, document, validate, and demonstrate DevSecOps solutions through personally built proofs of concept before enterprise rollout. • CI/CD governance: Define standards for source control, branching, pull requests, releases, reusable multi-stage YAML pipelines, approvals, and embedded security controls. • Container image security: Govern image registries and lifecycle controls, including scanning, signing, SBOM generation, provenance, promotion, vulnerability management, and immutability. • Kubernetes and GKE integration: Partner with Cloud Architecture to implement secure deployment patterns, admission controls, Helm and GitOps practices, workload identity, and pipeline integration. • Artifact and dependency management: Design and govern Sonatype Nexus usage to support secure repository access, dependency controls, lifecycle management, and end-to-end artifact traceability. • Software supply chain security: Integrate SAST, SCA, secret scanning, IaC scanning, container scanning, attestations, signing, and policy enforcement into delivery workflows. • Risk, compliance, and audit: Support architecture reviews, control design, risk assessments, audit evidence, remediation activities, and alignment with cybersecurity and enterprise standards. • Applied AI for DevSecOps: Evaluate and use AI-assisted tools to improve pipeline development, documentation, testing, compliance validation, vulnerability triage, and operational support while protecting enterprise data. • Automation and platform engineering: Build reusable pipeline templates, scripts, integrations, secrets-management workflows, and service-management automation at enterprise scale. • Technical leadership: Guide and mentor application teams, DSO Champions, platform teams, and junior resources through standards.