DevSecOps Architect

Knk Gt — Canada · Posted ~9 hours ago

Senior Full-time Remote

Skills

DevSecOps architecture CI/CD Kubernetes GKE container security software supply chain security SAST SCA SBOM source control YAML pipelines DevSecOps Sonatype Nexus YAML

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A permanent remote DevSecOps Architect role focused on enterprise platform engineering and secure software delivery. You will lead architecture and governance, validate solutions through hands-on proofs of concept, define CI/CD standards, govern container security and Kubernetes integrations, and implement software supply chain controls including SAST, SCA, SBOMs, signing, and policy enforcement.

Highlights

Permanent remote role offering enterprise-scale architecture ownership, hands-on proof-of-concept work, platform governance, CI/CD modernization, Kubernetes, and advanced software supply chain security.

Description

Position: DevSecOps Architect – Platform Engineering & Supply Chain Security Location: Remote- Montreal QC Job type: Full-Time/Permanent Hiring Lead architecture, governance, and evolution of enterprise DevSecOps platforms and software delivery pipelines across Agile Release Trains. Design and validate DevSecOps solutions through hands-on POCs before enterprise rollout. Define CI/CD standards, govern container security, Kubernetes/GKE integration, Sonatype Nexus, and software supply chain security (SAST, SCA, SBOM, signing, policy enforcement). Key Responsibilities: Lead enterprise DevSecOps platform architecture, governance, and evolution across Agile Release TrainsDesign, document, validate, and demonstrate DevSecOps solutions via hands-on POCs before rolloutDefine CI/CD standards: source control, branching, PRs, releases, multi-stage YAML pipelines, approvals, embedded security controlsGovern container image security: registries, scanning, signing, SBOM generation, provenance, promotion, vulnerability management, immutabilityPartner with Cloud Architecture on secure Kubernetes/GKE deployments, admission controls, Helm, GitOps, workload identity, pipeline integrationDesign and govern Sonatype Nexus for secure repository access, dependency controls, lifecycle management, artifact traceabilityIntegrate SAST, SCA, secret scanning, IaC/container scanning, attestations, signing, policy enforcement into delivery workflowsSupport architecture reviews, risk assessments, audit evidence, remediation, and alignment with cybersecurity/enterprise standardsEvaluate and apply AI-assisted tools for pipeline development, documentation, testing, compliance validation, vulnerability triageBuild reusable pipeline templates, scripts, integrations, secrets-management workflows, service-management automation at enterprise scaleGuide and mentor application teams, DSO Champions, platform teams, and junior resources through standards and best practices Required Skills: Primary: Enterprise DevSecOps architecture, CI/CD governance, YAML pipelines, Kubernetes/GKE security, Helm, GitOps, admission controls, workload identity, Sonatype Nexus, SBOM generation, image signing, Sigstore/Cosign, SLSA, SAST, SCA, secret scanning, IaC scanning, container scanning, policy enforcement (OPA/Rego, Kyverno), software supply chain security, risk assessments, audit evidence, applied AI for DevSecOps, platform engineering, reusable pipeline templates, secrets management, technical leadership, mentoring, Agile Release Trains, POCs Tools/Frameworks: GitHub Actions, GitLab CI, Azure DevOps, Jenkins, ArgoCD, Flux, Docker, Sonatype Nexus (Repository Manager, Lifecycle, IQ Server), Snyk, Trivy, Syft, Grype, Semgrep, Sigstore (Cosign, Fulcio, Rekor), HashiCorp Vault, Azure Key Vault, AWS KMS, CycloneDX, SPDX, Veracode, Checkmarx, Aqua Security, Prisma Cloud, Terraform, Python, Bash, Go, Git, Jira, Confluence, ServiceNow, GitHub Copilot, CodeQL, Falco, Prometheus, Grafana, ELK, Splunk Database/Cloud: GCP (GKE, Artifact Registry, KMS, Secret Manager), Azure (AKS, ACR, Key Vault), AWS (EKS, ECR, KMS, Secrets Manager), Harbor, JFrog Artifactory, Entra ID, Okta, Ping Identity, SSO/SAML/OIDC, RBAC/ABAC, audit logging, multi-cloud, hybrid cloud