Design, implement, and maintain CI/CD and GitOps pipelines that power secure, reliable, and scalable software delivery across cloud-native environments. Integrate security practices throughout the DevOps pipeline (DevSecOps), enhancing the security, efficiency, reliability, and performance of software and system deployment.
Reporting Line: IT Development Manager
Key Duties & Responsibilities
- Design, implement, and maintain CI/CD pipelines using GitHub Actions to support automated software delivery.
- Implement GitOps-based deployment workflows using ArgoCD.
- Support blue/green and canary deployment strategies within Kubernetes environments.
- Automate infrastructure provisioning using Infrastructure as Code, with Terraform preferred.
- Support containerization and orchestration using Docker and Kubernetes; develop and maintain Kubernetes manifests for standardized deployments.
- Troubleshoot pipeline and deployment issues across environments.
- Maintain comprehensive documentation of all CI/CD processes and policies implemented.
DevSecOps & Compliance Automation
- Integrate security tools and practices into CI/CD pipelines (DevSecOps), ensuring compliance with relevant policies and regulations at every stage of development and deployment.
- Integrate and maintain container and code security tools (e.g. Snyk, Aqua Security, Anchore, CodeQL).
- Automate security testing (SAST, DAST, IAST) and vulnerability management processes.
- Collaborate with the IT team to remediate vulnerabilities and apply patches or mitigations as necessary to improve overall system security.
- Ensure compliance with industry best practices and organizational security policies.
Secrets, Observability & Platform Integration
- Manage secrets and credentials using HashiCorp Vault or Azure Key Vault.
- Implement monitoring, logging, and performance optimization solutions to track the health of deployed services, applications, and infrastructure.
- Understand and manage the underlying IT infrastructure (servers, networking, storage, and virtualization) supporting deployed systems and platforms.
- Collaborate with development, security, and operations teams to ensure secure, scalable architectures that meet availability, performance, and maintainability requirements.
- Identify and address issues and bottlenecks in the software development lifecycle to streamline application delivery.
- Improve collaborative incident response in real time, maintaining documentation, runbooks, and modules to prepare teams for incidents.
Continuous Improvement & Collaboration
- Participate in Agile ceremonies and continuous improvement initiatives to enhance efficiency and productivity.
- Implement and maintain version control systems, configuration management tools, and other DevOps-related technologies.
- Projects and reporting as directed by the IT Development Manager / Director IT.
- BSc. Computer Science or equivalent from a recognised university
- Professional certifications in IT Security (CISSP, CCSP, CISA, CISM) is a plus
- 3+ years of experience in the field or similar roles.
- Proficient in scripting and coding, with aptitude in languages such as Python, JavaScript, and React.js.
- A champion of change within the DevOps culture and a strong advocate for improving and automating processes.
- Able to investigate reliability or performance issues, leveraging tools to automate scanning and monitoring.
- Strong awareness of cybersecurity principles and trends, including secure coding practices, encryption, threat modelling, and vulnerability management.
- Experience with security testing tools (e.g. OWASP ZAP, Burp Suite, Nessus).
- Familiarity with compliance frameworks and standards (e.g. GDPR, ISO 27001, NIST).
- Able to use B/OSS tools effectively to record information accurately and concisely in a timely manner.
- Strong knowledge of DevSecOps and cloud-native tooling, including CI/CD platforms (e.g. GitHub Actions, Azure DevOps, Jenkins, GitLab CI), GitOps tools (e.g. ArgoCD), Infrastructure as Code (Terraform preferred), and containerization/orchestration (Docker, Kubernetes).
- Experience with container and code security scanning tools (e.g. Snyk, Aqua Security, Anchore, CodeQL) and secrets management solutions (e.g. HashiCorp Vault, Azure Key Vault).
- Understanding and management of IT infrastructure, including servers, networking, storage, and virtualization, across on-premises and cloud environments.
- Strong knowledge of operating systems, networking, virtualization, and cloud platforms (Azure, GCP).