George Bernard Consulting
Senior DevOps Engineer (with DevSecOps expertise)
About the job
Responsibilities Architect and manage scalable, secure, and resilient infrastructure in Azure Cloud. Design, optimize, and maintain CI/CD pipelines for microservices ( Azure DevOps). Lead implementation of Infrastructure as Code (IaC) using tools such as Terraform . Integrate DevSecOps practices into CI/CD pipelines (e.g., static code analysis, dependency scanning, container security, secrets management). Implement automated security testing tools (SAST, DAST, SCA) within pipelines. Monitor and optimize system performance and availability using Azure Monitor, Prometheus, Grafana, or similar tools. Collaborate closely with NOC, Security, and Development teams for seamless deployment and operations. Act as a senior escalation point for NOC operationsreview escalated incidents, lead resolution efforts, and guide improvements in monitoring and alerting. Drive incident response planning, lead security incident investigations, and participate in on-call escalations. Define DevOps & DevSecOps standards and mentor junior engineers. Enforce cloud security best practices, including identity & access management (IAM), network security, encryption, and compliance (ISO 27001, PCI-DSS, GDPR, etc.). Configure and manage IAM for secure user and service authentication across cloud and application environments. Implement and maintain API communication security, including authentication, authorization, encryption, and secure API gateway configurations. Ensure compliance with API security best practices, including rate limiting, token management, and vulnerability scanning for exposed endpoint Support cloud infrastructure cost optimization initiatives. Requirements Bachelors degree in Computer Science, Information Technology, Cybersecurity, or related field. 5+ years of experience in DevOps/DevSecOps, Cloud Infrastructure, or Site Reliability Engineering. Strong expertise in Azure Cloud services (Compute, Networking, Storage, Security). Proven experience in CI/CD pipelines (Azure DevOps, GitHub Actions, Jenkins). Hands-on experience with IaC tools (Terraform, Bicep, ARM templates). Proficiency in containerization & orchestration (Docker, Kubernetes, AKS). Strong background in DevSecOps practices (automated security scanning, compliance checks, secrets management). Experience with security testing tools (e.g., SonarQube, OWASP ZAP, Checkmarx, Aqua, Twistlock, Trivy). Strong understanding of cloud security and compliance standards. Experience leading DevOps/DevSecOps teams and mentoring junior engineers. Certifications in Azure (AZ-400, AZ-104, or equivalent). Security certifications (e.g., CCSP, CISSP, or Azure Security Engineer Associate). Experience with large-software platforms or fintech systems. Familiarity with agile methodologies and cross-functional collaboration. Preferred Certifications in Azure (AZ-400, AZ-104, or equivalent). Security certifications (e.g., CCSP, CISSP, or Azure Security Engineer Associate). Experience with large-software platforms or fintech systems. Familiarity with agile methodologies and cross-functional collaboration.