Job Summary
We are looking for one senior, hands-on DevSecOps Platform Architect / Lead Engineer to support an enterprise DevSecOps services enhancement project.
The resource will assess the current enterprise DevSecOps environment, identify platform scalability, resiliency, availability, security, observability, and developer-experience gaps, and provide design guidance, implementation support, runbooks, roadmap inputs, and proof-of-concept/workshop support.
The role requires strong hands-on experience across enterprise CI/CD platforms, GitLab, Artifactory, build runners, DevSecOps security controls, observability, platform reliability, automation, Kubernetes/OpenShift, and large-scale engineering toolchains.
This is a single-resource requirement, so the candidate must be capable of leading customer discussions, performing technical assessments, preparing architecture recommendations, and supporting hands-on implementation/configuration activities.
Key Responsibilities
- Assess the current enterprise DevSecOps architecture, integrations, infrastructure, operations, dependencies, performance, and developer workflows.
- Review and analyze platforms and services such as GitLab, Artifactory, Grafana, Coverity, Polyspace, Elastic Build Runner Services, Kubernetes/OpenShift, databases, storage, networking, identity services, and related infrastructure.
- Identify bottlenecks, single points of failure, technical debt, capacity constraints, resiliency gaps, monitoring gaps, security gaps, and operational risks.
- Establish performance and capacity baselines for enterprise DevSecOps services.
- Evaluate scalability requirements to support growth from approximately 5,000 to 15,000 users over three years.
- Assess build runner scalability, concurrency, autoscaling behavior, queue-time objectives, workload isolation, infrastructure requirements, service quotas, and cost drivers.
- Evaluate global Active-Active architecture options, including regional topology, traffic management, replication, failover, data consistency, security, operational complexity, cost, and product constraints.
- Assess developer experience issues such as pipeline delays, onboarding challenges, service interruptions, latency, runner bottlenecks, lack of self-service, documentation gaps, and support friction.
- Design and recommend improvements to enhance availability, reliability, resiliency, scalability, security, automation, developer experience, and operational sustainability.
- Support secure software supply-chain improvements across CI/CD pipelines, including security controls, reusable templates, automated gates, exception workflows, and centralized reporting.
- Support integration or design of security capabilities such as SAST, SCA, secrets detection, DAST, Infrastructure-as-Code scanning, container scanning, malware detection, license compliance, vulnerability management, SBOM management, artifact signing, provenance, trusted promotion, protected runners, and compliance evidence retention.
- Define or support trusted and reproducible build practices using approved registries, approved repositories, dependency pinning, artifact immutability, least-privilege access, runner security, and prevention of unauthorized build inputs.
- Assess and improve CI/CD observability across logs, metrics, traces, dashboards, alerts, SLIs, SLOs, synthetic monitoring, service-health views, dependency monitoring, and incident-response integration.
- Design or enhance enterprise dashboards for platform operations, product owners, service desk teams, developers, security teams, and leadership.
- Define actionable alerting, escalation, severity, deduplication, suppression, and on-call integration recommendations to reduce alert fatigue and improve issue detection.
- Prepare architecture outputs, gap analysis, resiliency assessment, observability design, roadmap, runbooks, technical findings, recommendations, and knowledge-transfer material.
- Participate in customer workshops, design reviews, weekly status meetings, and monthly reporting inputs.
Support hands-on proof-of-concept or workshop activities for selected DevSecOps capabilities using representative applications and pipelines.
Skill Requirements
- Strong hands-on experience with enterprise DevOps / DevSecOps platforms and software delivery toolchains.
- Strong experience with GitLab administration, GitLab CI/CD, pipeline templates, GitLab runners, runner autoscaling, pipeline optimization, access controls, and enterprise-scale GitLab usage.
- Experience with artifact repositories and registries such as JFrog Artifactory, Nexus, Harbor, GitLab Registry, or equivalent.
- Experience with enterprise observability tools such as Grafana, Prometheus, Loki, ELK/OpenSearch, Splunk, Datadog, New Relic, AppDynamics, or equivalent.
- Experience with static analysis, code quality, and security tools such as Coverity, Polyspace, SonarQube, Checkmarx, Fortify, Snyk, Black Duck, Prisma Cloud, Trivy, Grype, Anchore, or equivalent.
- Strong understanding of CI/CD reliability, pipeline performance, queue-time analysis, runner provisioning, runner isolation, autoscaling, workload management, and build infrastructure optimization.
- Experience with Kubernetes, OpenShift, containerized workloads, container registries, Helm, Kustomize, and deployment automation.
- Experience with platform resiliency, high availability, backup and recovery, disaster recovery, service dependency mapping, capacity planning, and scalability analysis.
- Experience evaluating or designing Active-Active, multi-region, or highly available enterprise platform architectures.
- Experience with logs, metrics, traces, dashboards, alerting, synthetic monitoring, SLIs, SLOs, error budgets, escalation models, and incident-response integration.
- Experience with secure software supply-chain practices including SAST, SCA, secrets scanning, DAST, IaC scanning, container scanning, malware detection, license compliance, vulnerability management, SBOM, artifact signing, provenance, trusted promotion, and compliance evidence.
- Understanding of NIST SSDF, SLSA, SPDX, CycloneDX, secure build practices, protected runners, dependency governance, and least-privilege access.
- Experience with infrastructure automation and scripting using tools such as Terraform, Ansible, Helm, Bash, Python, PowerShell, or equivalent.
- Ability to assess current-state architecture and produce target-state architecture, gap analysis, risk findings, improvement roadmap, and implementation runbooks.
- Ability to work independently as the single primary resource for assessment, design guidance, hands-on support, documentation, workshops, and knowledge transfer.
- Strong customer-facing communication skills with the ability to work with engineering, security, infrastructure, operations, service desk, and leadership stakeholders.
Other Requirements
Preferred Skills
- Prior experience supporting enterprise DevSecOps platforms at large scale.
- Experience with aerospace, defense, federal, regulated, or security-sensitive environments.
- Experience with GitLab and Artifactory platform modernization or enterprise rollout.
- Experience with Coverity and Polyspace in engineering or embedded software environments.
- Experience with restricted-network, classified, or compliance-heavy environments.
- Experience creating three-year modernization roadmaps for enterprise platform services.
- Relevant certifications such as CKA, CKAD, CKS, GitLab certification, DevSecOps certification, CISSP, CCSP, AWS/Azure security, Kubernetes security, SRE, or equivalent.
Expected Deliverables
- Current-state DevSecOps system assessment.
- Availability and resiliency assessment.
- EBRS / build runner scalability and concurrency analysis.
- Global Active-Active architecture options analysis.
- Developer experience assessment and improvement backlog.
- Scalability, availability, and modernization roadmap.
- Secure software supply-chain architecture review and design guidance.
- Security control and pipeline integration design.
- SBOM, artifact signing, and provenance strategy.
- Trusted and reproducible build guidance.
- CI/CD observability gap analysis.
- Target-state observability architecture and design guidance.
- Out-of-band monitoring strategy.
- SLI / SLO framework.
- Enterprise dashboard and service-health design.
- Alerting and incident-detection recommendations.
- Implementation runbooks.
- Hands-on POC/workshop support.
- Knowledge-transfer material.
Soft Skills
- Strong ownership and independent execution capability.
- Ability to operate as the only assigned senior resource.
- Strong consulting, discovery, and stakeholder-management skills.
- Ability to lead technical workshops and architecture discussions.
- Strong analytical skills for identifying risks, gaps, dependencies, and improvement opportunities.
- Strong documentation and presentation skills.
- Ability to balance security, platform performance, developer experience, operational sustainability, and T&M project constraints.
- Ability to communicate clearly with both technical and non-technical stakeholders.