Responsibilities
- Lead the DevSecOps roadmap and promote agile,secure, and automated delivery across the enterprise
- Drive collaboration and change across software development, infrastructure and information security to support IT modernization
- Modernize the software delivery pipeline using Continuous Improvement/Continuous Deployment (CI/CD), Infrastructure as Code (IaC), and automated quality/security gates.
- Redesign release management and environment provisioning processes to reduce bottlenecks and manual handoffs.
- Advance “shift-left” security by embedding security controls early into the software development lifecycle, including static and dynamic code analysis, open-source risk management, and vulnerability detection into early stages of development.
- Lead the definition of IT environment strategy and lifecycle management covering non-production, production and disaster recovery systems.
- Set-up and monitor governance metrics to track adoption of secure development practices and ensure alignment with enterprise risk and compliance goals.
- Mentor teams on reliability engineering, automated testing, code quality, and incident management
- Drive continuous improvement of the DevSecOps practice by staying current with emerging technologies, evolving security regulations, industry best practices and ensuring these are integrated into delivery pipelines and team capabilities
- Support IT initiatives that affect delivery pipelines by ensuring alignment to DevSecOps practices, automation standards and security requirements.
Hard Skills
- Experience in system environment maintenance and strategy
- Proficiency in CI/CD (Continuous Integration and Continuous Deployment) pipelines
- Knowledge of Infrastructure as Code (IaC)
- Familiarity with automated testing frameworks
- Expertise in Shift Left Security, including:
- Static and dynamic code analysis
- Open-source risk management
- Experience Requirements:
Experienced Requirements
- • More than 5 years of relevant experience
- • At least 2 years of security experience (application and infrastructure
- security)
- • Exposure to core banking and digital applications for system environment
- management
- • Potential to lead a deployment team within 2–3 years