Overview
As Lead Software Engineer (DevSecOps), you will drive hands-on delivery of automated, secure software delivery capabilities and platform automation. You lead a DevSecOps and platform automation team, transforming strategy into production-grade pipelines and controls. You will partner with product, architecture, and security to embed best practices, enabling frequent, safe, scalable software releases. This role offers impact across pipeline health, security integration, and platform enablement, shaping secure delivery at scale.
Responsibilities
- Build and improve automated CI/CD pipelines for microservices, APIs, and platform services
- Develop and evolve IaC pipelines and templates that are secure by default and self-service
- Implement progressive delivery, blue-green/canary deployments, feature flags, and controlled rollouts
- Own pipeline health, performance, and reliability; reduce build times and failures
- Onboard teams onto standard pipelines and platform blueprints
- Embed security controls in pipelines (SAST, DAST, SCA) and container/image scanning
- Triage security findings with product teams and drive remediation
- Automate environment provisioning with Terraform/CloudFormation/ARM/Bicep and GitOps patterns
- Integrate observability and metrics (OpenTelemetry) into pipelines and platforms
- Contribute to incident response, disaster recovery automation, and on-call rotation
- Provide technical leadership, reviews, and enablement for DevSecOps practices
- Create documentation and golden-path guidance to enable self-service by product teams
Key requirements
- 8+ years of software engineering experience
- 4+ years in DevSecOps, CI/CD, and platform automation
- Proven experience building and operating automated delivery pipelines in production
- Technical lead experience for a small engineering team or workstream
- Solid understanding of software supply chain security principles
- strong troubleshooting and problem-solving
- clear written and verbal communication
- mentoring and coaching
- GitHub Actions, GitLab CI, Azure DevOps, Jenkins
- artifact repositories and container registries
- pipeline-as-code and reusable templates
…
