Sr DevSecOps Engineer - Onsite
Title: Sr DevSecOps Engineer - Onsite Mandatory skills: GitLab-based DevSecOps automated pipelines, AWS gov cloud, application delivery, CI/CD platform, GitLab CI/CD, CI/CD pipelines, CI/CD jobs, Version Control Systems, Git, GitLab, GitHub Actions, GitOps tools, deployment principles, ArgoCD, Flux, merge requests, issue tracking, branching, promotion, release strategies, SemRel, internalized registries, repositories, Nexus dependency management, internal container registries, GitLab runners, GitLab components, generally developing, utilizing templates, Cloud Platforms, AWS, Lambda, EC2, S3, EBS/EFS, ECS, EKS, SNS, CloudWatch, Docker, building, deploying, managing containers, Containerization, Kubernetes, orchestration, deployment strategies, security, troubleshooting Description: Position Requirements: Candidate will help build GitLab-based DevSecOps automated pipelines into AWS gov cloud; support and enable application delivery times on CI/CD platform; manage and operate GitLab CI/CD. Knowledge, Skills and Experience Version Control Systems Proficiency with Git Advanced knowledge of GitLab, including CI/CD pipelines, merge requests, and issue tracking Familiarity with branching, promotion, and release strategies (such as SemRel) Familiarity using internalized registries and repositories (Nexus dependency management, internal container registries, etc.) CI/CD GitLab CI/CD GitLab runners (configuration and management) GitLab components (Or generally developing and utilizing templates for CI/CD jobs in any platform, such as GitHub Actions) Cloud Platforms Demonstrated proficiency with AWS (Lambda, EC2, S3, EBS/EFS, ECS, EKS, SNS, CloudWatch) Containerization Docker (building, deploying, and managing containers) Kubernetes (orchestration, deployment strategies, security, troubleshooting) Container security best practices Including container hardening strategies, such as maintaining a secure “golden” image Deploying and managing container-based runners hosted on EKS GitOps tools and deployment principles (such as ArgoCD/Flux) Security Testing Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Interactive Application Security Testing (IAST) Software Composition Analysis (SCA) Container scanning tooling (Trivy, Prisma/Twistlock, Neuvector, etc) Infrastructure as Code (IaC) Terraform (writing, managing, and optimizing Terraform configurations) Other IaC tools (e.g., CloudFormation, Ansible) Scripting and Programming Proficiency in scripting languages (e.g., Python, Bash) Basic to intermediate programming skills Experience working with a Linux-based shell, managing way around a Linux-based system Ability to work well in a paired programming environment at times Automation Creating and maintaining automated security checks and remediations Integrating security into automated deployment processes Incorporating linting tooling into development processes Incorporating unit & performance testing into deployment processes Certification GitLab certification desired but not required. AWS certification desired but not required. Notes: Onsite VIVA USA is an equal opportunity employer and is committed to maintaining a professional working environment that is free from discrimination and unlawful harassment. The Management, contractors, and staff of VIVA USA shall respect others without regard to race, sex, religion, age, color, creed, national or ethnic origin, physical, mental or sensory disability, marital status, sexual orientation, or status as a Vietnam-era, recently separated veteran, Active war time or campaign badge veteran, Armed forces service medal veteran, or disabled veteran. Please contact us at [email protected] for any complaints, comments and suggestions. Contact Details : Account co-ordinator: Binodh M.T, Phone : (408) 709 3343, Email: [email protected] VIVA USA INC. 3601 Algonquin Road, Suite 425 Rolling Meadows, IL 60008 [email protected] | http://www.viva-it.com