Join BMC as a Principal, DevSecOps AI Enabled SDLC to drive enterprise-wide transformation by embedding secure, AI-powered, and automated practices across the software delivery lifecycle. This role is pivotal in translating strategy into execution standardizing pipelines, enhancing developer productivity, and ensuring secure, compliant, and high-quality releases at scale. You will lead the adoption of AI-enabled and agentic workflows, positioning BMC at the forefront of modern software engineering innovation.
Here is how, through this exciting role, YOU will contribute to BMC's and your own success:
- Execute enterprise DevSecOps strategy through standardized pipelines, architectures, and delivery roadmaps
- Build and scale secure, automated CI/CD pipelines and development workflows
- Drive organization-wide adoption of DevSecOps best practices and shift-left security
- AI Agentic SDLC Enablement
- Embed AI across SDLC (code quality, security analysis, testing, release validation)
- Implement AI-driven vulnerability prioritization and remediation
- Enable agentic workflows to automate SDLC and operational processes
- Establish governance and guardrails for responsible AI adoption
- Microsoft Ecosystem Leadership
- Leverage GitHub, GitHub Actions, Copilot, and GitHub Advanced Security
- Integrate Microsoft and third-party tools into standardized pipelines
- Align DevSecOps practices with broader cloud and workplace strategies
- Platform, Security Governance
- Implement SAST, DAST, SCA, IaC scanning, and secrets management
- Define governance frameworks, guardrails, and compliance mechanisms
- Rationalize toolsets for efficiency and scalability
- Metrics Continuous Improvement
- Track KPIs (pipeline adoption, remediation time, compliance, developer experience)
- Use data and AI insights to drive ongoing improvements
- Deliver executive-level insights and reporting
- Change Leadership
- Drive adoption through enablement, coaching, and documentation
- Act as a trusted advisor across Engineering, Security, and Product teams
- Translate technical initiatives into business outcomes
To ensure youre set up for success, you will bring the following skillset experience:
- Deep experience in DevSecOps, CI/CD platforms, and modern SDLC practices
- Strong hands-on expertise with GitHub ecosystem (GitHub, Actions, Copilot, Advanced Security)
- Proven track record in embedding AI/automation in software delivery workflows
- Strong application security knowledge (OWASP, secure SDLC, supply chain security)
- Experience implementing shift-left security, quality gates, and policy enforcement
- Hands-on CI/CD tools experience (GitHub, Jenkins)
- Ability to operate in complex, enterprise-scale environments
- Strong stakeholder management, communication, and change leadership skills
Whilst these are nice to have, our team can help you develop in the following skills:
- Experience defining enterprise DevSecOps and AI governance frameworks
- Exposure to regulated / audit-driven environments
- Knowledge of Microsoft Graph APIs for workflow automation
- Background in cloud-native architecture and platform engineering
- Experience influencing large, federated engineering organizations
- Advanced use of AI-assisted development and agentic workflows