The Senior DevOps Engineer is responsible for designing, automating, and operating CI/CD pipelines and cloud infrastructure for a large portfolio of applications across on-premises and AWS environments.
This role focuses on enhancing deployment speed, reliability, security, and observability through containerization, infrastructure as code, automated testing and scanning, and monitoring solutions.
Key Responsibilities
- Streamline CI/CD delivery for 45 applications using Bitbucket, Bamboo, and Artifactory to support consistent releases across on-premises and AWS environments.
- Increase delivery efficiency by implementing Docker containerization and automating Kubernetes deployments using Kustomize manifests for scalable, multi-environment release processes.
- Automate AWS infrastructure provisioning with Terraform, building reusable modules for VPCs, subnets, security groups, and RDS to ensure standardized deployment patterns.
- Design and manage a fault-tolerant, containerized Prometheus monitoring stack supporting 400 servers and 1,200 endpoints, reducing overhead and improving startup reliability through dependency ordering.
- Integrate Checkmarx SAST into CI/CD pipelines, enforcing quality gates and reducing high-severity post-deployment vulnerabilities by 40%.
- Implement AWS WAF rules for geo-restricted access and manage sensitive application configurations through AWS Secrets Manager.
- Administer Splunk integrations with Active Directory for role-based access, create dashboards, and configure real-time and scheduled alerts to reduce incident response time by 30%.
- Establish and maintain Git branching strategies to standardize release processes from development to production.
- Automate builds and deployments using Python and Shell scripting; develop internal dashboards with Python Flask to monitor build status and pipeline health.
- Integrate Grafana with LDAP/Active Directory for RBAC and create dashboards for performance monitoring, ephemeral port usage, and SSL certificate expiration.
- Automate SSL/TLS certificate renewals via Ansible in CI/CD pipelines to ensure continuous secure access for critical applications.
Required Qualifications
- Strong experience designing and managing CI/CD pipelines using Bitbucket, Bamboo, and Artifactory.
- Hands-on experience with Docker, Kubernetes, and Kustomize for containerization and deployment automation.
- Expertise with Terraform for infrastructure as code and AWS services including VPC, RDS, WAF, and Secrets Manager.
- Experience implementing monitoring solutions using Prometheus and Grafana.
- Experience administering Splunk, LDAP/Active Directory integrations, and alerting workflows.
- Proficiency in scripting with Python and Shell.
- Experience using Ansible for automation and certificate management.
- Strong understanding of DevSecOps practices including SAST and automated security scanning.
- Ability to design reliable, scalable, and secure cloud and on-premises infrastructure.
Preferred Qualifications
- Experience building internal dashboards or automation tools using frameworks such as Flask.
- Experience supporting high-availability and high-performance application environments.