TEMP Principal DevOps Engineer

Doble Engineering Company

West Village (MA)

On-site

USD 99,000 - 135,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Doble Engineering Company seeks a 6‑month contractor to migrate desktop/firmware CI pipelines into our Azure DevOps environment, while strengthening CRA and IEC 62443‑4‑1 secure‑SDLC practices. You will embed threat modeling, SBOM generation, and Snyk scanning into pipelines to produce CRA‑compliant evidence as a by‑product of day‑to‑day engineering.

Responsibilities include designing Azure DevOps multi‑stage pipelines, migrating from GitLab/SVN, supporting desktop/firmware builds,

Qualifications

  • 5+ years in DevOps/CI‑CD with hands‑on Azure DevOps Pipelines.
  • Experience building desktop/firmware or embedded build pipelines (not web‑only).
  • Knowledge of Snyk (SAST/SCA), SBOM generation, and STRIDE threat modeling.
  • Familiarity with the EU CRA and IEC 62443‑4‑1 secure‑development lifecycle concepts.
  • English working proficiency; Italian a strong plus given mixed-language migration meetings.

Responsibilities

  • Design and implement Azure DevOps multi‑stage pipelines.
  • Migrate sources from GitLab/SVN to Azure DevOps Git.
  • Support desktop/firmware builds (C/C++, .NET) and Yocto builds.
  • Containerize workflows with Docker and AKS.
  • Support monolith‑to‑microservices refactoring with per‑service pipelines.
  • Create reusable pipeline templates and manage infrastructure with Terraform.
  • Integrate Snyk and SBOM scanning into pipelines.
  • Enforce CRA/IEC secure‑SDLC practices and manage secrets in Key Vault.

Skills

Azure DevOps
GitLab migration
Desktop builds
Docker
AKS
SBOM generation
Threat modeling
Snyk
English proficiency
Italian beneficial

Tools

Yocto
Terraform
ACR

Job description

Role Purpose

A temporary (6 Months) contractor to support the Bologna and Taino (Altanova) engineering teams in migrating their desktop-application and firmware CI pipelines from GitLab/SVN/Jenkins/ADO into Doble's common Azure DevOps environment, while strengthening product-security practices required by the EU Cyber Resilience Act (CRA) and the IEC 62443-4-1 secure-development lifecycle. The contractor will embed threat modeling, Snyk scanning, and SBOM generation directly into the migrated pipelines so that CRA/CE technical evidence is produced as a by-product of day-to-day engineering.

Essential Functions - DevOps & CI Migration
  • Design and build Azure DevOps multi-stage YAML pipelines, repos, service connections, agent pools, and variable/secret groups for the migrated teams.
  • Execute source‑control migration from GitLab, SVN, and Bitbucket into Azure DevOps Git, including history, and advise on project/repo structuring (project-per-product vs. multi-repo).
  • Support desktop / thick‑client and firmware builds - C/C++, .NET, FPGA toolchains, code‑signing, and Yocto / embedded‑Linux build servers in Azure.
  • Containerize and manage build/scan workflows using Docker, AKS, and Azure Container Registry.
  • Provide CI support for monolith‑to‑microservices refactoring (strangler pattern), standing up per‑microservice pipelines.
  • Create reusable pipeline templates so the common environment is consistent across teams; manage infrastructure with Terraform.
Essential Functions - Security, Threat Modeling & CRA
  • Perform threat modeling using STRIDE (plus attack trees / MITRE ATT&CK for IC​S where appropriate), producing data‑flow diagrams with trust boundaries during the requirements/design phase.
  • Threat models must cover information flows, trust boundaries, data stores, external entities, comms protocols, externally accessible physical/debug ports, JTAG/debug headers and hardware attack vectors, CVSS‑scored threats, and documented mitigations - aligned to IEC 62443‑4‑1 SR‑2.
  • Build a reusable threat‑model template and repeatable process, and feed outputs into CRA risk assessments (asset ID threat modeling risk evaluation) and Stage‑Gate / Jira / ADO traceability.
  • Configure and operate Snyk - Snyk Code (SAST), Open Source (SCA), Container, and SBOM - as pipeline stages in ADO/Jenkins, set severity gates, and onboard new repos to raise coverage.
  • Add automated SBOM generation (CycloneDX/SPDX, machine‑readable, per release) to each migrated pipeline.
  • Harden pipelines: move secrets to Azure Key Vault (no hard‑coded credentials), secure service connections, enforce least‑privilege on ADO/AKS.
  • Validate that mitigations work (SVV‑2 threat‑mitigation testing) and produce audit‑trail artifacts (scan results, threat models, SBOMs, test records) for the CRA Annex VII technical file.
Requirements Summary - Must vs. Preferred vs. Nice‑to‑Have
Must‑have
  • ADO YAML pipelines; GitLab/SVN Azure DevOps migration; desktop/firmware + Yocto builds; Docker / AKS / ACR
  • Snyk (SAST/SCA/Container/SBOM); STRIDE threat modeling with DFDs & trust boundaries; SBOM in‑pipeline; CRA + IEC 62443‑4‑1 secure‑SDLC awareness
Strongly preferred
  • Terraform IaC; reusable pipeline templates / standardization; microservices / strangler‑pattern CI
  • Embedded/OT & hardware threat modeling (debug/JTAG ports, FPGA); CVSS scoring; CVD / vuln‑handling SLAs; secrets hardening (Key Vault)
Nice‑to‑have
  • Bitbucket / Jenkins / SVN; code‑signing; artifact management
  • Attack trees / MITRE ATT&CK for CS; mitigation‑validation testing (SVV‑2); Nessus, CodeQL / SonarQube; NIS2 Italy awareness
Minimum Qualifications
  • 5+ years in DevOps / CI‑CD engineering with hands‑on Azure DevOps Pipelines and Git‑based source‑control migration.
  • Demonstrated experience building desktop/firmware or embedded build pipelines (not web‑only).
  • Working knowledge of Snyk (or equivalent SAST/SCA), SBOM generation, and STRIDE threat modeling.
  • Familiarity with the EU CRA and IEC 62443‑4‑1 secure‑development lifecycle concepts.
  • English working proficiency; Italian a strong plus given the mixed‑language migration meetings.
PHYSICAL REQUIREMENTS

While performing the duties of this job the employee is often required to stand, sit, use computers, read, write, type, use copy machines, file paperwork, use telephones, and utilize written and oral communication to interact with clients, co‑workers, and customers. Reasonable accommodations may be made to enable individuals to perform the essential functions of this job. Must be capable of lifting 30 pounds. Must use assistance when lifting 50 or more pounds.

Actual base salary offered to the hired applicant will be determined based on their work location, level, qualifications, job related skills, as well as relevant education or training experience.

Hourly Pay: $85.00

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

We are an Equal Employment Opportunity employer that values the strength diversity brings to the workplace. All qualified applicants, regardless of race, color, religion, gender, sexual orientation, marital status, gender identity or expression, national origin, genetics, age, disability status, protected veteran status, or any other characteristic protected by applicable law, are strongly encouraged to apply.

The Americans with Disabilities Act of 1990 (ADA) prohibits discrimination by employers, in compensation and employment opportunities, against qualified individuals with disabilities who, with or without reasonable accommodation, can perform the "essential functions" of a job. A function may be essential for any of several reasons, including: the job exists to perform that function, the employee holding the job was hired for his/her expertise in performing the function, or only a limited number of employees are available to perform that function.

Applicants must be authorized to work for any employer in the United States. Doble Engineering is unable to sponsor or take over sponsorship of an employment visa at this time.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This employer is required to notify all applicants of their rights pursuant to federal employment laws.

For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TEMP Principal DevOps Engineer
TEMP Principal DevOps Engineer

ETS-Lindgren GmbH • Marlborough (MA)

On-site
USD 206,640,000 - 282,408,000
Staff Automation & Controls Engineer
Staff Automation & Controls Engineer

Divergent • Torrance (CA)

On-site
USD 148,000 - 236,000
Equity plan and incentive bonus
Paid vacation and holidays
Parental leave
+3
DevOps Engineer
DevOps Engineer

Robotics Technologies LLC • Sunnyvale (CA)

On-site
USD 130,000 - 160,000
Principal Automation & Controls Engineer
Principal Automation & Controls Engineer

Divergent • Torrance (CA)

On-site
USD 148,000 - 236,000
Equity plan
Discretionary bonus opportunities
Paid vacation & holidays
+1
Staff Automation & Controls Engineer
Staff Automation & Controls Engineer

Divergent • Los Angeles (CA)

On-site
USD 148,000 - 236,000
Competitive salary
Equity plan
Discretionary bonus
+6
Principal Automation & Controls Engineer
Principal Automation & Controls Engineer

Divergent • Los Angeles (CA)

On-site
USD 148,000 - 236,000
Equity plan
Discretionary results-based incentive
Paid vacation
+9
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Worky • New York (NY)

Hybrid
USD 170,000 - 230,000
Medical premiums paid by the company
Hybrid work environment
13+ holidays
DevSecOps Engineer
DevSecOps Engineer

Renesas Electronics • California (MO)

Hybrid
USD 150,000 - 160,000
Medical benefits
HSA / health savings account
Dental
+5
Senior DevOps Engineer
Senior DevOps Engineer

Applied Research Solutions • Beavercreek Township (OH)

On-site
USD 100,000 - 140,000
Senior DevOps - Azure Infrastructure & Deployment
Senior DevOps - Azure Infrastructure & Deployment

Matrix Design Group • Newburgh (IN)

On-site
USD 100,000 - 130,000
Comprehensive medical, dental, and vision insurance
401(k) Plan with company match
On-site health clinic
+1