Lead the design, implementation, and maintenance of a comprehensive DevSecOps CI build pipeline that integrates strict automated security guardrails directly into the developer workflow. This includes orchestrating local pre-commit secret detection, software composition analysis (SCA) to detect vulnerable third-party dependencies, static application security testing (SAST) and quality gates to enforce code metrics, rootless container builds, immutable container image scanning, and automated smoke testing before final registry release
Enforce a strictly decoupled CI/CD and GitOps delivery architecture to maintain a clean boundary between build artifacts and deployment configurations. The candidate will manage and automate the promotion of immutable image tags across Dev, SIT, UAT, and Production environments using a single-branch configuration repo with directory-based overlays to completely eliminate branch-per-environment drift, driving automated reconciliation solely via GitOps pull requests and controllers.
Own AppSec lifecycle governance, supply chain security, and post-deployment runtime defenses across all environments. Key responsibilities include securing the software supply chain by generating Software Bill of Materials (SBOMs) and signing container images (Cosign), integrating Dynamic Application Security Testing (DAST) via OWASP ZAP to catch runtime exploits in staging, and deploying active cloud-native runtime security cameras (Falco) on production Kubernetes nodes to detect and alert on suspicious container system calls in real-time....