DevSecOps Engineer

Il y a 9 heures

Brussels, Brussels-Capital, Belgique Tata Consultancy Services Temps plein
Nature of the Tasks
• Develop, configure, and monitor DevSecOps pipelines using pipelines-as-code with integrated quality gates (linting, testing, security scanning, environment promotion), ensuring efficient and reliable CI/CD processes.
• Automate deployments with progressive delivery strategies (e.g., canary, blue/green) and feature flagging, incorporating automated rollback mechanisms to ensure reliable and repeatable releases.
• Manage deployment and setup of services and applications, ensuring they are configured correctly and optimized for the production environment.
• Manage infrastructure provisioning, scaling, and availability using Infrastructure-as-Code (IaC) practices, with drift detection, policy-as-code enforcement, and tested disaster recovery runbooks (RTO/RPO).
• Implement monitoring and observability solutions (metrics, logs, traces) aligned with service level objectives (SLOs), ensuring application and infrastructure performance and health are tracked effectively.
• Coordinate incident management through on-call rotations, incident playbooks/runbooks, and blameless post-incident reviews, ensuring production issues are resolved swiftly with lessons learned embedded.
• Perform performance tuning of both applications and infrastructure to ensure optimal usage of resources and user experience.
• Integrate security practices into CI/CD pipelines, including software supply-chain security (SBOMs, provenance checks), secrets management, and least-privilege access, to maintain secure system configurations.
• Design and maintain internal developer platforms with golden paths, reusable templates, and policy-based guardrails, enabling teams to securely and consistently self-serve infrastructure and application environments.
• Plan and implement upgrades and migrations of software stack.
• Monitor, analyse, and optimise cloud costs by applying FinOps practices such as budgeting, forecasting, rightsizing, and implementing showback/chargeback models to maximise cost efficiency.
• Document pipelines, processes, and infrastructure for reusability and knowledge transfer.
• Implement GitOps for declarative cluster and application configuration management.
• Establish artifact repositories and image signing; enforce software supply-chain policies and integrity checks. Specific Expertise and Technologies
• Proven experience with Docker, Kubernetes, Terraform, Ansible, HashiCorp Vault, Linux.
• Proven experience with DevSecOps lifecycle tools (GitLab, Atlassian, GitHub).
• Proven experience with static code analysis (SonarQube, Fortify, Snyk, etc.).
• Proven experience with black box and white box testing (OWASP, HP Fortify, etc.).
• Proven experience with repository management tools (Nexus etc.).
• Proven experience with monitoring tools (Dynatrace, Splunk, Prometheus etc.).
• Proven experience with internal developer platforms (Backstage, Humanitec etc.).
• Proven experience with development languages (Python, YAML, Bash, PowerShell, Ruby, or Perl).
• Proven experience with cloud platforms (AWS, Azure, OVH etc.).
• Proven experience with Infrastructure-as-Code (Terraform, CloudFormation, CDK, Bicep, ARM).
• Proven experience with System Design and Architecture.
• Experience with large, enterprise-level multi-user Information Systems.
• Good knowledge in establishing and managing deployment pipelines and release management.
• Good knowledge in conducting DevSecOps in an Agile work environment.
• Good knowledge in cloud security architecture and security requirements.
• Good knowledge of continuous delivery and Application Lifecycle Management tools (JIRA, Git, Bamboo, Nexus, etc.).
• Good knowledge of secret management tools (CyberArk, HashiCorp etc.).
• Good knowledge of network fundamentals (DNS, Load Balancing, Firewalls, VPNs, basic network troubleshooting, etc.).
• CI options such as GitHub Actions, GitLab CI, Jenkins; and GitOps controllers like Argo CD and Flux.
• Supply-chain tooling (e.g., SBOM generation/signing, SLSA) and policy agents (e.g., OPA, Kyverno). Minimum Level of Expertise
• Normal Certification and/or Standards Mandatory: One of the following certifications (or equivalent):
• AWS Certified DevOps Engineer – Professional
• Microsoft Azure DevOps Engineer Expert
• Docker Certified Associate
• Certified Kubernetes Administrator (CKA)
• Certified Kubernetes Application Developer (CKAD)
• HashiCorp Terraform Associate
• DevSecOps Engineering (DSOE) Skills
• Rapid self-starting capability and experience in team working.
• Excellent interpersonal and communication skills.
• Ability to participate in multi-lingual meetings, ease of communication.
• Ability in applying security and cloud best practices.
• Automation skills to optimize and understand DevSecOps pipelines.
• Ability to understand, speak, and write English; French is considered an additional asset.
• Ability to work in a team as well as autonomously.
• Results-oriented mindset, focused on delivering.