DevSecOps Tool Ops Engineer

Highlights:

 5.00 – 7.00 Years

 20.00 – 25.00 INR (Lacs)/Yearly

 Full-time

 Noida, Bengaluru

Skills

Devsecops

Devsecops Engineer

DEVSecOPS tooling

DevSecOps CI CD

Roles & Responsibility

JOB PURPOSE

• Operate and maintain DevSecOps toolchain platforms supporting software development, security scanning, CI/CD automation, and delivery pipeline operations within the enterprise BSS managed services environment.

• Ensure continuous availability and operational effectiveness of DevSecOps tools used by BSS delivery and operations teams.

DUTIES AND RESPONSIBILITIES

• Operate and maintain DevSecOps toolchain: GitLab, Jenkins, Nexus, SonarQube, Anchore/Trivy, OWASP ZAP, Snyk, or equivalent.

• Administer CI/CD pipelines used for BSS application build, test, and deployment automation.

• Manage container image registries (Harbor, Quay, DockerHub) and artifact repositories (Nexus, JFrog Artifactory).

• Monitor DevSecOps platform health, pipeline execution success rates, and tool availability.

• Troubleshoot CI/CD pipeline failures, build errors, test execution issues, and deployment failures.

• Manage and maintain code quality gates and security scan policies in the pipeline.

• Operate vulnerability management tools: prioritize findings from SAST, DAST, SCA scans.

• Administer source code management (SCM) platform: GitLab/GitHub repository access, branch policies, merge request rules.

• Support integration of DevSecOps toolchain with ITSM, monitoring, and collaboration platforms.

• Perform toolchain upgrades, patches, and configuration changes under Change Management.

• Maintain DevSecOps toolchain documentation, pipeline run-books, and onboarding guides.

• Report on pipeline metrics: build success rate, deployment frequency, change failure rate, MTTR.

• Ensure DevSecOps tool access is governed per IAM and security policies.

SKILLS & EXPERIENCE

• 5–8 years of experience in DevOps/DevSecOps engineering.

• Expert knowledge of CI/CD platforms: Jenkins, GitLab CI, GitHub Actions, or Tekton.

See also  Direct Tax 

• Experience with security tooling: SonarQube, OWASP ZAP, Snyk, Trivy, or equivalent SAST/DAST/SCA tools.

• Container and Kubernetes expertise: Docker, Podman, Kubernetes, OpenShift.

• Experience with artifact management: Nexus, JFrog Artifactory.

• Scripting skills: Python, Bash, Groovy (Jenkins pipelines).

• Knowledge of infrastructure-as-code: Ansible, Terraform, Helm.

• Understanding of OWASP security principles and DevSecOps best practices.

• ITIL change management awareness for toolchain modifications.

• English skills – oral and written.

Requirements

TECHNICAL SKILLS – SYSTEM & PLATFORM COVERAGE

• DevSecOps – Primary platform – DevSecOps toolchain operations: GitLab/Jenkins CI/CD pipeline administration, SonarQube code quality gates, Trivy/OWASP ZAP/Snyk security scanning, Nexus artifact repository, and container image registry management

• Ansible – Primary automation platform – Ansible playbook management, AWX/Tower administration, infrastructure-as-code pipeline integration, and

automated BSS component configuration management via Ansible

• RHOS/Virtualization – CI/CD deployment target – DevSecOps pipelines deploying Ericsson BSS application images to RHOS OpenShift container platform; pipeline integration with OpenShift APIs

• Ericsson Billing (EB) – EB DMP Kubernetes deployment pipeline – CI/CD pipeline for EB container image build, security scanning, and deployment to OpenShift/RHOS

• Ericsson Order Management (EOC) – EOC deployment pipeline – automated build, test, scan, and deployment pipeline for EOC application releases.

• Ericsson Product Catalog (ECM) – ECM deployment pipeline – CI/CD automation for ECM catalog platform releases and configuration deployments

• Ericsson Mediation (EM) – EM deployment automation – Ansible-based EM configuration management and pipeline-driven EM patch deployments

• IAM/PAM/security tools – Pipeline secret management – vault integration for credential management; container image signing and verification; DevSecOps access governance and privileged pipeline account control

See also  Amazon Connect – Senior Analyst

• Monitoring (ENM, MITO ELK) – Pipeline metrics and deployment event logging – build success rate, deployment frequency, change failure rate, and MTTR dashboards in MITO ELK

• ITSM (MITO) – Change management integration – CI/CD pipeline linked to MITO ITSM change records; deployment governance and emergency change automation

EDUCATION

• University degree in Computer Science, Software Engineering, or equivalent.

DevOps/Security certifications preferred.

WORKING HOURS

• Business Hours 8×5.

• On-call for P1 DevSecOps toolchain incidents.