DevSecOps Architect
K&K Global Talent Solutions INC. · Canada
قدّم وتابع مع أبلاي إيدجPosition: DevSecOps Architect – Platform Engineering & Supply Chain Security Location: Remote- Montreal QC Job type: Full-Time/Permanent HiringLead architecture, governance, and evolution of enterprise DevSecOps platforms and software delivery pipelines across Agile Release Trains. Design and validate DevSecOps solutions through hands-on POCs before enterprise rollout. Define CI/CD standards, govern container security, Kubernetes/GKE integration, Sonatype Nexus, and software supply chain security (SAST, SCA, SBOM, signing, policy enforcement).Key Responsibilities:Lead enterprise DevSecOps platform architecture, governance, and evolution across Agile Release TrainsDesign, document, validate, and demonstrate DevSecOps solutions via hands-on POCs before rolloutDefine CI/CD standards: source control, branching, PRs, releases, multi-stage YAML pipelines, approvals, embedded security controlsGovern container image security: registries, scanning, signing, SBOM generation, provenance, promotion, vulnerability management, immutabilityPartner with Cloud Architecture on secure Kubernetes/GKE deployments, admission controls, Helm, GitOps, workload identity, pipeline integrationDesign and govern Sonatype Nexus for secure repository access, dependency controls, lifecycle management, artifact traceabilityIntegrate SAST, SCA, secret scanning, IaC/container scanning, attestations, signing, policy enforcement into delivery workflowsSupport architecture reviews, risk assessments, audit evidence, remediation, and alignment with cybersecurity/enterprise standardsEvaluate and apply AI-assisted tools for pipeline development, documentation, testing, compliance validation, vulnerability triageBuild reusable pipeline templates, scripts, integrations, secrets-management workflows, service-management automation at enterprise scaleGuide and mentor application teams, DSO Champions, platform teams, and junior resources through standards and best practicesRequired Skills:Primary: Enterprise DevSecOps architecture, CI/CD governance, YAML pipelines, Kubernetes/GKE security, Helm, GitOps, admission controls, workload identity, Sonatype Nexus, SBOM generation, image signing, Sigstore/Cosign, SLSA, SAST, SCA, secret scanning, IaC scanning, container scanning, policy enforcement (OPA/Rego, Kyverno), software supply chain security, risk assessments, audit evidence, applied AI for DevSecOps, platform engineering, reusable pipeline templates, secrets management, technical leadership, mentoring, Agile Release Trains, POCsTools/Frameworks: GitHub Actions, GitLab CI, Azure DevOps, Jenkins, ArgoCD, Flux, Docker, Sonatype Nexus (Repository Manager, Lifecycle, IQ Server), Snyk, Trivy, Syft, Grype, Semgrep, Sigstore (Cosign, Fulcio, Rekor), HashiCorp Vault, Azure Key Vault, AWS KMS, CycloneDX, SPDX, Veracode, Checkmarx, Aqua Security, Prisma Cloud, Terraform, Python, Bash, Go, Git, Jira, Confluence, ServiceNow, GitHub Copilot, CodeQL, Falco, Prometheus, Grafana, ELK, SplunkDatabase/Cloud: GCP (GKE, Artifact Registry, KMS, Secret Manager), Azure (AKS, ACR, Key Vault), AWS (EKS, ECR, KMS, Secrets Manager), Harbor, JFrog Artifactory, Entra ID, Okta, Ping Identity, SSO/SAML/OIDC, RBAC/ABAC, audit logging, multi-cloud, hybrid cloud