Responsibilities:
Currently there are no overall policies or guidelines to help application developers to utilize the Azure DevOps environment in a secure and resilient way. Objective of the project is to analyze the current DevOps Lifecycle and define the target state. Documentation needs to be created to describe the Software development governance and define policies. Existing tools to support identifying software vulnerabilities in the development cycle are to be analyzed and assessed.
- Identify and document gaps in the existing Secure Software Development Lifecycle
- Define a governance framework for a modern Secure Software Development Lifecycle (definition of policies, roles, and responsibilities) based on DevSecOps principles and taking the previously identified gaps into consideration.
- Identification of gaps in central tooling for DevSecOps activities and document them in a gap analysis presentation.
- Define and document selection criteria for additional tooling to fill the identified gaps. The selection criteria should be based on industry-wide security standards.
- Create Secure Development Lifecycle guideline based on the defined framework and provide it to us for a sign off.
- Training development
- Testing
- Analytical and conceptual focus with no programming
Key Skills:
-Must have: Solid experience in the introduction of a secure Software Development Lifecycle framework in an organization
- Good overview of security tooling in the software development area
- Fluency in English language (verbal and writing)
- Experience with CI/CD pipeline tools (preferably Azure DevOps)
- Effective communication and presentation skills
- Nice to have: Microsoft Azure Know-How
- ITIL certification
- IT Security certification in development area
- German language skills
- Provide profiles in ENGLISH
If you are interested, please do not hesitate to send me your current CV.
Do you have questions? You are welcome to contact me by calling.