TEMP Principal DevOps Engineer
Indexed description
Essential Functions — DevOps & CI Migration
- Design and build Azure DevOps multi-stage YAML pipelines, repos, service connections, agent pools, and variable/secret groups for the migrated teams.
- Execute source-control migration from GitLab, SVN, and Bitbucket into Azure DevOps Git, including history, and advise on project/repo structuring (project-per-product vs. multi-repo).
- Support desktop / thick-client and firmware builds — C/C++, .NET, FPGA toolchains, code-signing, and Yocto / embedded-Linux build servers in Azure.
- Containerize and manage build/scan workflows using Docker, AKS, and Azure Container Registry.
- Provide CI support for monolith-to-microservices refactoring (strangler pattern), standing up per-microservice pipelines.
- Create reusable pipeline templates so the common environment is consistent across teams; manage infrastructure with Terraform.
- Perform threat modeling using STRIDE (plus attack trees / MITRE ATT&CK for ICS where appropriate), producing data-flow diagrams with trust boundaries during the requirements/design phase.
- Threat models must cover information flows, trust boundaries, data stores, external entities, comms protocols, externally accessible physical/debug ports, JTAG/debug headers and hardware attack vectors, CVSS-scored threats, and documented mitigations — aligned to IEC 62443-4-1 SR-2.
- Build a reusable threat-model template and repeatable process, and feed outputs into CRA risk assessments (asset ID → threat modeling → risk evaluation) and Stage-Gate / Jira / ADO traceability.
- Configure and operate Snyk — Snyk Code (SAST), Open Source (SCA), Container, and SBOM — as pipeline stages in ADO/Jenkins, set severity gates, and onboard new repos to raise coverage.
- Add automated SBOM generation (CycloneDX/SPDX, machine-readable, per release) to each migrated pipeline.
- Harden pipelines: move secrets to Azure Key Vault (no hard-coded credentials), secure service connections, enforce least-privilege on ADO/AKS.
- Validate that mitigations work (SVV-2 threat-mitigation testing) and produce audit-trail artifacts (scan results, threat models, SBOMs, test records) for the CRA Annex VII technical file.
Snyk (SAST/SCA/Container/SBOM); STRIDE threat modeling with DFDs & trust boundaries; SBOM in-pipeline; CRA + IEC 62443-4-1 secure-SDLC awareness
Strongly Preferred
Terraform IaC; reusable pipeline templates / standardization; microservices / strangler-pattern CI
Embedded/OT & hardware threat modeling (debug/JTAG ports, FPGA); CVSS scoring; CVD / vuln-handling SLAs; secrets hardening (Key Vault)
Nice-to-have
Bitbucket / Jenkins / SVN; code-signing; artifact management
Attack trees / MITRE ATT&CK for ICS; mitigation-validation testing (SVV-2); Nessus, CodeQL / SonarQube; NIS2 Italy awareness
Minimum Qualifications
- 5+ years in DevOps / CI-CD engineering with hands-on Azure DevOps Pipelines and Git-based source-control migration.
- Demonstrated experience building desktop/firmware or embedded build pipelines (not web-only).
- Working knowledge of Snyk (or equivalent SAST/SCA), SBOM generation, and STRIDE threat modeling.
- Familiarity with the EU CRA and IEC 62443-4-1 secure-development lifecycle concepts.
- English working proficiency; Italian a strong plus given the mixed-language migration meetings.
Actual base salary offered to the hired applicant will be determined based on their work location, level, qualifications, job related skills, as well as relevant education or training experience.
Hourly Pay: $85.00
Equal Opportunity Employer/Protected Veterans/Individuals With Disabilities
We are an Equal Employment Opportunity employer that values the strength diversity brings to the workplace. All qualified applicants, regardless of race, color, religion, gender, sexual orientation, marital status, gender identity or expression, national origin, genetics, age, disability status, protected veteran status, or any other characteristic protected by applicable law, are strongly encouraged to apply.
The Americans with Disabilities Act of 1990 (ADA) prohibits discrimination by employers, in compensation and employment opportunities, against qualified individuals with disabilities who, with or without reasonable accommodation, can perform the “essential functions” of a job. A function may be essential for any of several reasons, including: the job exists to perform that function, the employee holding the job was hired for his/her expertise in performing the function, or only a limited number of employees are available to perform that function.
Applicants must be authorized to work for any employer in the United Sates. Doble Engineering is unable to sponsor or take over sponsorship of an employment visa at this time.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search