Lead DevOps / DevSecOps
Core
Build secure, automated delivery foundations for critical UAE traffic and public-sector systems by modernizing CI/CD pipelines and infrastructure.
Role type
Lead DevSecOps / Azure Platform Engineer
Builds
Secure CI/CD pipelines, automated scanning, infrastructure-as-code environments, and production observability for .NET/ASP.NET Core applications.
Domain
Public sector / Traffic systems / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Azure DevOps Pipelines, Azure production services (App Services, SQL, Storage, Key Vault, Entra ID, Monitor), CI/CD for .NET/ASP.NET Core, Infrastructure as Code (Bicep/Terraform), Secrets management, SAST/SCA/secret scanning, Docker/containerization, Branching and deployment gates
Preferred skills
Regulated/government/financial system experience, Modernizing manual deployment environments, APIM/WAF/private endpoints/NSGs/managed identity/RBAC, Security tools (SonarQube, Snyk, GitHub Advanced Security, Defender for Cloud, OWASP ZAP, Trivy, Checkov, Dependabot), Azure certifications (AZ-400, AZ-104, AZ-305, AZ-500)
Technologies
Azure DevOps, Azure App Services, Azure SQL, Azure Storage, Azure Key Vault, Entra ID, Application Insights, Azure Monitor, Bicep, Terraform, Docker, .NET, ASP.NET Core, SonarQube, Snyk, GitHub Advanced Security, Microsoft Defender for Cloud, OWASP ZAP, Trivy, Checkov, Dependabot
Responsibilities
Build baseline Azure DevOps pipelines for .NET/ASP.NET Core applications; Add build, test, SAST, SCA, secret scanning, artifact versioning, and deployment gates; Remove plaintext secrets and migrate to Azure Key Vault; Establish environment promotion across Dev/Test/Staging/Production; Create rollback-ready deployment procedures; Implement secure variable groups, service connections, managed identities, and least-privilege access; Support Azure App Services, Azure SQL, Storage, APIM, WAF, Application Insights, and Azure Monitor; Partner with security/governance to align releases with OWASP, ISO 27001, and internal change controls; Train developers on practical pipeline usage.
Seniority
Senior, hands-on IC