Shanghai, Shanghai, China
12 days ago
Senior DevOps Engineer

Digital Business Services (DBS)

Our GCIO organisation plays a critical role for the bank. This team partners with the businesses to build the platforms, systems, and products that our customers use every day. We keep people’s money and data safe, and are at the forefront of driving innovation for our businesses, customers, and colleagues.

We are currently seeking an experienced professional to join our team.

In this role, you will:

DevOps Strategy and Automation:
•Lead the design and implementation of secure, automated CI/CD pipelines to streamline development, testing, and deployment of banking applications.
•Implement Infrastructure as Code (IaC) using tools like Terraform or Ansible to provision and manage secure, scalable infrastructure.
•Automate security scanning, compliance checks, and vulnerability management within development workflows using tools like Snyk, SonarQube, or Aqua Security.
•Drive adoption of DevSecOps best practices to embed security into the software development lifecycle (SDLC).
Incident Support:
•Collaborate with the production support team to troubleshoot and resolve production incidents, ensuring minimal downtime for critical banking systems (e.g., core banking, payment platforms).
•Provide technical expertise during incident response, focusing on identifying security-related issues and implementing rapid fixes.
Collaboration and Coordination:
•Work closely with production support and application teams to integrate secure DevOps practices into operational workflows.
•Partner with the bank's operation resilience project team to align on security and resilience initiatives, ensuring compliance with regulatory requirements.
•Coordinate with global and regional SRE and DevOps teams to maintain consistency in tools, processes, and security standards across distributed systems.
Security and Compliance:
•Ensure banking systems comply with China's regulatory requirements (e.g., Cybersecurity Law, data localization) and global banking standards.
•Implement secure coding practices, secrets management (e.g., HashiCorp Vault), and encryption to protect sensitive financial data.
•Conduct regular security assessments and audits to identify and mitigate risks in production environments.
Monitoring and Observability:
•Deploy and maintain monitoring tools (e.g., Prometheus, Grafana, Splunk) to track system performance, security events, and compliance metrics.
•Develop dashboards and alerts to proactively detect and respond to potential issues in production systems.
Process Improvement:
•Optimize CI/CD pipelines, deployment processes, and security workflows to reduce lead time, improve deployment frequency, and enhance system reliability.
•Collaborate with SRE teams to integrate reliability and security practices into automated workflows.
Team Leadership and Mentorship:
•Lead and mentor a team of DevSecOps engineers, fostering a culture of security-first development, automation, and collaboration.
•Provide training and guidance on DevSecOps tools and practices to development and operations teams.

Confirmar seu email: Enviar Email