Role
AWS DevSecOps GITHUB
Key Responsibilities*
Below are the specifics of the role:
- Design, implement, and maintain GitHub Actions workflows for CI/CD across multiple repositories and environments (dev, staging, production)
- Build and manage self-hosted ARC (Actions Runner Controller) runners on Kubernetes (EKS), including runner scaling, pod identity, and network policies
- Integrate GitHub Advanced Security (GHAS) capabilities — secret scanning, push protection, code scanning (CodeQL), and dependency review — into developer workflows
- Migrate legacy CI/CD pipelines (Jenkins, TeamCity, CodePipeline/CodeBuild) to native GitHub Actions
- Enforce branch protection rules, required status checks, environment gates, and deployment approvals
- Develop reusable composite actions and reusable workflows to standardize pipeline patterns across teams
- Collaborate with InfoSec to embed SAST, DAST, SCA, and secrets hygiene into every pipeline stage
- Maintain GitHub Enterprise (EMU or GHEC) organization settings, team provisioning via SCIM/Okta, and repository governance policies
- Instrument pipelines with audit logging, metrics, and alerting (Splunk, CloudWatch, Datadog)
- Support infrastructure-as-code deployments via GitHub Actions (Terraform, CloudFormation, CDK)