×
Register Here to Apply for Jobs or Post Jobs. X

TEMP Principal DevOps Engineer

Job in Marlborough, Middlesex County, Massachusetts, 01752, USA
Listing for: ETS-Lindgren GmbH
Seasonal/Temporary position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Job Description & How to Apply Below

Essential Functions — Dev Ops & CI Migration

A temporary (6 Months) contractor to support the Bologna and Taino (Altanova) engineering teams in migrating their desktop-application and firmware CI pipelines from Git Lab/SVN/Jenkins/ADO into Doble’s common Azure Dev Ops environment, while strengthening product-security practices required by the EU Cyber Resilience Act (CRA) and the IEC 62443-4-1 secure-development lifecycle. The contractor will embed threat modeling, Snyk scanning, and SBOM generation directly into the migrated pipelines so that CRA/CE technical evidence is produced as a by-product of day-to-day engineering.

  • Design and build Azure Dev Ops multi-stage YAML pipelines
    , repos, service connections, agent pools, and variable/secret groups for the migrated teams.
  • Execute source-control migration from Git Lab, SVN, and Bitbucket into Azure Dev Ops Git
    , including history, and advise on project/repo structuring (project-per-product vs. multi-repo).
  • Support desktop / thick-client and firmware builds — C/C++, .NET, FPGA tool chains, code-signing, and Yocto / embedded-Linux build servers in Azure.
  • Containerize and manage build/scan workflows using Docker, AKS, and Azure Container Registry
    .
  • Provide CI support for monolith-to-microservices refactoring (strangler pattern), standing up per-microservice pipelines.
  • Create reusable pipeline templates so the common environment is consistent across teams; manage infrastructure with Terraform
    .
Essential Functions — Security, Threat Modeling & CRA
  • Perform threat modeling using STRIDE (plus attack trees / MITRE ATT&CK for ICS where appropriate), producing data-flow diagrams with trust boundaries during the requirements/design phase.
  • Threat models must cover information flows, trust boundaries, data stores, external entities, comms protocols,
    externally accessible physical/debug ports, JTAG/debug headers and hardware attack vectors
    , CVSS-scored threats, and documented mitigations — aligned to IEC 62443-4-1 SR-2.
  • Build a reusable threat-model template and repeatable process
    , and feed outputs into CRA risk assessments (asset  → threat modeling → risk evaluation) and Stage-Gate / Jira / ADO traceability.
  • Configure and operate Snyk — Snyk Code (SAST), Open Source (SCA), Container, and SBOM — as pipeline stages in ADO/Jenkins, set severity gates, and onboard new repos to raise coverage.
  • Add automated SBOM generation (CycloneDX/SPDX, machine-readable, per release) to each migrated pipeline.
  • Harden pipelines: move secrets to Azure Key Vault (no hard-coded credentials), secure service connections, enforce least-privilege on ADO/AKS.
  • Validate that mitigations work (
    SVV-2 threat-mitigation testing
    ) and produce audit-trail artifacts (scan results, threat models, SBOMs, test records) for the CRA Annex VII technical file.
Requirements Summary — Must vs. Preferred vs. Nice-to-Have

Priority

Dev Ops / CI

Security, CRA & Threat Modeling

Must-have

Snyk (SAST/SCA/Container/SBOM);
STRIDE threat modeling with DFDs & trust boundaries; SBOM in-pipeline; CRA + IEC 62443-4-1 secure-SDLC awareness

Strongly preferred

Embedded/OT & hardware threat modeling (debug/JTAG ports, FPGA); CVSS scoring; CVD / vuln-handling SLAs; secrets hardening (Key Vault)

Nice-to-have

Bitbucket / Jenkins / SVN; code-signing; artifact management

Minimum Qualifications

  • 5+ years in Dev Ops / CI-CD engineering with hands-on Azure Dev Ops Pipelines and Git-based source-control migration.
  • Demonstrated experience building desktop/firmware or embedded build pipelines (not web-only).
  • Working knowledge of Snyk (or equivalent SAST/SCA),
    SBOM generation, and STRIDE threat modeling
    .
  • Familiarity with the EU CRA and IEC 62443-4-1 secure-development lifecycle concepts.
  • English working proficiency;
    Italian a strong plus given the mixed-language migration meetings.
PHYSICAL REQUIREMENTS:

While performing the duties of this job the employee is often required to stand, sit, use computers, read, write, type, use copy machines, file paperwork, use telephones, and utilize written and oral communication to interact with clients, co-workers , and customers. Reasonable accommodations may be made to enable individuals to perform the essential functions of…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary