DevOps Engineer, Assurance and Infrastructure Services - USDS
Listed on 2026-07-10
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Information Security & Data Protection
Responsibilities
Our team owns the developer platform and release toolchain that powers Tik Tok’s US infrastructure. We focus on CI/CD pipelines, artifact repository management, and cloud deployment workflows, partnering closely with engineering teams and assurance partners (USDS/USTS, auditors) to make build, test, and release fast, secure, and compliant by design.
You will design, build, and operate the critical tooling that developers use every day: CI/CD pipelines, artifact repositories, and deployment workflows across multiple environments. You will work with engineers across teams to understand their development lifecycle, reduce friction in shipping code, and implement robust security and assurance guardrails that keep our production environments stable, auditable, and compliant.
- Own and Evolve CI/CD Pipelines:
Design, build, and maintain CI/CD pipelines for backend and platform services, improving reliability, speed, and developer experience while embedding security and compliance checks. - Secure Supply Chain Management:
Implement and manage software supply chain security controls, including SBOM generation and validation, artifact signing and attestation (e.g., SLSA), and provenance tracking to ensure the integrity of the build and release process. - Automate Policy-as-Code Gates:
Integrate and enforce automated security and compliance gates within CI/CD pipelines, such as secrets scanning, dependency risk analysis, license compliance checks, and vulnerability scanning, with fail‑safe promotion rules. - Ensure Auditability and Evidence Collection:
Design and operate systems for comprehensive auditability, including immutable change logs, deployment records, and traceable rollbacks. Support internal and external assurance requests by providing clear, auditable evidence. - Manage Cloud IAM and Secrets:
Design and enforce least‑privilege access controls in OCI/cloud environments. Implement best practices for role design, key/secrets hygiene, and periodic access reviews to minimize security risks. - Enhance System Resilience and Disaster Recovery:
Align release tooling with Risk, Disaster Recovery (DR), and Business Continuity Planning (BCP) requirements. Implement and periodically test backup and restore procedures for critical repositories and pipelines. - Develop and Maintain Incident Playbooks:
Create, document, and rehearse incident response playbooks for build/deploy failures and security events. Lead postmortems and drive corrective actions to prevent recurrence. - Design and Maintain Deployment Workflows:
Standardize deployment workflows (e.g., blue/green, canary, automated rollout/rollback) in a major cloud environment (OCI preferred). - Manage Artifact Repositories:
Administer artifact repositories (e.g., Artifactory) including layout, permissions, retention policies, and housekeeping to ensure build reproducibility and integrity.
Minimum Qualifications
- Bachelor’s degree in Computer Science, a related technical field, or equivalent practical experience.
- Solid software engineering skills with one or more programming languages (e.g., Python, Go, Java).
- Hands‑on experience building and maintaining CI/CD pipelines using systems like Git Lab CI, Jenkins, or similar.
- Experience with at least one major cloud provider (OCI, AWS, GCP), with a strong understanding of IAM concepts.
- Practical experience with artifact repositories (e.g., JFrog Artifactory, Nexus) for container images and language packages.
- Experience integrating security scanning tools (e.g., for dependencies, vulnerabilities, secrets) into CI/CD pipelines.
- Good communication skills and the ability to work closely with developers and partner teams.
Preferred Qualifications
- Experience working within compliance‑heavy environments and supporting audits (e.g., SOC2, ISO 27001, PCI).
- Expertise in designing and implementing software supply chain security measures, such as code signing, SBOM tools (e.g., Syft, Grype), and artifact attestation frameworks (e.g., SLSA).
- Deep experience with OCI, including advanced IAM, and automating infrastructure and deployments.
- Experience in platform or developer productivity teams, building internal tools and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).