DevSecOps Manager

Posted Feb 16

About Benefitfocus:

Benefitfocus, a wholly owned subsidiary of Voya Financial (NYSE: VOYA), is a leading provider of cloud-based benefits administration software solutions for consumers, employers, insurance carriers and brokers. Benefitfocus’ platform consists of an integrated portfolio of products and services enabling clients to efficiently shop, enroll, manage and exchange benefits information. With a user-friendly interface and consumer-centric design, the Benefitfocus platform provides one place for consumers to access all their benefits. Benefitfocus solutions support the administration of all types of benefits including core medical, dental, and other voluntary benefits plans as well as wellness programs.

Job Description:

We are seeking a DevSecOps Manager to join our team. The successful candidate will have a strong on-prem and cloud background with experience automating a continuous Integration/continuous delivery (CICD) pipeline with a goal to increase the efficiency, timeliness, and security of software deployments. In addition, the DevSecOps manager is responsible for maintaining middleware software components within the platform environment.

This role requires hands-on engineering, mentoring other team members, and building/executing a roadmap and strategy for the program. This role reports directly to the CISO and partners closely with the Cybersecurity, Technical Operations, Architecture, and Software Engineering teams.

Responsibilities:

  • Create and on a DevSecOps strategy and roadmap for the enterprise
  • Work closely with other technical teams to build a high quality, low friction, secure deployment pipeline supporting an Agile software development methodology
  • Create a flexible, automated CICD pipeline that can be easily modified to support changes/improvements in database and infrastructure
  • Manage platform middleware components including upgrading and patching. A portion of the middleware components include Weblogic, Tomcat, ActiveMQ, Kubernetes, Jenkins, Teamcity, Ansible, Java, Hashicorp, Kubernetes, and JBoss
  • Manage a team of 10+ individuals both onshore and offshore
  • Establish team member commitments and ensure deliverables are met with quality
  • Develop maintainable orchestration code using standard best practices
  • Create Ansible playbooks and Terraform scripts to support deployment automation and IaC
  • Address issues with respect to performance or failed builds in a timely and efficient manner
  • Develop solutions/code to automate routine day-to-day tasks improving the timeliness of the software release process
  • Help application development teams with code deployment for emerging codebases to ensure that they are highly scalable, secure, available, and meet applicable regulatory & auditing requirements
  • Additional responsibilities, as required

Experience and Skills:

  • Bachelor’s degree or higher
  • 3-5 years of DevOps/DevSecOps experience preferred
  • 3-5 years Automating CI/CD pipelines
  • Experience with Middleware application software Apache Tomcat, Spring Boot, Jetty, JBoss
  • Experience containerizing applications/services
  • 2-3 years working with automation tools such as Ansible, Terraform, or Cloud Formation
  • AWS certification in relevant technologies preferred
  • Experience with cloud security tools preferred
  • Experience with Kubernetes/orchestration/containerization tools
  • Experience working in environments with PCI, PHI, SOX, or HITRUST regulatory auditing requirements preferred
  • Innovative thinker who strives to continuously improve the DevSecOps process
  • Motivated, self-starter with a proven track record of delivering high-quality results in a dynamic environment with little supervision
  • Team player not afraid to take on new challenges or projects that require them to learn a new technology or stretch themselves outside their comfort zone
  • Strong work ethic
  • Great verbal and written communicator
  • This is a remote work position that requires the individual to be available during core business hours of 9-5 Eastern Time.