DevOps Tools Lead (Vulnerability Scanning) - Vice President Citigroup Tampa, FL

Kate

Administrator
Команда форума
Citi, the world leading global bank, has approximately 200 million customer accounts and a presence in more than 160 countries and jurisdictions worldwide. Citi provides consumers, corporations, governments and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management. Citi enables clients to achieve their strategic financial objectives by providing them with cutting-edge ideas, best-in-class products and solutions, and unparalleled access to capital and liquidity.

Department Overview:

Citi’s Enterprise Infrastructure Operations & Technology organization (EIO&T) is driving an innovative Cloud First strategy that works to optimize the IT environment, reduce complexity, and implement high degrees of automation to enable more agile application delivery.

We aim to give Citi businesses a competitive edge by leveraging cloud scale architectures and enabling new infrastructure economics. EIO&T operates as a technology company focused on implementing scalable and innovative next gen technology solutions that will shape the future of global banking.

This is a challenging and exciting opportunity to work in the Application Lifecycle Automation (ALA) area within the Global Functions Technology (GFT) Sector.

GFT has set an ambitious goal to standardize tool models and invest in the latest technology that improves productivity, application lifecycle management and security, particularly in the public cloud domain. As part of the technology team, you will play a key role in achieving that goal. The team works side by side with Developers, Engineers and Architects in setting the sector tooling/application scanning strategy. Providing technical support and on-boarding of new applications to sector scanning tools - in addition to building out and maintaining existing scanning tool integrations with existing CI/CD tooling models.

The DevOps Tools Lead (Vulnerability Scanning) will be instrumental in managing the approach to code quality, vulnerability scanning and reporting; in addition, promoting best practices that enable applications teams to use the scanning tools in an optimal way and provide the roadmap for future scanning tool integrations. The role is responsible for all aspects of scanning tools used by the GFT sector including strategy, implementation, developing proof of concept models, building, maintaining and operating the model through all phases of its life – including metric reporting and training delivery. A key aspect and challenge of the role is the ability to understand, leverage and build on pre-existing CI/CD models and scanning tool integrations already used within the sector by the application development teams.

The ideal candidate will have knowledge of CI/CD orchestration with a specific focus on ensuring that the pipelines, using a range of scanning tools, effectively scan application code for vulnerabilities and quality issues, and identify and report on same to the application team and senior management team.

The role requires a talented technologist with experience developing and defining CI/CD processes and best practices that can be integrated with scanning tools such as SonarQube, Blackduck, CheckMarx.

The successful candidate will take full ownership of the broad range of tool integrations, associated processes, training and sector reporting for all GFT Scanning tools that are used as part of the software development lifecycle. In addition they will be instrumental in formulating the scanning tool strategy that GFT application teams will utilize in the future.

Responsibilities/Requirements:

Must be a self-starter, effective listener, problem solver and team player.

Excellent communication skills with the ability to influence manage and articulate clearly to project stakeholders and senior management through clear project planning and status reporting

Excellent social and organizational skills, able to handle diverse situations, multiple initiatives and changing priorities

Strong troubleshooting, problem solving skills and the ability to manage issues in a multi-platform environment

Ability to work independently, while collaborating cross-functionally with partner security, operations, and infrastructure teams

In depth knowledge of SonarQube Scans, Quality Profiles, Quality Gate management and Portfolio Management and Reporting

Knowledge of Blackduck Scans, Issue Resolution and Portfolio Management and Reporting

Knowledge of CheckMarx Scans, Issue Resolution and Portfolio Management and Reporting

Ability to create, deliver and maintain product roadmaps for all scanning tools used within the GFT Sector

Ability to manage and report on all projects within the scanning tools domain in a timely manner

Ability to lead other team members with respect to workload management, issue resolution and client interaction.

Qualifications/Experience:
  • 5+ years experience with engineering/support experience in code quality/vulnerability scanning/analysis tools
  • 5+ years experience with Cloudbees Jenkins, Bitbucket)
  • 5+ years engineering/support experience in code quality/vulnerability scanning/analysis tools
  • 5+ years experience of DevOps processes and methodologies, including source control best practices (Git) and deployment tools such as Harness.io, BMC-RLM
  • 5+ years experience of continuous integration, continuous deployment (CI/CD) and related orchestration, code management tools (Cloudbees Jenkins, Bitbucket)
  • 5+ years experience in using, supporting and maintaining scanning tools such as SonarQube, Blackduck, CheckMarx
Education:

Bachelor’s degree/University degree or equivalent experience

Exceptional candidates who do not meet these criteria may be considered for the role provided they have the necessary skills and experience.

What we Offer:

As well as a competitive salary and consideration for a yearly discretionary bonus Citi offer;

23 days paid annual leave

Award winning pension scheme,

Life assurance and

Private medical insurance with Bupa healthcare

In addition, we offer a competitive maternity, paternity and adoption leave scheme and employees also have the option (provided they have a student loan from the Student Loan Company) to divert saver and company match contributions to their student loan. We pride ourselves on our ability to offer employees a number of lifestyle benefits including; on site restaurant and coffee shops, online shopping and concierge service and subsidized clubs and societies.

Our select benefit package offers you the opportunity to customize your benefits according to your own lifestyle preferences and includes corporate discounts, memberships and a range of additional extras.

Our vast range of diversity networks and on site multi faith room demonstrates Citi’s commitment to growing a diverse workforce.



Job Family Group: Technology



Job Family: Applications Development



Time Type:



Citi is an equal opportunity and affirmative action employer.

Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Citigroup Inc. and its subsidiaries ("Citi”) invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review .

View the " " poster. View the .

View the .

View the
 
Сверху