Role Overview
This position owns the automation layer that moves software from commit to production across cloud-native environments. Day to day, the engineer builds and maintains CI/CD and GitOps workflows, hardens them with security controls, and keeps deployments observable, repeatable, and fast. The work directly affects how safely and quickly the organisation can ship software, respond to incidents, and meet internal and regulatory expectations. This role reports to the IT Development Manager.
Key Responsibilities
- Build, extend, and maintain delivery pipelines in GitHub Actions, including reusable workflows, automated gates, and promotion steps that support frequent releases.
- Run deployments through ArgoCD and GitOps principles, keeping environment state in version control and enabling blue/green and canary releases on Kubernetes.
- Provision cloud and platform resources with Terraform or comparable infrastructure-as-code tooling, and manage Docker images plus Kubernetes manifests for consistent runtime environments.
- Embed DevSecOps controls into pipelines: wire in container and code scanners such as Snyk, Aqua Security, Anchore, or CodeQL; automate SAST, DAST, and IAST checks; track findings through to remediation with the IT team; and keep controls aligned with internal security policies and applicable standards.
- Administer secrets and credentials in HashiCorp Vault or Azure Key Vault, applying appropriate access controls across environments.
- Instrument monitoring, logging, and performance visibility for services, applications, and infrastructure; use that data to diagnose bottlenecks and improve reliability while understanding the servers, networking, storage, and virtualization underneath.
- Diagnose and resolve pipeline and deployment failures across environments, produce runbooks and documentation, and support real-time incident response with development, security, and operations colleagues.
- Contribute to Agile ceremonies, version control and configuration management practices, and continuous improvement efforts that reduce friction in the software delivery lifecycle.
Requirements & Qualifications
- Bachelor's degree in Computer Science or an equivalent qualification from a recognised university.
- At least three years in DevOps, platform engineering, or a closely related role.
- Hands-on scripting and coding ability, with working knowledge of languages such as Python, JavaScript, and React.js.
- Strong grounding in DevSecOps and cloud-native tooling, including CI/CD platforms (GitHub Actions, Azure DevOps, Jenkins, GitLab CI), GitOps tools (ArgoCD), infrastructure as code (Terraform preferred), and containers/orchestration (Docker, Kubernetes).
- Experience using container and code security scanners (Snyk, Aqua Security, Anchore, CodeQL) and secrets management platforms (HashiCorp Vault, Azure Key Vault).
- Familiarity with security testing tools such as OWASP ZAP, Burp Suite, and Nessus, plus an understanding of secure coding, encryption, threat modelling, and vulnerability management.
- Knowledge of compliance frameworks and standards such as GDPR, ISO 27001, and NIST.
- Comfortable managing IT infrastructure across on-premises and cloud environments, including servers, operating systems, networking, storage, virtualization, and platforms such as Azure and GCP.
- Ability to investigate reliability or performance problems, automate scanning and monitoring, and use B/OSS tools to record information accurately and promptly.
- A strong advocate for change who improves and automates processes within a DevOps culture.
- Professional IT security certifications such as CISSP, CCSP, CISA, or CISM are a plus.
794 open positions on Semasocial right now
· 10875 open positions in Nairobi County, Kenya
· 35 posted in the last 7 days
Contact Information