Role track: DevSecOps Engineer

Role overview

Embed security in delivery workflows: policy gates, supply-chain controls, and feedback loops from runtime back into build and release.

Core responsibilities (framework):

  • Secure CI/CD and deployment pipelines

  • Secure infrastructure-as-code and build artifacts

  • Admission and related policy enforcement

  • Threat modeling outcomes into monitoring and IR playbooks

  • Workload isolation and zero-trust patterns in delivery

  • Artifact signing and attestation verification gates

  • Runtime detection tuning and signal quality

  • Feed production learnings back into build/test/release

Product deep-dives

Take these after Intermediate supply-chain labs (201-05 / 201-11) or alongside Advanced runtime and supply-chain labs:

  • RHACS — policy, CI/CD gates, runtime, and compliance workflows

  • TSSC — Trusted Artifact Signer and Trusted Profile Analyzer