01 Zakres zadań
- Define and maintain the DevSecOps service roadmap aligned with business and security priorities.
- Establish service standards, guardrails, and reference architectures for the DevSecOps platform.
- Embed security controls into CI/CD pipelines and developer workflows.
- Drive adoption of secure coding, SAST, DAST, SCA, secrets scanning, and container security.
- Define and enforce security gates and quality thresholds across the SDLC.
- Ensure high availability, performance, and resilience of DevSecOps tooling and pipelines.
- Define SLAs/SLOs and monitor service health.
- Lead incident management and root cause analysis for platform issues.
- Manage upgrades, capacity planning, and technical debt.
- Ensure DevSecOps processes meet internal security policies and external regulatory requirements.
- Support audit readiness (e.g., SOX, ISO, SOC2).
- Implement access controls, audit logging, and segregation of duties.
- Drive pipeline standardization and reusable automation patterns.
- Reduce manual controls through policy-as-code and infrastructure-as-code.
- Continuously optimize lead time, deployment frequency, and failure rates.
- Act as the primary service owner and escalation point.
- Manage service demand, intake, and prioritization.
- Manage DevSecOps platform budget and forecast.
