• Build and maintain CI/CD pipelines across a range of languages and functions, primarily in GitHub Actions.
• Develop and optimize containerized build and test workflows; own base images, build caching, and artifact management (JFrog Artifactory).
Secure Containers, SBOM & Scanning
• Own the secure container supply chain: harden base images, manage trusted registries, and integrate image scanning into every build.
• Automate SBOM generation and vulnerability/license scanning (e.g., JFrog Xray) across artifacts and container images, delivering results back to software teams in a clear, actionable, automated format.
• Own static analysis tooling (e.g., Black Duck, Klocwork) and surface findings in a digestible, automated way.
Software Supply-Chain Security
• Code Signing**:** Own code-signing infrastructure and verification workflows that guarantee the authenticity and integrity of Apex software
• Build lightweight internal solutions — policy-as-code, custom scanners, CI/CD integrations — that make security and compliance automatic and auditable.
• Partner with software engineers to identify, triage, and remediate application security vulnerabilities; champion secure coding, threat modeling, and developer security training.
• Work with embedded, ground, and infrastructure teams to embed security principles directly into CI/CD pipelines.