DevX Build Pipeline/DevOps Engineer CGEMJP
Job Description
Role Title: DevX Build Pipeline/DevOps Engineer
\nDuration: contract to run until 30/11/2026
\nLocation: Hybrid. Sheffield, 3 days onsite with additional need to travel to other offices within the UK
\nRate: up to £538.20 p/d Umbrella inside IR35
\nRole purpose/summary
\nOwn and evolve our Jenkins Shared Library powering multi-language builds (Java/Maven, Node/NPM, Python, Helm, Terraform, containers). Deliver fast, secure, provenance-rich pipelines (SLSA, SBOM, digests) and strengthen supplychain integrity across teams.
\nCore Responsibilities:
\n- \n
- Design and maintain Groovy pipeline steps (build, test, package, scan, deploy). \n
- Extend Python tooling for SLSA provenance, SBOM generation, hash/digest accuracy, and security scan aggregation (SonarQube, Sonatype IQ, SAST/Container). \n
- Optimize performance (parallel builds, caching, scope-reduced BOMs, dependency prefetch). \n
- Ensure artifact integrity (correct SHA1/SHA256 mapping, reproducible inputs, evidence modelling). \n
- Refactor Legacy scripts (remove global state, consolidate hashing, standardize templates). \n
- Document ci-config.yaml standards and usage patterns. \n
- Mentor engineers on secure pipeline development and supply-chain practices. Troubleshoot and prevent pipeline incidents. \n
Essential Skills:
\n- \n
- 7+ years engineering; 3+ in CI/CD platform or DevSecOps. \n
- Strong Jenkins + Groovy shared library expertise. \n
- Advanced Python automation (JSON/YAML processing, tooling scripts). \n
- Deep Maven/NPM/Python packaging knowledge; exposure to Helm/Terraform and container image metadata. \n
- Supply-chain security (SLSA, CycloneDX SBOM, digests). \n
- Experience with SonarQube, Sonatype IQ, container and SAST scanning. \n
- Proven performance tuning (caching, parallelization, dependency pruning). Compliance Awareness. \n
Nice-to-Have
\n- \n
- Artifact signing/attestations (cosign, OCI). \n
- Terraform module and Helm chart publishing patterns. \n
- GitOps or release automation experience. \n
- GCP/AWS cloud experience \n
Soft Skills:
\n- \n
- Precise communicator documentation discipline. \n
- Ownership mindset, able to operate with minimal supervision. \n
Deliverables (First 30 Days):
\n- \n
- Current state assessment: audit shared library structure with view to understand all building blocks and modules support requests: work on user's reported issues to get to know critical parts of the pipeline and various configuration options. Identify bugs, classify them and develop hot fixes. feature requests: deliver 2 x small features/improvements to pipeline code. \n
All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!
\nIf you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
