SCOPE WORK
The contractor will be part of a team providing Technical Level 2 and 3 support, ensuring the secure, available, managed and compliant delivery of Public Cloud Services to NATO and its Strategic Commands.
Under the direction / guidance of the IaaS/PaaS Team technical lead or the Cloud Operations Center Manager, the contractor will perform the following activities:
1)Operation of cloud infrastructure in Microsoft Azure by leveraging DevSecOpspractices:
a)Deploy and manage landing zones by utilizing DevSecOps practices to ensure asecure, scalable foundation for cloud workloads;
b)Deploy and manage cloud workloads on top of the landing zones in an automatedfashion;
c)Utilize Infrastructure as Code and CI/CD pipelines through Azure Devops;
d)Build, deploy and maintain containerized workloads using Azure KubernetesServices (AKS);
e)Deploy and monitor Azure Virtual Machines (VMs), including sizing, patching,backup, performance tuning and cost optimization;
f)Build and maintain automated disaster recovery and backup solutions usingservices like Azure Backup, Site Recovery and storage replication;
g)Monitor the performance and effectiveness of landing zones and cloudworkloads;
h)Identify opportunities for improvement and implement optimizations to enhancesecurity and efficiency.
2)Support for application deployment and troubleshooting:
a)Manage secure and reliable access to applications for end-users includingconfiguration of Azure Application Gateways, Azure load-balancers and customdomains;
b)Monitor Application availability, performance and security using services such asAzure Monitor, Log Analytics, Application insights and configure automatedalerts;
c)Provide support for Microsoft Azure Services - related issues, includingtroubleshooting access, networking and cloud resource specific issues;
d)Maintain comprehensive documentation for Microsoft Azure Services processes,configurations, and workflows;
3)Security and Compliance:
a)Implement and manage governance controls such as Azure policies to ensurecompliance with organizational standards;
b)Ensure all deployed workloads and services adhere to Zero trust securityprinciples, including proper network segmentation, identity-base access controland logging;
c)Conduct regular audits and reviews of access controls and permissions.
4)Collaboration and Communication:
a)Collaborate with IT security, compliance, and other relevant teams to ensurecohesive cloud resources management strategies.
b)Contribute to the lifecycle of cloud secure products in collaboration with the CTOCCOE to ensure reusable, secure and automated infrastructure modules
c)Communicate effectively with stakeholders to understand IaaS and Paasrequirements and address concerns.
5)Automation and Efficiency:
a)Identify opportunities to enhance efficiency through automation and proactivelyimplement solutions.
b)Champion continuous improvement by evaluating new Azure capabilities,DevOps tools and security practices and integrate them into operations.
c)Lead operational readiness for new cloud solutions, by establishing runbooks,knowledge base transfer sessions and handover to support teams
The services related to the activities above will be delivered in Sprints, and each sprint will have the duration 5 working days.
QUALIFICATIONS
The Support for DevSecOps Engineering requires an experienced DevSecOps Engineer with the following qualifications:
1)Technical Expertise:
a.In-depth knowledge of Microsoft Azure Cloud IaaS/PaaS Services;
b.Proficiency in designing, deploying and managing landing zones in MicrosoftAzure by leveraging IaC and CI/CD pipelines;
c.Expertise in managing governance controls such as Azure Policy;
d.Experience in building, deploying and maintaining containerized workloadsusing Azure Kubernetes Services (AKS);
e.Experience in managing deploying and monitoring Azure Virtual Machines(VMs);
f.Expertise in enabling secure and reliable access to applications for end-users.
2)Analytical and Problem-Solving Skills:
a.Strong analytical skills to assess and improve DevSecOps processes andworkflows;
b.Ability to troubleshoot complex Microsoft Azure Services issues andimplement effective solutions.
3)Security and Compliance Knowledge:
a.Understanding of security best practices and compliance requirementsrelated to Microsoft Azure services and DevSecOps practices;
b.Experience conducting audits and ensuring adherence to regulatorystandards.
4)Communication and Collaboration:
a.Excellent communication skills to effectively collaborate with IT teams,stakeholders, and end-users;
b.Ability to document processes clearly and provide training on Microsoft AzureServices and DevSecOps practices.
5)Organizational Skills:
a.Strong organizational skills to manage multiple tasks and priorities effectively;
b.Attention to detail in managing user accounts, groups, and access controls.
6)Team Collaboration:
a.Ability to work effectively as part of a team and share knowledge andresources;
b.Willingness to collaborate with colleagues to solve complex issues.
7)Others:
a.The Contractor has strong customer relationship skills, including negotiatingcomplex and sensitive situations under pressure;
b.Full proficiency in the English language. French language proficiency is ofadvantage.