Qualitest · 20 hours ago
#21291 - DevSecOps Release Manager
Qualitest is a leading AI-powered Quality Engineering Company, seeking a DevSecOps Release Manager to join their growing team. The role involves end-to-end release ownership, managing CI/CD pipelines, and integrating security controls to ensure smooth and secure software releases.
ConsultingEnterprise SoftwareInformation ServicesInformation TechnologyOutsourcingQuality AssuranceSoftwareTest and Measurement
Responsibilities
End to end release ownership across applications, ensuring timelines, dependencies, and risks are tightly managed
Hands on CI/CD engineering expertise, including building, maintaining, and troubleshooting pipelines
Strong DevSecOps discipline with integrated security controls and solid change/incident management
Integration planning with other apps
Release Planning & Governance
Own the maintenance of end-to-end release calendar, milestones, and scope across applications/services and environments (dev/test/stage/prod)
Facilitate release planning ceremonies: scope reviews, go/no-go, readiness checkpoints, cutover rehearsals, and PIRs (post-implementation reviews)
Coordinate with Modern Sales and Shared Services teams to align release content, dependencies, and windows
Ensure adherence to the Management Model SOPs for change, risk, approvals, and documentation
Own all release-related tickets and workflows in the designated system (e.g., Change Requests, Release Records, CAB submissions, approvals)
Ensure tickets meet SOP criteria: correct metadata, risk ratings, rollback/contingency plans, test evidence, and stakeholder sign-offs
Serve as the first escalation point for release incidents; manage war rooms, communications, and coordinated recovery
Perform root-cause analysis (RCA) and track corrective/preventive actions (CAPA) to closure
Build, operate, and troubleshoot CI/CD pipelines (e.g., YAML pipelines, build agents, artifact/versioning strategy, approvals, gate policies)
Execute release activities hands-on: tagging, packaging, artifact promotion, parameterization, configuration, and deployment orchestrations
Maintain pipeline-as-code standards, templates, and reusable components for consistency and scale
Optimize build/test stages (parallelization, caching, selective test runs) to improve lead time and reliability
Integrate security controls into the pipeline (SAST, SCA, secret scanning, container/image scanning, SBOM generation)
Enforce policy gates for quality and security thresholds (coverage, critical findings, license violations) prior to promotion
Partner with Security and Compliance to implement vulnerability triage workflows, risk exceptions, and remediation SLAs
Ensure approved artifacts/process steps, provenance/attestations, and secure supply-chain practices (e.g., least-privileged credentials, key rotation)
Collaborate with the Enterprise DevOps team to automate release and build processes end-to-end (infrastructure, pipelines, testing, deployments)
Contribute to and adopt enterprise standards (tooling, runners/agents, templates, guardrails, observability)
Drive 'shift-left' automation: automated environment provisioning, config-as-code, test data seeding, and blue/green/canary strategies
Champion infrastructure-as-code (IaC) practices for environment consistency and repeatability (e.g., Terraform/Bicep/ARM/Ansible)
Ensure test strategy coverage per release: unit, integration, API, performance, security, and UAT
Enforce quality gates in pipelines (test pass rates, defect leakage thresholds, performance baselines)
Coordinate test data management and environment readiness; prevent 'test flakiness' via stabilization efforts and quarantines
Ensure IT Testing is attached for each User Story, includes following up proactively throughout the release for testing evidence as stories are sent for PR review
Manage environment (Production is primary, but will also have responsibilities on lower environments), including sequencing, freeze windows, and promotion paths (dev → test → staging → prod)
Oversee configuration and secrets management aligned with enterprise standards
Validate monitoring, logging, and alerting are in place pre-release (dashboards, SLOs/SLIs, runbooks)
Conduct release health checks, smoke tests, and progressive rollouts with automated rollback criteria
Maintain up-to-date runbooks, playbooks, and support handoffs for on-call readiness
Maintain a single source of truth for release notes, change logs, deployment instructions, and rollback plans
Ensure audit-ready records: approvals, evidence, control adherence, and traceability from commit → build → artifact → release
Keep SOPs current; propose improvements based on retrospectives and audit feedback
Track and report DORA/SPACE-aligned metrics: deployment frequency, lead time for changes, change failure rate, MTTR, pipeline success rate
Run data-driven retrospectives and publish improvement backlogs (pipeline stability, test reliability, automation coverage)
Forecast release capacity and throughput; highlight bottlenecks and risks with actionable mitigation plans
In collaboration with the PO, assist in providing clear, concise status updates and release comms (roadmaps, readiness, risks, cutover plans, outcomes)
Align expectations with business stakeholders regarding scope, timing, and risk tolerance
Coach squads on release hygiene, versioning strategies (semver), branching models (GitFlow/Trunk-based), and 'build once, deploy many.'
Qualification
Required
End to end release ownership across applications, ensuring timelines, dependencies, and risks are tightly managed
Hands on CI/CD engineering expertise, including building, maintaining, and troubleshooting pipelines
Strong DevSecOps discipline with integrated security controls and solid change/incident management
Integration planning with other apps
Own the maintenance of end-to-end release calendar, milestones, and scope across applications/services and environments (dev/test/stage/prod)
Facilitate release planning ceremonies: scope reviews, go/no-go, readiness checkpoints, cutover rehearsals, and PIRs (post-implementation reviews)
Coordinate with Modern Sales and Shared Services teams to align release content, dependencies, and windows
Ensure adherence to the Management Model SOPs for change, risk, approvals, and documentation
Own all release-related tickets and workflows in the designated system (e.g., Change Requests, Release Records, CAB submissions, approvals)
Ensure tickets meet SOP criteria: correct metadata, risk ratings, rollback/contingency plans, test evidence, and stakeholder sign-offs
Serve as the first escalation point for release incidents; manage war rooms, communications, and coordinated recovery
Perform root-cause analysis (RCA) and track corrective/preventive actions (CAPA) to closure
Build, operate, and troubleshoot CI/CD pipelines (e.g., YAML pipelines, build agents, artifact/versioning strategy, approvals, gate policies)
Execute release activities hands-on: tagging, packaging, artifact promotion, parameterization, configuration, and deployment orchestrations
Maintain pipeline-as-code standards, templates, and reusable components for consistency and scale
Optimize build/test stages (parallelization, caching, selective test runs) to improve lead time and reliability
Integrate security controls into the pipeline (SAST, SCA, secret scanning, container/image scanning, SBOM generation)
Enforce policy gates for quality and security thresholds (coverage, critical findings, license violations) prior to promotion
Partner with Security and Compliance to implement vulnerability triage workflows, risk exceptions, and remediation SLAs
Ensure approved artifacts/process steps, provenance/attestations, and secure supply-chain practices (e.g., least-privileged credentials, key rotation)
Collaborate with the Enterprise DevOps team to automate release and build processes end-to-end (infrastructure, pipelines, testing, deployments)
Contribute to and adopt enterprise standards (tooling, runners/agents, templates, guardrails, observability)
Drive 'shift-left' automation: automated environment provisioning, config-as-code, test data seeding, and blue/green/canary strategies
Champion infrastructure-as-code (IaC) practices for environment consistency and repeatability (e.g., Terraform/Bicep/ARM/Ansible)
Ensure test strategy coverage per release: unit, integration, API, performance, security, and UAT
Enforce quality gates in pipelines (test pass rates, defect leakage thresholds, performance baselines)
Coordinate test data management and environment readiness; prevent 'test flakiness' via stabilization efforts and quarantines
Ensure IT Testing is attached for each User Story, includes following up proactively throughout the release for testing evidence as stories are sent for PR review
Manage environment (Production is primary, but will also have responsibilities on lower environments), including sequencing, freeze windows, and promotion paths (dev → test → staging → prod)
Oversee configuration and secrets management aligned with enterprise standards
Validate monitoring, logging, and alerting are in place pre-release (dashboards, SLOs/SLIs, runbooks)
Conduct release health checks, smoke tests, and progressive rollouts with automated rollback criteria
Maintain up-to-date runbooks, playbooks, and support handoffs for on-call readiness
Maintain a single source of truth for release notes, change logs, deployment instructions, and rollback plans
Ensure audit-ready records: approvals, evidence, control adherence, and traceability from commit → build → artifact → release
Keep SOPs current; propose improvements based on retrospectives and audit feedback
Track and report DORA/SPACE-aligned metrics: deployment frequency, lead time for changes, change failure rate, MTTR, pipeline success rate
Run data-driven retrospectives and publish improvement backlogs (pipeline stability, test reliability, automation coverage)
Forecast release capacity and throughput; highlight bottlenecks and risks with actionable mitigation plans
In collaboration with the PO, assist in providing clear, concise status updates and release comms (roadmaps, readiness, risks, cutover plans, outcomes)
Align expectations with business stakeholders regarding scope, timing, and risk tolerance
Coach squads on release hygiene, versioning strategies (semver), branching models (GitFlow/Trunk-based), and 'build once, deploy many.'
Experience with: Azure DevOps; Terraform; SonarQube; CheckMARX, PBI, general cloud tooling - more specific to Azure PCP? Chat…
Familiarity with ITIL change management, CAB processes, and regulated environments (SOC2, SOX, PCI, HIPAA as applicable)
Benefits
401k plan where Qualitest will match your contributions accelerating your savings plan.
Enrollment into one of our competitive healthcare benefits.
Qualitest will match towards your HSA if you choose to participate.
QCraft – our Learning & Development platform: 50,000+ courses, 300+ virtual labs, mentorship and leadership programs, professional tribes, sponsored certifications, and much more.
Corporate Wellness Program. We pay your Gym membership and giving you opportunities to Earn additional vacation times for attendance the gym!
Client Referral and Employee Referral Program’s. Refer and earn – tap your network for net-worth.
Qudos platform - You can earn bonuses and spot awards by celebrating your and your peers’ achievements.
Qualitest Employee Perks for discounts on anything from travel to electronics.
Company
Qualitest
Qualitest is the world’s leading managed services provider of AI-led quality engineering solutions.
H1B Sponsorship
Qualitest has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (12)
2024 (36)
Funding
Current Stage
Late StageTotal Funding
unknown2019-07-10Acquired
Recent News
2025-07-14
Company data provided by crunchbase