Negotiable
Inside
Hybrid
Hybrid-remote in Sheffield, South Yorkshire
Summary: The DevOps Engineer role at Whitehall Resources involves hybrid working, requiring three days onsite in Sheffield and the remainder remote, for an initial four-month contract. The position focuses on enhancing Jenkins Shared Library and delivering secure, efficient CI/CD pipelines. Candidates must possess extensive experience in engineering and DevSecOps, particularly with Jenkins and Python automation. The role also includes mentoring and optimizing performance across various tools and technologies.
Key Responsibilities:
- Own and evolve Jenkins Shared Library for multi-language builds.
- Deliver secure, provenance-rich pipelines and strengthen supply chain integrity.
- Design and maintain Groovy pipeline steps (build, test, package, scan, deploy).
- Extend Python tooling for SLSA provenance and security scan aggregation.
- Optimize performance through parallel builds and caching.
- Ensure artifact integrity and refactor legacy scripts.
- Document ci-config.yaml standards and mentor engineers on secure pipeline practices.
Key Skills:
- 7+ years engineering experience; 3+ years in CI/CD platform or DevSecOps.
- Strong expertise in Jenkins and Groovy shared libraries.
- Advanced Python automation skills.
- Deep knowledge of Maven/NPM/Python packaging; exposure to Helm/Terraform.
- Experience with supply-chain security and scanning tools.
- Proven performance tuning capabilities.
Salary (Rate): undetermined
City: Sheffield
Country: United Kingdom
Working Arrangements: hybrid
IR35 Status: inside IR35
Seniority Level: undetermined
Industry: IT
DevOps Engineer
Whitehall Resources are looking for a DevOps Engineer. This role is hybrid working with 3 days per week onsite in Sheffield, and the remainder remote working for an initial 4 month contract.
***Inside IR35***
Job Description:
– Own and evolve our Jenkins Shared Library powering multi-language builds (Java/Maven, Node/NPM, Python, Helm, Terraform, containers).
– Deliver fast, secure, provenance-rich pipelines (SLSA, SBOM, digests) and strengthen supply chain integrity across teams.
Core Responsibilities:
– Design and maintain Groovy pipeline steps (build, test, package, scan, deploy)
– Extend Python tooling for SLSA provenance, SBOM generation, hash/digest accuracy, and security scan aggregation (SonarQube, Sonatype IQ, SAST/Container).
– Optimize performance (parallel builds, caching, scope-reduced BOMs, dependency prefetch).
– Ensure artifact integrity (correct SHA1/SHA256 mapping, reproducible inputs, evidence modelling).
– Refactor legacy scripts (remove global state, consolidate hashing, standardize templates).
– Document ci-config. yaml standards and usage patterns.
– Mentor engineers on secure pipeline development and supply-chain practices. Troubleshoot and prevent pipeline incidents.
Essential Skills:
– 7+ years engineering; 3+ in CI/CD platform or DevSecOps.
– Strong Jenkins + Groovy shared library expertise.
– Advanced Python automation (JSON/YAML processing, tooling scripts).
– Deep Maven/NPM/Python packaging knowledge; exposure to Helm/Terraform and container image metadata.
– Supply-chain security (SLSA, CycloneDX SBOM, digests).
– Experience with SonarQube, Sonatype IQ, container and SAST scanning.
– Proven performance tuning (caching, parallelization, dependency pruning). Compliance Awareness.
Nice-to-Have:
– Artifact signing / attestations (cosign, OCI).
– Terraform module and Helm chart publishing patterns.
– GitOps or release automation experience.
– GCP/AWS cloud experience
All of our opportunities require that applicants are eligible to work in the specified country/location, unless otherwise stated in the job description.
Whitehall Resources are an equal opportunities employer who value a diverse and inclusive working environment. All qualified applicants will receive consideration for employment without regard to race, religion, gender identity or expression, sexual orientation, national origin, pregnancy, disability, age, veteran status, or other characteristics.
