Happiest Minds
Detailed Job Description DevOps Contractor – Scope of Services DoubleVerify | Tech Ops / DevOps 1. Role Overview This contractor role sits within the DoubleVerify Tech Ops / DevOps organization and provides embedded DevOps engineering support across four key technical initiatives. The successful candidate will work directly alongside DV DevOps teams, participating in day-to-day engineering, infrastructure, and security improvement activities. Strong collaboration skills and the ability to engage with cross-functional engineering teams across the organization are essential. 2. In-Scope Services 2.1 Onboarding – DevOps Complete a structured onboarding program to gain full familiarity with DoubleVerify's DevOps toolchain, platform standards, and internal processes. Obtain access to and working knowledge of core systems including GitLab (CI/CD pipelines, project management), JFrog Artifactory (artifact registry), HashiCorp Vault (secrets management), Terraform Cloud (infrastructure state), and GCP (Google Cloud Platform), AWS and Oracle cloud management Review and adhere to DV's internal DevOps standards, including GitLab project conventions, CI/CD pipeline structure (AutoPipeline / GitLab CI), container image policies, and security baseline requirements. Shadow senior DevOps engineers and participate in team stand-ups, sprint ceremonies, and knowledge-transfer sessions to understand active roadmaps and ongoing initiatives. Gain context on DV's Kubernetes infrastructure, cluster environments (staging, production), and deployment tooling (Helm, ArgoCD) used across the platform. Familiarize yourself with DV's internal documentation in Confluence and ticketing practices in Jira to navigate support requests and DevOps backlogs effectively. 2.2 Assist with the Container Base Image and Signing Project Support DV's ongoing Container Golden Image initiative , which standardizes all containerized workloads on Debian 12. Assist development teams in migrating existing Dockerfiles from deprecated. Help identify repositories still using non-compliant or end-of-life base images by reviewing Grafana dashboards and GitLab pipeline scan results; coordinate remediation with repository owners. Support the rollout and enforcement of container image signing integrated into DV's CI/CD pipelines, ensuring containers are cryptographically signed before deployment Assist teams in resolving build failures caused by Wiz IaC policy violations (e.g., by providing guidance on correct base image paths and Dockerfile remediation steps. Contribute to the DV base image weekly rebuild process and help validate that rebuilt images do not introduce regressions for downstream application teams. Document migration steps, common failure patterns, and resolution playbooks in Confluence to accelerate self-service adoption by engineering teams. 2.3 Terraform Cloud Migration Support the migration of Terraform-managed infrastructure workloads from GCS-backed remote state to Terraform Cloud (TFC / HCP Terraform) , following DV's CloudOps-managed migration playbook. Assist teams in updating git lab pipeline configurations, Work with the DevOps Cloud team to create new TFC workspaces using available automation tooling (DV's GitLab Project Manager) and templates, ensuring all repos under the Terraform GitLab group are onboarded correctly. Validate migrated workspaces, and confirming state locking and IAM permissions are correctly configured in GCS or TFC. Support the upgrade and maintenance of Terraform provider versions (currently targeting v1.9.5+, moving toward v1.10+) and assist in testing provider upgrades for GCP workloads across Dev, Staging, and Production environments. Assist teams experiencing Terraform state inconsistencies or drift issues, applying terraform refresh and documenting root causes and resolutions. Ensure all migrated workloads comply with DV OPA (Open Policy Agent) policy validations enforced in CI pipelines, and help teams resolve any policy exceptions through the established exception process. 2.4 Wiz Familiarization and Issue Burn-Down Initiative Develop working knowledge of Wiz , DV's Cloud Native Application Protection Platform (CNAPP), covering key modules: Wiz Code (CI/CD scanning), Wiz Cloud (CSPM, CIEM, DSPM), and Wiz Defend (real-time threat detection). Access Wiz via SP-initiated SSO using assigned Okta group membership (Wiz-Global-Contributor-Okta or equivalent role) and navigate the Wiz Security Graph, Issues, Findings, and Cloud Events views. Participate in the active Wiz issue burn-down initiative , which involves triaging high and critical severity Issues generated by Wiz and working with application teams to remediate underlying Findings (vulnerabilities, misconfigurations, cleartext secrets, end-of-life software). Assist in resolving Jira tickets raised from Wiz detections — including IaC policy violations, publicly exposed containers with initial-access vulnerabilities, hardcoded secrets in GitLab repositories, and end-of-life OS/package findings. Support teams in understanding the distinction between a Wiz Issue (toxic combination of risks) and a Finding (individual risk), and guide them toward the most efficient remediation path (fixing one Finding to resolve the broader Issue). Use Wiz's Cloud Events feature to trace the origin of configuration changes in GCP and assist incident response investigations as needed. Coordinate with DV's DevSecOps and InfoSec teams (via Slack channel) on escalations, Wiz scan failures in pipelines, and any security exceptions requiring InfoSec review. Contribute to tracking burn-down progress through Jira and shared Google Sheets trackers maintained by the DevOps and InfoSec teams. 2.5 Working and Engaging with Other DoubleVerify Team Members Collaborate actively with DevOps, DevSecOps, CloudOps, and application engineering teams across DV's global offices (US, EU, APAC), primarily through Slack, Jira, Confluence, and GitLab. Participate in DevOps sprint cycles, daily stand-ups, and engineering sync meetings as required. Respond to support requests raised in support group and dedicated team Slack channels in a timely manner, following DV's established tagging rules and thread etiquette. Proactively share knowledge and document work in Confluence, ensuring completed tasks are accessible and reusable by other team members. Engage respectfully and professionally with engineers at all levels and across all departments, building trust through consistent delivery and clear communication. 4. Required Skills & Knowledge Hands-on experience with Docker, container image management, and Dockerfile authoring Working knowledge of Terraform (v1.12+), GitLab CI/CD pipelines, and remote state management Familiarity with GCP 25+ services (GKE, GCS, IAM, Cloud Armor) and Kubernetes fundamentals, Managing AWS and OCI cloud deployments Understanding of cloud security concepts: vulnerability management, CSPM, secrets management Ability to read and interpret CI/CD pipeline logs, identify failures, and drive resolution Strong written and verbal communication skills; experience working in distributed, global engineering teams Familiarity with Jira and Confluence for task tracking and documentation 5. Preferred Experience Experience in Cloud platforms like AWS, GCP and OCI with Terraform Cloud / HCP Terraform workspace management Knowledge of container image signing (Cosign / Notary) and software supply chain security concepts Prior exposure to Wiz or equivalent CNAPP/CSPM platforms (Prisma Cloud, Orca, etc.) Familiarity with Debian-based Linux environments and package management Experience working in managed services or outsourced DevOps / TechOps delivery models