UK remote
DevOps Engineer - Build Pipeline Engineer
About this role
Anticipated Contract End Date/Length: November 30, 2026 Work Set Up: Hybrid (3 days per week in office) Our client in the Information Technology and Services industry is looking for a DevOps Engineer / Build Pipeline Engineer to own and evolve a Jenkins Shared Library powering multi-language builds across Java/Maven, Node/NPM, Python, Helm, Terraform, and container technologies. The successful candidate will deliver fast, secure, provenance-rich pipelines using SLSA, SBOMs, and artifact digests while strengthening software supply chain integrity across engineering teams.
What you will do: Design and maintain Groovy pipeline steps covering build, test, package, scan, and deployment activities. Extend Python tooling for SLSA provenance, SBOM generation, hash and digest accuracy, and security scan aggregation. Integrate and maintain security scanning capabilities across SonarQube, Sonatype IQ, SAST, and container scanning. Optimise pipeline performance through parallel builds, caching, dependency prefetching, and scope-reduced BOMs.
Ensure artifact integrity through accurate SHA1/SHA256 mapping, reproducible inputs, and evidence modelling. Refactor legacy scripts by removing global state, consolidating hashing, and standardising pipeline templates. Document ci-config.yaml standards, configuration requirements, and usage patterns. Mentor engineers on secure pipeline development and software supply chain practices. Troubleshoot pipeline incidents and implement improvements to prevent recurring issues.
Assess the current shared library structure and understand supported building blocks and modules. Investigate user-reported issues to develop a strong understanding of critical pipeline components and configuration options. Identify and classify pipeline bugs and develop appropriate hot fixes. Deliver at least two small pipeline features or improvements during the initial 30-day period. Apply secure and compliant CI/CD practices across engineering environments.
Bring 7+ years of software engineering experience, including at least 3 years working with CI/CD platforms or DevSecOps. Demonstrate strong Jenkins and Groovy Shared Library expertise. Demonstrate advanced Python automation skills, including JSON/YAML processing and tooling development. Bring deep knowledge of Maven, NPM, and Python packaging, with exposure to Helm, Terraform, and container image metadata. Demonstrate strong understanding of software supply chain security practices, including SLSA, CycloneDX SBOMs, and artifact digests.