Build & Deployment Manager – JFrog Artifactory – 11870CF
Proactive Appointments
In this Build & Deployment Manager role, you take ownership of secure software delivery and supply‑chain controls within a regulated financial services environment. You will build, secure, and automate enterprise DevSecOps capabilities across JFrog Artifactory, Xray, GitHub Enterprise, and CI/CD tooling, partnering with engineering and security teams. You will design auditable pipelines, manage vulnerabilities end‑to‑end, and drive improvements in secure delivery. This is a hands‑on, scale‑oriented engineering position with meaningful impact on risk and delivery quality.
Responsibilities- Administer JFrog Artifactory and Xray including repos, permissions, promotion, build information, retention, and scanning
- Design, implement and support secure CI/CD pipelines across multiple tech stacks
- Manage GitHub Enterprise repositories, branching, PRs, permissions, releases, and security/build tooling integration
- Embed security controls (SAST, SCA, dependency and artefact scanning, secrets detection, SBOM generation, policy gates)
- Oversee vulnerabilities lifecycle from discovery to remediation with evidence-based closure
- Integrate vulnerability and asset information with ServiceNow for remediation tracking
- Automate processes using PowerShell, Bash, Python, REST APIs and configuration-as-code
- Support build/deploy tools (TeamCity, Octopus Deploy, GitHub Actions, Azure DevOps)
- Troubleshoot complex issues across SCM, pipelines, dependencies, build agents, security tooling and targets
- Produce technical designs, reusable pipeline standards, SOPs and audit artifacts
- Work within change, incident, problem, release and vulnerability-management processes
- Operate in a complex or regulated environment with a DevSecOps/platform engineering focus
- Strong hands-on experience with JFrog Artifactory and Xray
- Proven ability to design and support secure CI/CD pipelines
- Strong knowledge of GitHub Enterprise and modern source-control practices
- Understanding of artefact repositories, package managers, dependency management and SBOMs
- Practical knowledge of secure coding, OWASP and remediation approaches
- Experience managing vulnerabilities lifecycle
- Experience integrating security tooling with ServiceNow (Vulnerability/Application Vulnerability Response)
- Strong scripting and automation skills; REST APIs; configuration-as-code
- Working knowledge of Windows and Linux build agents; credentials, certificates, TLS, secrets management, logging, access controls
- Ability to investigate and resolve complex issues across the software delivery lifecycle
- Knowledge of JFrog Advanced Security/Curation, GitHub Advanced Security, CodeQL, Dependabot, Terraform, Docker, Kubernetes, SBOMs, software signing/attestation or cloud-native platforms (advantageous)
- Knowledge of Java, .NET, JavaScript/TypeScript, Python or Go is useful but not required
- collaboration with cross-functional teams
- problem solving
- attention to detail
- JFrog Artifactory
- Xray
- GitHub Enterprise
Reference: WJ-747_30991574