devsecops engineering

Designs and implements CI/CD pipelines, toolchain integrations, and automation that embed security controls and testing into software delivery; configures devtools (source control, build systems, artifact registries, scanners, secret managers, policy engines) to enforce security, compliance, and automated remediation. Builds monitoring and feedback loops and analyzes pipeline posture, access controls, and deployment workflows to harden delivery processes and operationalize security practices.

devsecopsengineering

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
2.6
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$179K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines

Jun 06, 2025
SD
Sowmiya Dhandapani
🏛️ Independent Cyber Security Researcher

This paper addresses the insufficient identification and mitigation of software supply chain security risks throughout the CI/CD pipeline lifecycle. We propose a structured threat modeling methodology grounded in the STRIDE framework, applied incrementally across core infrastructure components—including GitHub, Jenkins, Docker, and Kubernetes—to cover all phases from source code management to production deployment. A novel integration of STRIDE with the SLSA maturity model enables quantitative assessment of how specific security controls elevate SLSA compliance levels. By unifying Security as Code principles with the “Shift Left–Shield Right” paradigm, our approach realizes threat-driven, automated security enforcement. The outcomes include a structured threat–control mapping matrix and an actionable CI/CD security hardening roadmap, directly supporting DevSecOps adoption and progressive SLSA compliance advancement.

Analyzing vulnerabilities from source code to deployment with GitHub, Jenkins, Docker, KubernetesEnhancing CI/CD security via NIST, OWASP, and SLSA-based controls and toolchain integrationIdentifying and mitigating risks in CI/CD pipelines using STRIDE threat modeling

DevOps Automation Pipeline Deployment with IaC (Infrastructure as Code)

Nov 15, 2024
AS
Adarsh Saxena
🏛️ University of Allahabad | University of South Wales | Cardiff Metropolitan University

This paper addresses the conceptual ambiguity, ill-defined boundaries, and lack of implementation standards between Infrastructure-as-Code (IaC) and Pipeline-as-Code in DevOps practice. To resolve these issues, we systematically delineate their respective roles and synergistic mechanisms within the DevOps ecosystem and propose a reusable, standardized IaC-driven CI/CD implementation framework. Our approach integrates Terraform for infrastructure provisioning, Ansible for configuration management, GitLab CI for pipeline orchestration, and Docker/Kubernetes for containerized deployment—enabling an end-to-end automated delivery pipeline. Empirical evaluation demonstrates 99.8% configuration change accuracy, reduces environment provisioning time from hours to minutes, and significantly improves deployment consistency and delivery efficiency.

Clarify DevOps implementation in CI/CD pipelinesDemonstrate Infrastructure as Code (IaC) strategyStreamline software development and deployment processes

This work addresses the growing complexity of CI/CD pipelines and the lack of structured analysis capabilities in existing tools for understanding their behavior, failures, and version evolution. The authors propose an innovative approach that uniquely integrates digital twin technology with BPMN-based modeling in DevOps contexts. By automatically parsing raw CI configurations and execution logs, the method constructs structured, high-level process models that enable pipeline visualization, failure traceability, and cross-version comparison. Evaluated across multiple open-source projects, the approach demonstrates effectiveness in monitoring, evolutionary analysis, and fault diagnosis, offering a modular and extensible foundational framework for the analysis and optimization of CI/CD pipelines.

CI/CD pipelinesDevOpsDigital Twin

Empirical Analysis on CI/CD Pipeline Evolution in Machine Learning Projects

Mar 18, 2024
AH
Alaa Houerbi
🏛️ University of Michigan- Dearborn

This study presents the first empirical investigation into the evolution of CI/CD configurations in machine learning (ML) projects. Addressing the lack of understanding regarding how CI/CD configurations co-evolve with ML components, the authors analyze 508 open-source ML projects, 343 manually annotated commits, and 15,634 automated CI/CD commits. They propose a novel 14-category taxonomy capturing synergistic changes between CI/CD and ML components, develop a dedicated clustering tool to identify recurrent evolutionary patterns, and establish an empirically grounded model linking developer experience to CI/CD configuration modification behavior. Results show that 61.8% of CI/CD-related commits involve build strategy modifications; common anti-patterns—including dependency hardcoding and missing test frameworks—are identified; and senior developers modify CI/CD configurations more frequently and effectively than juniors, confirming the critical role of experience in CI/CD maintenance.

Analyzes CI/CD evolution in ML projectsDevelops clustering tool for CI/CD patternsIdentifies common CI/CD configuration changes

On the Need to Monitor Continuous Integration Practices - An Empirical Study

Sep 08, 2024
JS
Jadson Santos
🏛️ Federal University of Rio Grande do Norte | University of Otago | University of Waterloo

Continuous Integration (CI) practices suffer from severe monitoring deficiencies: developers largely neglect critical metrics such as “build health” and “time-to-fix failed builds,” while mainstream CI services offer only weak native monitoring capabilities, forcing reliance on fragmented and often redundant third-party tools. Method: We conducted a triangulated investigation—including documentation analysis, developer surveys, functional audits of CI platforms, and case studies of open-source projects—to systematically identify cognitive gaps and practical monitoring needs. Contribution/Results: Our study provides the first empirical evidence that although over 80% of developers track test coverage, only a minority monitor build health or timeliness; further, all major CI services lack built-in multidimensional monitoring support. These findings establish an evidence-based foundation for designing next-generation CI monitoring frameworks and prioritizing tooling enhancements.

CI services lack native support for monitoring key practices.Developers inadequately monitor Continuous Integration practices.Third-party tools fail to fully address CI monitoring gaps.

Latest Papers

What's happening recently
View more

This study addresses the lack of standardized guidance for effectively integrating technical debt management tools into existing CI/CD practices, which hinders the continuous control of technical debt. By systematically analyzing approximately 600,000 Travis CI configuration files and 50,000 auxiliary scripts from GitHub, the authors identify 3,684 pipelines that integrate technical debt management tools. Their findings reveal that such integrations predominantly rely on external script invocations and frequently exhibit configuration anti-patterns, notably the absence of feedback mechanisms. This work provides empirical evidence of current integration practices and prevalent anti-patterns, offering actionable insights to inform the design of better tooling and improve CI/CD integration strategies for technical debt management.

CI/CDConfiguration Anti-patternsIntegration Practices

This work addresses the challenge developers face in efficiently authoring CI/CD configurations due to limited DevOps expertise by proposing a large language model (LLM)-based, context-aware generation approach. The method leverages both natural language descriptions and repository structure to automatically produce accurate and executable pipeline configurations for platforms such as GitHub Actions and GitLab CI/CD. Integrated with automated validation and human-in-the-loop feedback mechanisms, this framework is the first to combine repository context understanding with natural language-driven configuration synthesis. Experimental results demonstrate that the approach significantly lowers the barrier to DevOps adoption, markedly improves the accuracy and validity of generated configurations, and substantially reduces manual configuration effort.

CI/CD pipeline configurationconfiguration errorsdeveloper productivity

This work addresses the fragility, inefficiency, and strong platform coupling commonly found in CI/CD pipelines for legacy COBOL systems, which often result in high maintenance costs and vendor lock-in. To overcome these challenges, the authors propose a portable CI/CD architecture tailored for highly secure and compliance-driven environments. The approach leverages OCI-compliant container images preloaded with COBOL toolchains, introduces a platform abstraction layer, integrates multiple repositories, and employs Groovy script refactoring to achieve platform-agnostic continuous integration and delivery. Empirical evaluation demonstrates that the proposed solution significantly enhances efficiency—reducing pipeline execution time by 82%—while simultaneously improving system portability, security, and maintainability. This architecture offers a reusable paradigm for modernizing legacy COBOL applications within regulated domains.

CI/CDCOBOLlegacy systems

This work addresses the vulnerability of build system code to poisoning attacks, which pose a critical threat to software supply chain security. While existing tools primarily focus on application source code, they largely overlook the security of the build process itself. To bridge this gap, we propose a novel paradigm—“development-phase isolation”—that, for the first time, incorporates build scripts into the scope of security analysis. By leveraging information flow tracking and behavioral privilege modeling, our approach enables fine-grained monitoring of build-time code execution. We implement this methodology in a prototype tool, Foreman, which effectively detects anomalous and malicious behaviors within build scripts. In real-world evaluations, Foreman successfully identified the poisoned test files used in the recent XZ Utils supply chain attack, demonstrating both the efficacy and practicality of our approach.

build system securityC codedevelopment phase isolation

Hot Scholars

AB

Alessandro Brighente

Assistant Professor (Tenure Track), University of Padova
wireless network securitycyber-physical systems security
SK

Stefan Katzenbeisser

Professor, Chair of Computer Engineering, University of Passau
ProfessorChair of Computer Engineering
MC

Mauro Conti

IEEE Fellow - Prof.@University of Padua - Wallenberg WASP Guest.Prof.@Örebro U.- Affiliate Prof.@UW
SecurityPrivacy