What are the responsibilities and job description for the Director, Digital Delivery position at Osmose?
- Purpose of Position
The role will collaborate with product teams, DevOps, project managers, and stakeholders to drive secure, consistent quality through automated testing, continuous improvement in release processes and foster a culture of agility and proactive security. The incumbent will own maturing Company’s secure deployment automation and facilitating retrospectives and mentoring teams in agile and security best practices.
- Position Relationships
- Key Responsibilities
- Design, build, and maintain scalable, secure, and reliable release pipelines for the software development teams, that support continuous integration and continuous delivery (CI/CD) with security embedded at every stage.
- Integrate Secure by Design principles—such as threat modeling, secure defaults, and defense in depth—into all aspects of build and deployment processes.
- Champion the adoption of SecDevOps practices by embedding continuous, automated security into every phase of the development and release lifecycle.
- Lead the evaluation and implementation of SecDevOps tooling, including static and dynamic code analysis, software composition analysis (SCA), artifact management, and secrets detection.
- Develop and enforce best practices for secure source control, branching strategies, build automation, artifact management, and deployment automation.
- Collaborate with DevOps, development, and operations teams to ensure smooth, secure quality assured releases and rapid delivery cycles.
- Establish and monitor release metrics, including security-related metrics, to provide transparency into build stability, deployment frequency, release quality, and security posture.
- Troubleshoot and resolve build, integration, deployment, and security issues quickly and efficiently.
- Maintain up-to-date release documentation, including release notes, rollback procedures, deployment guides, and security controls.
- Champion the evaluation and adoption of new tools and technologies to continually improve both the efficiency and security of the release process.
- Guide teams and individuals in adopting and improving agile practices, such as Scrum, alongside Secure by Design practices and a security-first mindset.
- Facilitate agile ceremonies, including sprint planning, daily stand-ups, reviews, and retrospectives, with an emphasis on incorporating security considerations into planning and review.
- Mentor Scrum Masters, Product Owners, and development teams on agile principles as well as secure development lifecycles (e.g., integrating security stories and tasks into sprints).
- Assess agile and security maturity at the team and organization level, developing tailored coaching plans to address gaps and challenges in both areas.
- Leverage PMP (Project Management Professional) certification to bring a structured, standards-based approach to project execution, risk management, and stakeholder communication, ensuring alignment with organizational goals and industry best practices. Utilize this expertise to drive project timelines, manage cross-functional dependencies, and deliver high-quality, secure releases in alignment with agile and security objectives.
- Promote a culture of continuous improvement, secure collaboration, and effective feedback loops.
- Work with leadership to remove organizational impediments to both agility and security, and to support scaling best practices.
- Ensure transparency, accountability, and high performance across teams, emphasizing shared responsibility for security.
- Serve as a liaison among engineering, product management, operations, security teams, and business stakeholders.
- Communicate release schedules, risks (including security risks), and status updates clearly and proactively.
- Facilitate knowledge sharing and foster a learning environment around both agile and Secure by Design practices.
- Advocate for the voice of the customer and security in release planning and agile transformation initiatives.
- Identify process bottlenecks and inefficiencies in release engineering, agile practices, and security.
- Lead initiatives for process optimization, secure tool adoption, automation opportunities, and security enhancements.
- Stay updated with industry trends, emerging technologies, secure software development practices, and evolving agile methodologies.
- Promote experimentation and measure results, driving data-informed improvements in both agility and security.
- Measures of Performance
- Reduction in release-related incidents, deployment failures, and security vulnerabilities.
- Acceleration of release cycle times and secure delivery of features to end-users.
- Increased agile and security maturity scores across teams.
- Higher team engagement, satisfaction, and security awareness scores.
- Improvement in engineering productivity, quality, and security metrics.
- Personal Qualifications & Experience
- Degree in a relevant field.
- Certifications such as Certified ScrumMaster (CSM), Certified Agile Coach (ICP-ACC), SAFe Program Consultant (SPC).
- Experience coaching at scale across multiple teams or in enterprise environments.
- Background in software engineering, QA, or application security is a plus.
- Demonstrated thought leadership in both agile fields.
- Project Management Professional (PMP) certification is highly desirable, reflecting strong project leadership and the ability to deliver complex initiatives within scope, time, and budget constraints.
- Familiarity with SecDevOps frameworks and tooling (e.g., Snyk, Checkmarx, Veracode, SonarQube, GitHub Advanced Security, HashiCorp Vault, Terraform).
- Personal Trait Profile
- Self-Starter.
- Teamwork and communication skills: Foster a collaborative and supportive work environment.
- Strong verbal and written communications skills.
- Leadership: Inspires confidence and empowers teams to achieve their best work, while championing a culture of security.
- Problem Solving: Approaches challenges analytically and collaboratively, finding innovative and secure solutions.
- Adaptability: Thrives in fast-paced, evolving environments and adapts coaching style to diverse audiences and security challenges.
- Customer service mindset: Demonstrating empathy and providing helpful support to internal users builds trust and satisfaction.
- Organization: Managing multiple tasks, projects, and information efficiently is critical for productivity.
- Stress management: Ability to remain calm and focused under pressure, particularly during critical incidents, is important.
- Ethical: Maintaining data confidentiality, protecting user privacy, and adhering to security protocols are paramount.
- Integrity: Taking responsibility for your actions, being honest, and demonstrating trustworthiness are valued qualities.
- Hands-on, “roll up your sleeves” approach.