Role Overview
Key Responsibilities
- Design and maintain a modular, role-based Ansible project structure (collections, roles, playbooks) aligned to banking ITSM standards (ITIL v4).
- Build and enforce Ansible best practices: idempotency, error handling, vault secrets management, and tag-based execution strategies.
- Develop reusable Ansible Collections for internal consumption and publish to a private Automation Hub / Galaxy.
- Integrate Ansible with AWX / Ansible Automation Platform (AAP) 2.x for workflow orchestration, RBAC, and audit trail.
- Architect end-to-end CI/CD pipelines for playbook testing (Molecule, ansible-lint, YAML lint) via GitLab CI / Jenkins
- Automate VM lifecycle: provisioning, cloning, snapshot management, decommissioning via community. vmware collection.
- Integrate with vRealize Orchestrator and NSX-T for network-aware VM provisioning.
- Health checks: datastore capacity, VM sprawl detection, HA/DRS cluster status, vCenter certificate expiry
- Automate cluster provisioning, VM creation, disk/network attachment via nutanix.ncp collection
- Automate OCI resource provisioning: Compute instances, VCNs, subnets, Block Volumes, OCI Vault secrets via oracle.oci collection
- Implement cost governance: tag enforcement playbooks, idle resource detection, and scheduled shutdown/startup.
- Automate AIX system provisioning via NIM (Network Installation Manager) integrated with Ansible
- Manage LPAR lifecycle, VIOS virtual adapter configuration, and WPARs using ibm.power_aix collection.
- Automate configuration management for multi-vendor network devices (Cisco IOS/NX-OS, Juniper JunOS, Arista EOS, F5 BIG-IP) using platform-specific Ansible collections.
- Implement network compliance playbooks: enforce baseline configs, detect drift, and remediate via NAPALM / netconf / RESTCONF.
- Design and operate bank-wide OS patching automation for Linux (RHEL, SLES, Ubuntu), Windows Server, AIX, and OCI instances
- Integrate patching workflows with ServiceNow: auto-open CRQs, update CMDB, close with compliance evidence.
- Develop and schedule comprehensive health-check playbooks for all platforms (daily/weekly/ondemand).
- Build capacity reporting automation: CPU/memory/storage trending, forecast alerts.
Required Skills and Experience
- Experience with Ansible Core, including AAP 2.x/AWX, Ansible Navigator, Ansible Lint, Molecule, RBAC, Execution Environments, Ansible Collections, and Ansible Vault.
- Hands-on experience with VMware technologies, including vSphere 7/8, vCenter, ESXi, NSX-T, vSAN, vROps, and SDDC Manager.
- Strong knowledge of CI/CD and DevOps tools, including GitLab CI, Jenkins, Git, Jinja2, YAML, Python 3.x, Bash scripting, REST APIs, and JSON/YAML parsing.
- Experience with ITSM and monitoring platforms, including ServiceNow (CMDB, CRQ, Incident Management), Splunk, ELK Stack, Grafana, Prometheus, and Dynatrace.
- Knowledge of security and compliance standards, including CIS Benchmarks, STIG, PCI-DSS, SWIFT CSP, HashiCorp Vault, CyberArk AAM, and Qualys/Tenable APIs.
- Strong understanding of automation, infrastructure management, and enterprise DevOps best practices.
- Excellent troubleshooting, scripting, and problem-solving skills in enterprise environments.
Required Certifications
- Red Hat Certified Specialist in Advanced Automation (EX374) certification is mandatory.
- Red Hat Certified Engineer (RHCE, EX294 Ansible) certification is mandatory.
- Ansible Automation Platform (AAP) Implementation certification is recommended.
- Red Hat Certified Architect (RHCA) certification is recommended.
-
Expected Deliverables
- Ansible playbooks, roles, and automation workflows.
- VMware infrastructure automation and configuration.
- CI/CD pipeline integration and automation.
- REST API, Python, and Bash automation solutions.
- ServiceNow integration and incident automation.
- Automation monitoring, troubleshooting, and operational support.
- Technical documentation, runbooks, and knowledge transfer.