HamburgerMenu
hirist

DevSecops Cloud Security Manager

Black & White Business Solutions
8 - 12 Years
Bangalore

Posted on: 27/06/2026

Job Description

Key Responsibilities :

- Design and implement DevSecOps security practices across CI/CD pipelines.

- Perform application security assessments using SAST, DAST, and other security testing tools.

- Integrate automated security scans into the software development lifecycle.

- Ensure compliance with security frameworks, regulatory standards, and organizational policies.

- Identify, assess, and remediate application and cloud security vulnerabilities.

- Collaborate with development, DevOps, and cloud engineering teams to implement secure coding practices.

- Develop and enforce cloud security controls across AWS, Azure, or GCP environments.

- Conduct threat modeling, risk assessments, and security reviews for applications and cloud infrastructure.

- Monitor security posture, investigate incidents, and recommend remediation measures.

- Stay updated with emerging security threats, tools, and DevSecOps best practices.

Required Technical Skills :

- Strong experience in Application Security.

- Hands-on experience with SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) tools.

- Knowledge of cloud security principles and best practices (AWS, Azure, or GCP).

- Experience with DevSecOps practices and CI/CD security integration.

- Strong understanding of security compliance frameworks such as ISO 27001, SOC 2, PCI-DSS, CIS, or NIST.

- Expertise in vulnerability management, threat modeling, and security risk assessment.

- Experience with IAM (Identity and Access Management), secrets management, and security monitoring.

- Knowledge of container security (Docker, Kubernetes) and Infrastructure as Code (Terraform/CloudFormation) is preferred.

- Familiarity with scripting languages such as Python, Bash, or PowerShell is an advantage.

Preferred Skills :

- Cloud Security (AWS Security, Azure Security, or GCP Security)

- DevSecOps & Secure CI/CD Pipelines

- SAST & DAST Tools (Checkmarx, Veracode, Fortify, SonarQube, Burp Suite, OWASP ZAP, etc.)

- Vulnerability Assessment & Penetration Testing (VAPT)

- Security Compliance & Governance

- Secure SDLC

- IAM & Secrets Management

- Container & Kubernetes Security

- Threat Modeling & Risk Assessment

- Excellent analytical, communication, and stakeholder management skills.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...