HamburgerMenu
hirist

Innovatily - Security Platform/DevSecOps Engineer - Container & Cloud Security

Innovatily
5 - 8 Years
Anywhere in India/Multiple Locations

Posted on: 31/08/2026

Job Description

Security Platform / DevSecOps Engineer Container & Cloud Security

Role Summary:

We are seeking a hands-on Security Platform / DevSecOps Engineer to help advance security engineering initiatives across hardened container images, CI/CD security enablement, vulnerability reduction, cloud security tooling, and compliance-supporting automation. This role will work closely with Security, DevOps, SRE, Engineering, and vendor teams to operationalize secure-by-default platform capabilities and reduce execution risk across active security programs.

Why This Role Is Needed:

Security is supporting multiple concurrent priorities, including SOC2, GovRAMP, cloud security, vulnerability management, PSIRT design and implementation, CNAPP strategy, CI/CD security initiatives, Secrets-to-Vault migration, customer security reviews, security intake, and Belden integration activities.

Key Responsibilities:

- Own and drive hardened base image evaluation and rollout activities, including POC planning, technical validation, and migration support for engineering teams.

- Analyze existing Dockerfiles and container build workflows, then adapt them to hardened or minimal image models, including multi-stage builds, shell-less images, non-root runtime patterns, package dependencies, and custom module handling.

- Partner with engineering teams to onboard representative services and validate hardened images against real application requirements such as NGINX, Go/protoc builds, Java runtime images, Ubuntu-derived workloads, and package-specific constraints.

- Support container registry integration patterns, including GCP Artifact Registry mirroring, pull-through cache models, self-hosted registries, scheduled synchronization, and related tooling such as Skopeo.

- Help integrate security tooling into CI/CD workflows to improve vulnerability visibility, image hygiene, SBOM adoption, signing/verification practices, and continuous remediation.

- Coordinate with vendors and internal stakeholders during POCs, technical troubleshooting, architecture reviews, pricing/licensing inputs, support escalations, and rollout planning.

- Contribute to vulnerability management and CNAPP-related initiatives by supporting cloud security tooling, including Wiz-related workflows and integration considerations.

- Collaborate with Compliance/GRC stakeholders to ensure engineering controls and integrations can support SOC2, GovRAMP, Vanta evidence collection, and audit-readiness needs.

- Document technical patterns, migration guidance, implementation decisions, known limitations, and support procedures for engineering adoption.

- Provide practical technical support across global teams, with the ability to collaborate effectively with APAC/India-based engineering resources.

Required Qualifications:

- Strong hands-on experience with Docker, container image construction, multi-stage builds, Linux package management, and runtime hardening.

- Practical experience with Kubernetes or containerized production environments.

- Experience with CI/CD pipelines and secure software delivery workflows.

- Working knowledge of container vulnerability scanning, image patching, SBOMs, image signing, and supply-chain security concepts.

- Familiarity with cloud environments, especially GCP and GCP Artifact Registry.

- Ability to troubleshoot build-time and runtime container issues, including missing shells, package dependencies, module paths, non-root execution, and registry access.

- Strong scripting or automation skills in Bash, Python, Go-adjacent build tooling, or similar.

- Ability to work across Security, DevOps, SRE, Engineering, Compliance, and external vendor teams.

- Strong written communication skills for documenting migration patterns, technical findings, and rollout guidance.

Preferred Qualifications:

- Experience with hardened, minimal, or distro-less container images.

- Experience with Minimus, Chainguard, Wolfi, Alpine, Ubuntu, or equivalent secure image ecosystems.

- Familiarity with Wiz, Orca, Vanta, Grype, Trivy, Snyk, or similar CNAPP / vulnerability management / compliance tools.

- Experience supporting SOC2, GovRAMP, CRA, NIS2, or similar security/compliance initiatives from an engineering-control perspective.

- Experience integrating security tooling into developer workflows without creating unnecessary engineering friction.

- Experience working with globally distributed teams, especially across North America and APAC time zones.

Success Measures:

- Hardened base image POC progresses from evaluation into documented implementation patterns and repeatable onboarding guidance.

- Engineering teams can migrate representative services to approved hardened image patterns with fewer blockers and clearer support paths.

- CI/CD security and base image scanning workflows become more repeatable, better documented, and less dependent on a single individual.

- Security gains additional execution capacity for CNAPP transition work, Secrets-to-Vault, base image/CI-CD security scanning, and vulnerability remediation coordination.

- Compliance and audit activities benefit from more reliable technical evidence, better tooling integration, and clearer ownership of security engineering controls.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...