HamburgerMenu
hirist

Job Description

Job Summary :


We are seeking a Senior DevSecOps Engineer with deep hands-on expertise in securing CI/CD pipelines, cloud infrastructure, and containerized environments. The ideal candidate will have a strong background in DevOps/CloudOps with a security-first mindset and experience operating in compliance-heavy environments such as Finance, Healthcare, or SaaS.


Key Responsibilities :


DevSecOps Ownership :


- Architect, build, and manage secure CI/CD pipelines across various environments.

- Integrate security tools (SAST, DAST, SCA, secret scanners, vulnerability scanners) into the development lifecycle.

- Define and enforce code promotion, rollback, and release strategies.

Cloud & Infrastructure Security :


- Manage and secure AWS or Azure environments with proper network controls (VPC, NAT, firewalls, route tables).

- Implement security group rules, NACLs, and compliance-based access controls.

- Collaborate with cloud architects to enforce governance and policy compliance.


Toolchain & Automation :


- Drive infrastructure-as-code using Terraform, Ansible, and Helm.

- Own and automate tooling such as Jenkins, Docker, Kubernetes, Git, etc.

- Streamline provisioning and configuration management processes.

Container & Orchestration Security :


- Secure Kubernetes clusters and Docker containers with RBAC, network policies, image scanning (Trivy, AquaSec), and runtime protection.

- Define pod security standards and ensure container hardening practices.

Monitoring, Logging & Incident Response :


- Set up observability stack using ELK, Prometheus, Grafana, CloudWatch, CloudTrail, and Splunk.

- Lead incident response efforts, perform root cause analysis, and implement mitigation strategies.

Collaboration & Governance :


- Work with Development, InfoSec, and IT Ops teams to ensure security is embedded in DevOps culture.

- Ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, etc.).


Required Skills & Technologies :

DevOps/CloudOps :


- Jenkins, Git, Docker, Kubernetes, Helm, Terraform, Ansible

Security :


- SAST, DAST, SCA Tools: SonarQube, Snyk, AquaSec, Trivy

Cloud Networking :


- VPC, NAT Gateways, Firewalls, DNS, Load Balancing, NACL, Route Tables

CI/CD Expertise :


- Pipeline design, code promotion policies, secure rollback strategies

Monitoring & Logging :


- ELK, Prometheus, Grafana, CloudTrail, CloudWatch, Splunk

Scripting :


- Bash, Python, Groovy


Qualifications :


- Degree in Computer Science, Information Systems, or related field; or equivalent work experience

- 3+ years of direct DevSecOps experience (within 7- 10 years total)

- Prior experience in regulated domains like BFSI, Healthcare, or SaaS is highly preferred

- Excellent communication and collaboration skills

The job is for:

May work from home
info-icon

Did you find something suspicious?