HamburgerMenu
hirist

Job Description

Description :


Job Title : Senior DevSecOps Engineer


Location : Bengaluru, India (onsite/hybrid)


Experience : 7+ years


Responsibilities :


- Embed security into the full software development lifecycle, from design through deployment and operations (the Sec in DevSecOps).


- Define, build and maintain CI/CD pipelines with integrated security controls : SAST, DAST, SCA, secrets scanning, container/IaC checks etc.


- Automate security guardrails for cloud infrastructure and code, utilising serverless architectures and workflow orchestration (e.g., AWS Step Functions)


- Design and implement Infrastructure as Code (IaC) for cloud & hybrid environments, with security baked in (Terraform/CloudFormation/Ansible etc)


- Monitor and maintain threat detection, logging, auditing, and incident response mechanisms for production systems


- Collaborate across development, operations and security teams; perform threat modelling, risk assessments and recommend remediation for vulnerabilities


- Provide leadership/mentoring for more junior engineers and drive continuous improvement of secure delivery practices


Required Skills & Qualifications :


- 7+ years of experience in roles combining development, operations and security (DevSecOps)


- Strong scripting/programming skills (e.g., Python, Bash, Go)


- Hands-on experience with serverless/workflow tools such as AWS Step Functions, AWS Lambda, or equivalent, preferably in production. (e.g., one job showed Hands-on experience with AWS Step Functions and Lambda for event-driven automation across cloud environment).


- Deep experience building and maintaining CI/CD pipelines and embedding security checks into them


- Experience with cloud security (AWS/Azure/GCP), container orchestration (Docker, Kubernetes), and IaC tools


- Knowledge and experience with application and infrastructure security best practices : SAST, DAST, supply chain, secrets management, etc.


- Good understanding of networking, OS, cloud services, monitoring/logging, compliance frameworks


- Excellent verbal and written communication skills, ability to influence teams and drive change


Preferred / Nice to Have :


- Certifications such as AWS Certified Security, CISSP or equivalent


- Experience in regulated industries (financial, healthcare etc)


- Experience with containers in production, admission controllers, runtime security tools


- Experience with hybrid or multi-cloud setups


- Previous mentoring or team-lead experience


info-icon

Did you find something suspicious?