Position: Senior DevSecOps Engineer
Experience: 8+ Years
Location: Open
Work Mode: Hybrid / Onsite / Remote (as per company requirements)
Overview:
We are seeking an experienced Senior DevSecOps Engineer with strong expertise in DevOps (70%) and Security (30%) practices. The ideal candidate will have hands-on experience with AWS, Kubernetes, CI/CD automation, and implementing DevSecOps best practices across the software delivery lifecycle. Experience in security tools like SonarQube is essential.
Key Responsibilities:
DevOps (Primary – 70%)
- Design, develop, and optimize CI/CD pipelines using tools like Jenkins, GitLab CI, GitHub Actions, Azure DevOps, etc.
- Manage and automate infrastructure using AWS services (EC2, S3, IAM, VPC, Lambda, CloudWatch, RDS, EKS).
- Deploy, maintain, and scale applications on Kubernetes (EKS, AKS, GKE or self-managed clusters).
- Implement and manage Infrastructure as Code (IaC) using Terraform, CloudFormation, or Ansible.
- Monitor system performance, optimize resources, and ensure high availability & scalability.
- Support development teams with environment automation, deployment best practices, and troubleshooting.
DevSecOps / Security (30%)
- Integrate security controls into CI/CD pipelines (SAST, SCA, DAST, secrets scanning, compliance checks).
- Use and configure tools such as SonarQube, OWASP Dependency Check, Trivy, HashiCorp Vault, etc.
- Conduct vulnerability assessments and ensure timely remediation with development teams.
- Implement security best practices for cloud platforms (AWS) and containerized environments.
- Ensure compliance with security frameworks (ISO27001, SOC2, CIS Benchmarks, etc.).
- Manage identity and access controls, security groups, and encryption standards.
Required Skills & Experience:
- 8+ years of experience in DevOps, Cloud Engineering, or DevSecOps roles.
- Strong hands-on expertise in AWS cloud services.
- Proven experience working with Kubernetes clusters (EKS preferred).
- Strong proficiency in CI/CD pipeline automation.
- Experience integrating security tools such as SonarQube, Snyk, Fortify, Checkmarx, or similar.
- Strong knowledge of Linux, Docker, Git, and scripting (Bash, Python, or Shell).
- Experience with IaC using Terraform or CloudFormation.
- Knowledge of container security, secrets management, network security, and cloud security.
- Understanding of microservices architecture and secure SDLC.