06 Aug
|
Sourcebae
|
India
DevSecOps Engineer
Role: DevSecOps Engineer
Experience: 5–10 Years
Job Type: Fulltime
Location: Bangalore / Remote
Must-have Skills
Python
Linux / Unix / macOS
About the Role
We are looking for a DevOps Engineer with a robust focus on infrastructure and operating system security to harden, monitor, and protect our on-premises environment. You will own the security posture of our servers, virtualization layer, and internal networks — building automated, repeatable hardening and compliance processes rather than one-off fixes. This role sits at the intersection of DevOps automation and security engineering.
Key Responsibilities
Harden Linux (and Windows, where applicable) servers in line with CIS Benchmarks.
Automate hardening and compliance checks using Ansible, OpenSCAP, and Lynis.
Implement and maintain host-level security controls including SSH hardening, sudo/least-privilege policies, SELinux/AppArmor, auditd, host firewalls (nftables/firewalld), and kernel hardening.
Build and operate a vulnerability management program including scheduled scanning (OpenVAS/Nessus), CVE triage, and automated patch management.
Manage configuration as code using Ansible (or Puppet/Salt) with version control and drift detection.
Deploy and manage centralized logging, monitoring, and detection using Wazuh, ELK, Graylog, or similar tools.
Implement file integrity monitoring, privileged activity alerting, and log retention.
Strengthen network security through VLAN segmentation and firewall rule management.
Implement and administer secrets management using HashiCorp Vault or equivalent.
Eliminate hardcoded credentials and enforce secret rotation.
Harden identity infrastructure including Active Directory, FreeIPA, or LDAP with tiered administration, service account hygiene, and MFA.
Secure out-of-band management interfaces such as iDRAC, iLO, and IPMI.
Support compliance and audit activities aligned with CIS, NIST, and ISO 27001 frameworks.
Participate in incident response, investigation, containment, and post-incident hardening.
Required Skills & Qualifications
5+ years of experience in DevOps, Systems Engineering, or Infrastructure with hands-on security responsibilities.
Strong Linux administration experience (RHEL/Ubuntu) with expertise in OS hardening, permissions, PAM, and kernel security.
Experience implementing and auditing CIS Benchmarks using OpenSCAP, Lynis, or similar tools.
Proficiency in Ansible (or Puppet/Salt) for configuration management and automated hardening.
Strong networking fundamentals including TCP/IP, VLANs, Firewalls, TLS/PKI, VPNs, and network segmentation.
Experience with vulnerability scanning and patch management in on-premises environments.
Experience with SIEM and host-based intrusion detection solutions such as Wazuh, ELK, or Graylog.
Proficiency in Bash and Python scripting.
Familiarity with virtualization platforms including VMware vSphere, Proxmox, or Hyper-V and their security models.
Experience with Git and Infrastructure-as-Code practices.
Important Note:
We are not looking for just a DevOps Engineer, but for an On-Prem Infrastructure/DevOps Engineer who is strong in Linux security and hardening, with hands-on Ansible, CIS compliance, vulnerability management, networking and CI/CD.
📌 Security Engineer (India)
🏢 Sourcebae
📍 India