07 Aug
|
Fusion Business Solutions
|
Udaipur
07 Aug
Fusion Business Solutions
Udaipur
About the Role
This is a hands-on engineering role, not a compliance-checkbox role. You own the security posture of the paths that code takes to production: pipelines, artifacts, secrets, cloud infrastructure, and runtime. Changes reach production in minutes across multiple data centers; a compromised pipeline, a leaked credential, or an over-privileged service account is a company-level event, not a ticket. You embed security into the delivery platform so that the secure path is the quick path engineers ship faster because of your work, not despite it.
You operate at the intersection of SRE, security engineering, and platform engineering. You write code, break builds for good reasons, and are the person incident commanders call when the question is "how did this get into prod, and what else did.
What You'll Do
- Ship a measurable reduction in a vulnerability class e.g., eliminate long-lived cloud keys from CI,
or bring critical-CVE MTTR under SLA with automated remediation and publish the metric.
- Harden one stage of the supply chain end-to-end (e.g., artifact signing + verification at deploy, or registry access scoping) behind flags, with rollback, without breaking the deploy cadence.
- Run a purple-team or attack-path exercise against the delivery platform (poisoned dependency, stolen CI token, malicious MR) and close the gaps it finds.
- Kill at least one recurring source of engineer friction flaky scanner, noisy alert, manual evidence collection — and automate it out of existence.
- Review IaC and pipeline MRs across teams with a bar that catches privilege escalation paths, unscoped tokens, public-by-default resources, and secrets in logs — and teach teams to catch them first.
📌 DevSecOps Engineer SaaS Platform (Udaipur)
🏢 Fusion Business Solutions
📍 Udaipur