11 Aug
|
Meta Infotech
|
Mumbai
11 Aug
Meta Infotech
Mumbai
Role Summary
Client is looking for a DevSecOps Engineer to lead the operational management of our TruffleHog platform. You will be the primary guardian against "secret leakage," ensuring that sensitive credentials such as API keys, private keys, and hardcoded passwords are detected and remediated across our global development pipeline. You will manage the infrastructure, tune the scanning engines, and partner with development teams to ensure secure software delivery.
Key Responsibilities
1. TruffleHog Platform & Infrastructure Management
- Uptime & Health: Monitor the TruffleHog platform uptime; conduct regular infrastructure health checks and manage scheduled maintenance with proactive stakeholder communication.
- Global Upgrades: Plan and execute scanner version upgrades across all global regions to ensure the latest detection patterns are active.
- Troubleshooting: Resolve network connectivity issues and basic infrastructure bottlenecks to minimize scan failures and ensure 24/7 service availability.
- Resilience: Maintain the scanner infrastructure in strict alignment with Client's Disaster Recovery (DR) and Business Continuity Planning (BCP) policies.
2. Secret Discovery & Risk Management
- Secret Inventory: Conduct automated and manual discovery scans to establish and maintain a centralized Secret Risk Register and inventory.
- Policy Alignment: Partner with CTO-GPSE stakeholders to define secret discovery rules and remediation guidelines that align with enterprise security standards.
- Integration: Support Client's developers during the deployment and configuration of TruffleHog components into their CI/CD pipelines and data source integrations.
3. Incident Response & Event Management
- Triage: Analyze generated alerts to distinguish between true positives and false positives.
- Remediation Management:
Manage the remediation lifecycle based on defined SLAs, validating that "secrets" are properly rotated or revoked rather than just hidden.
- User Support: Act as the technical point of contact for end-user queries, providing clear technical guidelines on how to remediate leaked credentials securely.
4. Operational Excellence
- Documentation: Create and maintain high-quality Standard Operating Procedures (SOPs) and technical "how-to" guides for the developer community.
- Continuous Improvement: Provide ongoing tuning of the platform to reduce noise and improve the accuracy of detection engines.
- Training: Facilitate operational handovers and training sessions for internal teams to promote a "shift-left" security culture.
Required Technical Skills & Qualifications
- Specialized Tooling: Deep hands-on experience with TruffleHog (Enterprise or Open Source). Familiarity with other secret scanning tools (e.g., GitGuardian, Gitleaks) is a plus.
- DevSecOps Pipeline: Experience integrating security tools into Git (GitHub/GitLab/Bitbucket) and CI/CD pipelines (Jenkins, GitLab CI, or GitHub Actions).
- Infrastructure: Proficiency in Linux administration and containerization (Docker/Kubernetes).
- Development Knowledge: Ability to read code and understand how API keys, tokens, and certificates are used in modern application development.
- Communication: Robust ability to provide technical guidance to developers while escalating risks to senior stakeholders when SLAs are breached.
Key Performance Indicators (KPIs)
- Scan Coverage: Percentage of global code repositories onboarded to TruffleHog.
- MTTR (Mean Time to Remediate): Speed at which high-risk secrets are invalidated or rotated after detection.
- False Positive Rate: Continuous reduction of alert noise through effective pattern tuning.
📌 DevSecOps Engineer (Secrets Management & TruffleHog Specialist) (Mumbai)
🏢 Meta Infotech
📍 Mumbai