14 Aug
|
Haleon
|
Bengaluru
About the role
We are seeking a highly skilled and hands on DevSecOps Engineer to support and evolve our enterprise DevSecOps ecosystem. In this role, you will part of governance, engineering, and continuous improvement of our developer platforms, CI/CD pipelines, security tooling, and cloud native infrastructure. You will work closely with Cloud, Security, Platform Engineering, and Product teams to ensure that our engineering workflows remain secure, scalable, and compliant across a global, highly regulated setting.
Key responsibilities
- Administer and optimize GitHub Enterprise Cloud / GitHub Enterprise Server, Azure DevOps, SonarQube, Datadog SAST, and Docker Desktop at enterprise scale.
- Define and enforce organization wide governance, including branch protection, repository standards, permissions, audit logging, SSO/SCIM, and GitHub Action / ADO runner governance (managed vs. self-hosted, isolation, patching).
- Implement and manage GitHub Advanced Security features such as CodeQL, Depend Bot, secret scanning with push protection, and integrate SAST, SCA, DAST, IaC scanning, and artifact signing into pipelines.
- Support evaluation, onboarding, and migration of next gen security tools (e.g., Datadog Code Security) Migration strategies (e.g., SonarQube Datadog POCs).
- Govern security across CI/CD pipelines in GitHub Actions and Azure DevOps, ensuring secure release workflows, multistage approvals, environment protections, and quality gates.
- Support teams in designing and deploying secure applications on Azure, ensuring alignment with cloud security best practices.
- Implement IaC best practices using Terraform Cloud/Native Terraform, including policy checks, workspace governance, remote backends, and drift detection.
- Maintain hardened Docker base images,
enforce secure container usage, and ensure compliance across AKS and ACR environments.
- Build actionable dashboards, alerts, and audit ready evidence pipelines for observability and compliance.
- Provide L3 operational support for DevSecOps platforms, including handling escalations and resolving complex incidents.
- Track and publish DevSecOps adoption, security posture metrics, and platform coverage insights.
- Lead remediation sprints, POCs, platform upgrades, migrations, maintenance activities, and broader architectural improvements.
- Collaborate closely with Cloud, Security, Platform Engineering, and Product teams to address cross functional engineering challenges.
- Drive improvements in developer productivity and experience through self-service infrastructure provisioning, developer portals, and Internal Developer Platform (IDP) capabilities.
- Enable and support standardized development workflows to improve onboarding, consistency, and delivery efficiency across teams.
- Work within Agile delivery models, actively participating in sprint planning, backlog refinement, daily stand-ups, sprint reviews, and retrospectives.
- Support and leverage Azure-native engineering capabilities including AKS, Azure Functions, Azure DevOps, GitHub Actions, Azure Developer CLI (azd), and Terraform (AzureRM).
Qualifications and skills
Essential
- Strong hands-on experience administering GitHub Enterprise, GitHub Advanced Security, Azure DevOps, and enterprise CI/CD pipelines.
- Solid understanding of Azure cloud services, Entra ID (IAM), network security, least privilege principles, and secure workload design.
- Proven expertise in SAST, SCA, secret scanning, vulnerability triage, and governance workflows.
- Experience securing and operating Azure Kubernetes Service (AKS), ACR, and containerized applications.
- Proficiency in Terraform, Terraform Cloud, module development, policy enforcement, and remote backends.
- Strong scripting skills in YAML, Bash, and PowerShell (Python and JavaScript proficiency expected).
- Proficient in coding using Python and JavaScript to support automation, security tooling integration, and developer workflows.
- Strong understanding of coding standards aligned to SDLC best practices, including software compliance and secure coding standards.
- Experience working with SaaS platforms and strong understanding of platform security and integration patterns.
- Good to have exposure to DaaS platforms, particularly MongoDB Atlas.
- Ability to troubleshoot complex CI/CD, pipeline, GitHub/ADO, or container security issues end to end.
- Strong analytical thinking, communication skills, and experience working in global, multi-region, regulated environments.
Preferred
- Microsoft Certified: Azure DevOps Expert, CKAD, or equivalent certifications.
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Senior DevSecOps Engineer (Bengaluru)
🏢 Haleon
📍 Bengaluru