19 Aug
|
IntraEdge
|
Hyderabad
19 Aug
IntraEdge
Hyderabad
Detailed – Senior DevSecOps Engineer
Role: Senior DevSecOps Engineer
Experience: 6+ Years
Location: Hyderabad
Employment Type: Full-Time
Job Summary
We are seeking an experienced Senior DevSecOps Engineer with strong expertise in DevOps, Cloud Engineering, Site Reliability Engineering (SRE), and Cybersecurity.
The ideal candidate will be responsible for integrating security throughout the software development lifecycle and building secure, automated, and reliable CI/CD pipelines. The role requires hands-on experience with cloud platforms, containers, Infrastructure as Code, security automation, vulnerability management, and DevSecOps tools.
The candidate will work closely with Development, Security, Cloud, Infrastructure, SRE, and Architecture teams to implement shift-left security, automate security controls, improve application reliability, and ensure enterprise compliance.
Key Responsibilities
- DevSecOps Strategy & Implementation
- Design, implement, and maintain DevSecOps practices across the software development lifecycle.
- Integrate security controls into development, build, testing, deployment, and production processes.
- Promote a shift-left security approach by identifying and addressing vulnerabilities early in the SDLC.
- Establish security gates and automated validation within CI/CD pipelines.
- Collaborate with development and security teams to define secure development standards.
- Continuously evaluate and improve DevSecOps processes, tooling, and automation.
- Support security-by-design principles across cloud-native applications and infrastructure.
2. CI/CD Pipeline Security
- Design, build, and maintain secure CI/CD pipelines using tools such as:
- Jenkins
- GitHub Actions
- GitLab CI/CD
- Azure DevOps
- Integrate automated security testing into CI/CD pipelines.
- Implement security checks for source code, dependencies, containers, infrastructure, and application artifacts.
- Configure automated quality and security gates to prevent vulnerable code from progressing through environments.
- Implement secure artifact management and deployment practices.
- Manage pipeline credentials, secrets, tokens, and service accounts securely.
- Troubleshoot pipeline failures and optimize build and deployment processes.
- Implement automated rollback and recovery mechanisms where required.
3. Cloud Security & Engineering
- Design and implement secure cloud infrastructure across:
- AWS
- Microsoft Azure
- Google Cloud Platform (GCP)
- Implement cloud security controls based on enterprise security standards.
- Apply least-privilege access principles across cloud environments.
- Work with IAM, RBAC, networking, encryption, secrets management, and security monitoring.
- Identify and remediate cloud security misconfigurations.
- Support secure cloud-native application deployments.
- Implement monitoring and security controls across cloud infrastructure.
- Collaborate with cloud architects and security teams to ensure compliance with organizational standards.
4. Container & Kubernetes Security
- Build, secure, and maintain containerized applications using Docker.
- Deploy and manage workloads across:
- Kubernetes
- Helm
- OpenShift
- Implement container security best practices.
- Scan container images for vulnerabilities before deployment.
- Configure secure Kubernetes deployments and access controls.
- Manage Kubernetes secrets, RBAC, network policies, and security configurations.
- Implement secure Helm charts and deployment templates.
- Troubleshoot container and Kubernetes security issues.
- Support vulnerability remediation across containerized workloads.
5. Infrastructure as Code & Automation
- Develop and maintain Infrastructure as Code (IaC) solutions using:
- Terraform
- CloudFormation
- Bicep
- Ansible
- Automate provisioning and configuration of cloud infrastructure.
- Implement security controls directly into infrastructure provisioning processes.
- Perform security validation of infrastructure configurations before deployment.
- Create reusable IaC modules and automation frameworks.
- Ensure infrastructure configurations follow security, compliance, and operational standards.
- Detect and remediate configuration drift and security vulnerabilities.
6. Application & Code Security
- Integrate application security testing into CI/CD pipelines.
- Perform and automate:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Container security scanning
- Infrastructure security scanning
- Work with tools such as:
- SonarQube
- Checkmarx
- Veracode
- OWASP ZAP
- Snyk
- Trivy
- Prisma Cloud
- Analyze security findings and work with development teams to remediate vulnerabilities.
- Establish appropriate vulnerability severity and remediation processes.
- Track security defects and ensure remediation within defined SLAs.
- Promote secure coding practices across engineering teams.
7. Security Automation
- Develop automation scripts and tools to improve security operations.
- Automate vulnerability detection, reporting, remediation, and compliance checks.
- Develop security automation using:
- Python
- Bash
- PowerShell
- Go
- Support automation across CI/CD, cloud infrastructure, containers, and application environments.
- Build reusable automation components that reduce manual security activities.
8. DevOps & SRE Collaboration
- Work closely with DevOps and SRE teams to improve application reliability and operational readiness.
- Implement automated monitoring and alerting.
- Support incident investigation and root cause analysis.
- Improve deployment reliability and recovery capabilities.
- Implement security controls without negatively impacting application availability or delivery speed.
- Participate in production incident response and remediation activities.
- Support disaster recovery and business continuity requirements where applicable.
9. Security Monitoring & Vulnerability Management
- Monitor security findings across applications, infrastructure, containers, and cloud environments.
- Analyze vulnerability reports and prioritize remediation.
- Track security risks and provide remediation recommendations.
- Support security incident investigations related to application and cloud environments.
- Integrate security monitoring and alerting into operational workflows.
- Maintain appropriate security documentation and audit evidence.
10. Governance & Compliance
- Ensure DevOps processes comply with enterprise security standards.
- Implement security controls aligned with organizational policies and regulatory requirements.
- Support internal and external security audits.
- Maintain documentation for security controls, pipeline configurations, and infrastructure.
- Participate in risk assessments and security reviews.
- Ensure security requirements are incorporated into application and infrastructure design.
Required Skills & Qualifications Must-Have
- 6+ years of overall IT/software engineering experience.
- Minimum 3+ years of hands-on experience in DevOps, Cloud Engineering, SRE, Cybersecurity, or DevSecOps.
- Strong experience implementing security controls within CI/CD pipelines.
- Hands-on experience with cloud platforms such as AWS, Azure, or GCP.
- Robust experience with DevOps and CI/CD technologies.
- Strong understanding of containerization and Kubernetes.
- Hands-on experience with Infrastructure as Code.
- Experience implementing application and infrastructure security scanning.
- Solid scripting and automation skills.
- Valuable understanding of security principles, vulnerability management, and secure software development.
DevOps & CI/CD Hands-on experience with one or more:
- Jenkins
- GitHub Actions
- GitLab CI/CD
- Azure DevOps
- Git
- CI/CD pipeline automation
- Automated security gates
- Build and release automation
Cloud Technologies Experience with one or more:
- AWS
- Microsoft Azure
- Google Cloud Platform
Knowledge of:
- IAM/RBAC
- Cloud networking
- Encryption
- Secrets management
- Cloud security
- Logging and monitoring
- Security posture management
Container Technologies
Strong knowledge of
- Docker
- Kubernetes
- Helm
- OpenShift
- Container image security
- Kubernetes RBAC
- Secrets
- Network policies
Infrastructure as Code
Experience with
- Terraform
- CloudFormation
- Bicep
- Ansible
Security Tools Hands-on experience with several of the following:
- SonarQube
- Checkmarx
- Veracode
- OWASP ZAP
- Snyk
- Trivy
- Prisma Cloud
Experience integrating these tools into CI/CD pipelines is highly desirable. Programming & Scripting
Strong scripting/programming experience in one or more:
- Python
- Bash
- PowerShell
- Go
- Java
- C#
- JavaScript
The candidate should be comfortable writing automation scripts for CI/CD, cloud infrastructure, security scanning, reporting, and operational processes.
Preferred Skills
- Experience with SAST, DAST, SCA, IaC scanning, and container security.
- Knowledge of OWASP security principles.
- Experience with cloud security posture management.
- Knowledge of secrets management tools such as Vault or cloud-native secret stores.
- Experience with API security.
- Knowledge of Kubernetes security best practices.
- Experience with vulnerability management platforms.
- Exposure to SIEM/security monitoring solutions.
- Experience with Agile/Scrum methodologies.
- Experience working in enterprise or regulated environments.
- Security certifications such as Security+, CISSP, CSSLP, or cloud security certifications are a plus.
The candidate will be expected to embed security throughout the development lifecycle: Plan → Code → Build → Test → Secure → Deploy → Monitor → Respond → Improve
This includes automated security testing, vulnerability remediation, secure infrastructure provisioning, container security, cloud security, and continuous compliance.
📌 Senior DevSecOps Engineer (Hyderabad)
🏢 IntraEdge
📍 Hyderabad