About UsSolutionsInsightsCareersContact Us
Talk to Us
All open roles
Engineering
DevSecOps Engineer
Own the cloud estate, the delivery pipeline and the security posture of the platform across every setting, end to end. You report to the Head of Engineering and you are the only person in the company whose job this is.
Apply now
Location
Greater Noida
- Hybrid
Type Full-time, permanent
Reports to
Head of Engineering
Experience
6+ years
Why this role The infrastructure is a compliance artefact.
01
KMS configuration determines whether we can legally call ourselves data-blind
02
Residency you can evidence — ap-south-1, and only ap-south-1
03
Bring infrastructure and release management in-house from our partner
04
Security gates that can actually block a release The work
What you'll actually do
01
What you'll own
- The AWS estate: ECS Fargate, VPC design, Aurora/RDS, MSK, KMS — in ap-south-1, and only ap-south-1
- Infrastructure as code: Terraform with genuine environment parity, so pre-prod tells the truth about production
- The pipeline: GitLab CI/CD with OIDC federation, security gates that can block a release, and a release process a regulator could read
- Observability: CloudWatch, X-Ray and log aggregation, designed to debug a system whose contents we are not allowed to read
- The security perimeter: WAF and Shield, Secrets Manager, private CA and mTLS between services, GuardDuty and Config with rules that mean something
- Continuity: backups, restore drills you have actually run, DR against a seven-year retention obligation, and a cloud bill you can explain line by line
02
The hard part
- Observability without visibility — most of the standard playbook assumes you can look at the payload. You cannot
- Residency you can evidence: demonstrating data never left India, including in backups, logs, replicas and third-party tooling
- Solo on-call, honestly stated — for the first stretch you are the infrastructure function; we will fund the tooling, protect your time and hire alongside you
03
Minimum qualification
- 6 years running production cloud infrastructure,
or 4 years with an advanced degree — or equivalent practical experience
- 4 years of hands-on Terraform, managing real environments through their whole lifecycle
- 4 years of AWS across compute, networking and data: ECS or equivalent orchestration, VPC design, RDS/Aurora, and IAM you have had to debug
- 3 years of CI/CD ownership including security gating — SAST, DAST, dependency and secret scanning wired into the pipeline
- Working knowledge of applied cryptography in cloud: KMS, envelope encryption, certificate lifecycle, mTLS
- Scripting fluency in Python or Bash
- A real incident and on-call track record, and the writing habit to leave a postmortem behind
04
Preferred
- Data-residency or sovereignty constraints implemented in practice — ap-south-1 only, and able to prove it
- Kafka or MSK operations, not just consumption
- SOC 2 or ISO 27001 evidence-gathering from the infrastructure side, ideally with a compliance automation platform in the loop
- AWS Solutions Architect, DevOps Engineer or Security Specialty certification
- Private CA operation, WAF/Shield tuning, or GuardDuty and Config beyond default rules
05
How we work
- Hybrid working style with anchor at our Grandthum office in Greater Noida, Tech Zone IV
- Defined core collaboration hours — outside that, flex your day around its natural shape
- Architecture decisions get written down and argued in the open. Small, reviewable changes.
Depth is valued over volume
- Company-issued devices and approved tooling for anything touching customer or compliance data. Given what we build, we hold ourselves to the standard we sell
06
The practical details
- Location: Grandthum, Tech Zone IV, Greater Noida West, Gautam Buddha Nagar,
Uttar Pradesh
- Employment type: full-time, permanent
- Reports to: Head of Engineering
- Education: B.E./B.Tech or M.Tech in CS/IT, or equivalent demonstrated experience — we mean the second part
- Offers are subject to standard background verification, which we will explain before we ask for anything
07
How we'll interview you
- A 30-minute conversation with our Head of Engineering
- A code and architecture discussion on something you have built and can talk about honestly
- A conversation with the founder about the company, the regulation and where this goes
- Four stages. We aim to complete them inside two weeks and to give you a decision either way
Ideal candidate
You'll thrive here if this sounds like you
You treat security as design, not as a checklist somebody else wrote
You can shadow a handover, take the Terraform, and then own it
You can prove a claim to someone who assumes you are wrong
You are comfortable being the only person in the company doing this job for a while
You write postmortems and leave systems easier to run than you found them
Apply
Tell us about yourself
Share a few details and your CV. We read every application, typical response within two weeks.
Full name
Email
Phone
LinkedIn URL
Why this role
CV / Resume
Click to upload your CV
PDF, DOC, or DOCX
- up to 10 MB
More open roles Other ways to join the team
Engineering
Backend Engineer II
Engineering
Backend Engineer I
Engineering
AI Engineer
Engineering
Frontend Engineer
Engineering
QA Automation Engineer
Operations
IT Administrator
BUILD THE SYSTEMS
THAT ENABLE PROGRESS.
Partner with ASCENRA to create infrastructure designed for long-term growth.
Share Your Requirements
Powering Structured Growth.
Digital infrastructure for institutions building beyond the cycle.
Address
Unit No 239-240, 2nd Floor, Phase-5, Grandthum, Gautam Buddha Nagar, Uttar Pradesh, India, 201318
Get in touch
[email protected]
+91 6366 321 779
© 2026 ASCENRA. All rights reserved.
Powered by Quantana
📌 DevSecOps Engineer (Karamba)
🏢 Ascenra Technologies
📍 Karamba