22 Aug
|
IntraEdge
|
Hyderabad
22 Aug
IntraEdge
Hyderabad
Detailed – Senior DevSecOps Engineer
Role: Senior DevSecOps Engineer
Experience: 6+ Years
Location: Hyderabad
Employment Type: Full-Time
Job Summary
We are seeking an experienced Senior DevSecOps Engineer with strong expertise in DevOps, Cloud Engineering, Site Reliability Engineering (SRE), and Cybersecurity .
The ideal candidate will be responsible for integrating security throughout the software development lifecycle and building secure, automated, and reliable CI/CD pipelines. The role requires hands-on experience with cloud platforms, containers, Infrastructure as Code, security automation, vulnerability management, and DevSecOps tools .
The candidate will work closely with Development, Security, Cloud, Infrastructure, SRE, and Architecture teams to implement shift-left security , automate security controls, improve application reliability, and ensure enterprise compliance.
Key Responsibilities
1. DevSecOps Strategy & Implementation
- Design, implement, and maintain DevSecOps practices across the software development lifecycle.
- Integrate security controls into development, build, testing, deployment, and production processes.
- Promote a shift-left security approach by identifying and addressing vulnerabilities early in the SDLC.
- Establish security gates and automated validation within CI/CD pipelines.
- Collaborate with development and security teams to define secure development standards.
- Continuously evaluate and improve DevSecOps processes, tooling, and automation.
- Support security-by-design principles across cloud-native applications and infrastructure.
1. CI/CD Pipeline Security
- Design, build, and maintain secure CI/CD pipelines using tools such as:
- Jenkins
- GitHub Actions
- GitLab CI/CD
- Azure DevOps
- Integrate automated security testing into CI/CD pipelines.
- Implement security checks for source code, dependencies, containers, infrastructure, and application artifacts.
- Configure automated quality and security gates to prevent vulnerable code from progressing through environments.
- Implement secure artifact management and deployment practices.
- Manage pipeline credentials, secrets, tokens, and service accounts securely.
- Troubleshoot pipeline failures and optimize build and deployment processes.
- Implement automated rollback and recovery mechanisms where required.
1. Cloud Security & Engineering
- Design and implement secure cloud infrastructure across:
- AWS
- Microsoft Azure
- Google Cloud Platform (GCP)
- Implement cloud security controls based on enterprise security standards.
- Apply least-privilege access principles across cloud environments.
- Work with IAM, RBAC, networking, encryption, secrets management, and security monitoring.
- Identify and remediate cloud security misconfigurations.
- Support secure cloud-native application deployments.
- Implement monitoring and security controls across cloud infrastructure.
- Collaborate with cloud architects and security teams to ensure compliance with organizational standards.
1. Container & Kubernetes Security
- Build, secure, and maintain containerized applications using Docker .
- Deploy and manage workloads across:
- Kubernetes
- Helm
- OpenShift
- Implement container security best practices.
- Scan container images for vulnerabilities before deployment.
- Configure secure Kubernetes deployments and access controls.
- Manage Kubernetes secrets, RBAC, network policies, and security configurations.
- Implement secure Helm charts and deployment templates.
- Troubleshoot container and Kubernetes security issues.
- Support vulnerability remediation across containerized workloads.
1. Infrastructure as Code & Automation
- Develop and maintain Infrastructure as Code (IaC) solutions using:
- Terraform
- CloudFormation
- Bicep
- Ansible
- Automate provisioning and configuration of cloud infrastructure.
- Implement security controls directly into infrastructure provisioning processes.
- Perform security validation of infrastructure configurations before deployment.
- Create reusable IaC modules and automation frameworks.
- Ensure infrastructure configurations follow security, compliance, and operational standards.
- Detect and remediate configuration drift and security vulnerabilities.
1. Application & Code Security
- Integrate application security testing into CI/CD pipelines.
- Perform and automate:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Container security scanning
- Infrastructure security scanning
- Work with tools such as:
- SonarQube
- Checkmarx
- Veracode
- OWASP ZAP
- Snyk
- Trivy
- Prisma Cloud
- Analyze security findings and work with development teams to remediate vulnerabilities.
- Establish appropriate vulnerability severity and remediation processes.
- Track security defects and ensure remediation within defined SLAs.
- Promote secure coding practices across engineering teams.
1. Security Automation
- Develop automation scripts and tools to improve security operations.
- Automate vulnerability detection, reporting, remediation, and compliance checks.
- Develop security automation using:
- Python
- Bash
- PowerShell
- Go
- Support automation across CI/CD, cloud infrastructure, containers, and application environments.
- Build reusable automation components that reduce manual security activities.
1. DevOps & SRE Collaboration
- Work closely with DevOps and SRE teams to improve application reliability and operational readiness.
- Implement automated monitoring and alerting.
- Support incident investigation and root cause analysis.
- Improve deployment reliability and recovery capabilities.
- Implement security controls without negatively impacting application availability or delivery speed.
- Participate in production incident response and remediation activities.
- Support disaster recovery and business continuity requirements where applicable.
1. Security Monitoring & Vulnerability Management
- Monitor security findings across applications, infrastructure, containers, and cloud environments.
- Analyze vulnerability reports and prioritize remediation.
- Track security risks and provide remediation recommendations.
- Support security incident investigations related to application and cloud environments.
- Integrate security monitoring and alerting into operational workflows.
- Maintain appropriate security documentation and audit evidence.
1. Governance & Compliance
- Ensure DevOps processes comply with enterprise security standards.
- Implement security controls aligned with organizational policies and regulatory requirements.
- Support internal and external security audits.
- Maintain documentation for security controls, pipeline configurations, and infrastructure.
- Participate in risk assessments and security reviews.
- Ensure security requirements are incorporated into application and infrastructure design.
Required Skills & Qualifications Must-Have
- 6+ years of overall IT/software engineering experience .
- Minimum 3+ years of hands-on experience in DevOps, Cloud Engineering, SRE, Cybersecurity, or DevSecOps .
- Strong experience implementing security controls within CI/CD pipelines .
- Hands-on experience with cloud platforms such as AWS, Azure, or GCP .
- Strong experience with DevOps and CI/CD technologies.
- Strong understanding of containerization and Kubernetes.
- Hands-on experience with Infrastructure as Code.
- Experience implementing application and infrastructure security scanning.
- Strong scripting and automation skills.
- Good understanding of security principles, vulnerability management, and secure software development.
DevOps & CI/CD Hands-on experience with one or more:
- Jenkins
- GitHub Actions
- GitLab CI/CD
- Azure DevOps
- Git
- CI/CD pipeline automation
- Automated security gates
- Build and release automation
Cloud Technologies Experience with one or more:
- AWS
- Microsoft Azure
- Google Cloud Platform
Knowledge of:
- IAM/RBAC
- Cloud networking
- Encryption
- Secrets management
- Cloud security
- Logging and monitoring
- Security posture management
Container Technologies
Strong knowledge of
- Docker
- Kubernetes
- Helm
- OpenShift
- Container image security
- Kubernetes RBAC
- Secrets
- Network policies
Infrastructure as Code
Experience with
- Terraform
- CloudFormation
- Bicep
- Ansible
Security Tools Hands-on experience with several of the following:
- SonarQube
- Checkmarx
- Veracode
- OWASP ZAP
- Snyk
- Trivy
- Prisma Cloud
Experience integrating these tools into CI/CD pipelines is highly desirable. Programming & Scripting
Robust scripting/programming experience in one or more:
- Python
- Bash
- PowerShell
- Go
- Java
- C#
- JavaScript
The candidate should be comfortable writing automation scripts for CI/CD, cloud infrastructure, security scanning, reporting, and operational processes.
Preferred Skills
- Experience with SAST, DAST, SCA, IaC scanning, and container security .
- Knowledge of OWASP security principles.
- Experience with cloud security posture management.
- Knowledge of secrets management tools such as Vault or cloud-native secret stores.
- Experience with API security.
- Knowledge of Kubernetes security best practices.
- Experience with vulnerability management platforms.
- Exposure to SIEM/security monitoring solutions.
- Experience with Agile/Scrum methodologies.
- Experience working in enterprise or regulated environments.
- Security certifications such as Security+, CISSP, CSSLP, or cloud security certifications are a plus.
The candidate will be expected to embed security throughout the development lifecycle: Plan → Code → Build → Test → Secure → Deploy → Monitor → Respond → Improve
This includes automated security testing, vulnerability remediation, secure infrastructure provisioning, container security, cloud security, and continuous compliance.
📌 Senior DevSecOps Engineer (Hyderabad)
🏢 IntraEdge
📍 Hyderabad