Engagement summary
Hands-on senior individual contributor role. Contract engineer to design, build, and operate the cryptographic and infrastructure foundation for McAfee. The role centers on three specific technology pockets: AWS CloudHSM, Terraform / Terragrunt, and JFrog Artifactory.
What you'll own
- AWS CloudHSM - cluster design, deployment, key ceremony, rotation, HA operations, and integration with downstream auth and signing services.
- Terraform + Terragrunt - multi-environment module structure across Dev, QA, Stage, Prod; Policy-as-Code (OPA / Sentinel) in CI.
- JFrog Artifactory - signed container images, Helm charts, SBOM generation, scanning gates, GitOps-integrated promotion policies.
- EKS platform operations - Helm charts, CRDs, service mesh, ingress / egress controls, Zero Trust principles.
- Delegation-chain observability - audit trails answering *who acted on whose behalf, with what scope, when.*
Required
- 7+ years in DevSecOps, Platform Engineering, or SRE with a security focus.
- Hands-on production experience with AWS CloudHSM. *(highly desirable)*
- Advanced Terraform + Terragrunt - DRY module composition, remote-state governance, multi-setting.
- JFrog Artifactory - enterprise artifact governance, signed builds, CI/CD integration.
- Strong AWS expertise (VPC, IAM, KMS, EKS, Route 53, security services).
- Production Kubernetes / EKS, Helm, CRDs.
- Zero Trust principles; service mesh (Istio / Envoy / Linkerd / App Mesh).
- Deep cloud networking - DNS, firewalls, routing.
- GitOps + CI/CD pipeline expertise.
Preferred
- Cryptographic delegation flows - OAuth 2.0 token exchange, workload identity federation.
- Familiarity with agentic security patterns (scoped-capability tokens).
- Policy-as-Code (OPA / Sentinel).
- AWS Professional / Specialty certs; Kubernetes certs (CKA, CKAD, CKS).
📌 Devsecops Engineer (Bengaluru)
🏢 LTM
📍 Bengaluru