Engagement summary
Hands-on senior individual contributor role. Contract engineer to design, build, and operate the cryptographic and infrastructure foundation for McAfee. The role centers on three specific technology pockets: AWS CloudHSM, Terraform / Terragrunt, and JFrog Artifactory.
What you'll own
AWS CloudHSM - cluster design, deployment, key ceremony, rotation, HA operations, and integration with downstream auth and signing services.
Terraform + Terragrunt - multi-environment module structure across Dev, QA, Stage, Prod; Policy-as-Code (OPA / Sentinel) in CI.
JFrog Artifactory - signed container images, Helm charts, SBOM generation, scanning gates, GitOps-integrated promotion policies.
EKS platform operations - Helm charts, CRDs, service mesh, ingress / egress controls, Zero Trust principles.
Delegation-chain observability - audit trails answering who acted on whose behalf, with what scope, when.
Required
7+ years in DevSecOps, Platform Engineering, or SRE with a security focus.
Hands-on production experience with AWS CloudHSM. (highly desirable)
Advanced Terraform + Terragrunt - DRY module composition, remote-state governance, multi-setting.
JFrog Artifactory - enterprise artifact governance, signed builds, CI/CD integration.
Robust AWS expertise (VPC, IAM, KMS, EKS, Route 53, security services).
Production Kubernetes / EKS, Helm, CRDs.
Zero Trust principles; service mesh (Istio / Envoy / Linkerd / App Mesh).
Deep cloud networking - DNS, firewalls, routing.
GitOps + CI/CD pipeline expertise.
Preferred
Cryptographic delegation flows - OAuth 2.0 token exchange, workload identity federation.
Familiarity with agentic security patterns (scoped-capability tokens).
Policy-as-Code (OPA / Sentinel).
AWS Skilled / Specialty certs; Kubernetes certs (CKA, CKAD, CKS).
📌 Devsecops Engineer Bengaluru
🏢 LTM
📍 Bengaluru