29 Aug
|
Orcapod Consulting Services
|
Hyderabad
29 Aug
Orcapod Consulting Services
Hyderabad
Location: Hyderabad
Description:
DevSecOps Engineer Role Summary: We are looking for a dedicated and enthusiastic DevSecOps Engineer to embed security automation across pipelines using Azure DevOps, GitHub Enterprise, and Microsoft-native tools. This role enforces secure application onboarding, integrates automated vulnerability scanning, and embeds security throughout the SDLC. The DevSecOps Engineer collaborates closely with architecture, engineering, development, operations, and security teams to integrate security into the SDLC, enhance application and infrastructure protections, and reduce delivery risk through continuous validation, governance, and ongoing improvement of the organizations overall security posture. The ideal candidate brings solid technical depth in automation, platform security, and secure development practices, and can translate security requirements into practical solutions that support engineering velocity.
Key Responsibilities
• Implement, operate, and continuously enforce security controls across CI/CD pipelines, cloud platforms, and application environments in alignment with defined architectural standards, including execution of security gates and validation of control effectiveness • Configure, deploy, and maintain secure baseline templates, pipeline patterns, and reusable automation standards for repositories, workflows, and delivery processes based on established security frameworks • Integrate, configure, and run security tooling within the SDLC, including code scanning, dependency analysis, secrets detection, artifact validation, and vulnerability management workflows, ensuring alignment with approved toolchain designs • Implement and administer identity and access controls using Entra ID, RBAC, and platform configurations across pipelines, repositories, and security tooling, including execution of access provisioning, modification,
and revocation in response to defined access models and requests • Automate and execute onboarding processes and security workflows, including issue creation, tracking, and integration with enterprise systems (e.g., ServiceNow), in accordance with prescribed process designs • Troubleshoot, triage, and resolve CI/CD, identity, and security tool integration issues, including pipeline failures and control enforcement gaps, escalating systemic or design-related issues as appropriate • Monitor, track, and produce operational reporting on security control coverage, pipeline health, vulnerability remediation, and overall effectiveness using established metrics and reporting frameworks • Execute audit, attestation, and compliance support activities, including data collection, reporting, and evidence generation to meet control and regulatory requirements • Investigate security events and actively support incident response activities across development and pipeline environments in coordination with security and architecture teams • Develop, update, and maintain operational documentation, SOPs, and implementation guidance aligned with DevSecOps and SDLC practices • Identify, implement, and operationalize improvements to automation, tooling, and processes to enhance efficiency, consistency, and security posture in alignment with evolving architectural direction Required Skills and Expertise • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field,
or 10 years of equivalent hands on professional experience.
- Strong understanding of DevSecOps principles and secure software development lifecycle (SDLC) practices • Hands-on experience securing CI/CD pipelines and integrating security controls into build and release processes • Proficiency in programming and scripting languages (e.g., Python, Java, or shell scripting) for automation and integration • Experience implementing and managing security tools such as SAST, Knowledge of application security practices, including secure coding and vulnerability identification • Experience with cloud platforms and cloud security controls • Understanding of infrastructure as code (IaC) and automation tools (e.g., Terraform, Ansible) • Knowledge of identity and access management (IAM), authentication, authorization, and least-privilege principles • Experience with containerization and orchestration technologies (e.g., Docker, Kubernetes) • Understanding of networking fundamentals and secure system design concepts • Experience with vulnerability management, remediation workflows, and risk mitigation • Strong troubleshooting, analytical, and problem-solving skills in distributed and pipeline environments • Experience with logging, monitoring, and security event analysis across application and infrastructure layers Preferred Qualifications • Certified DevSecOps Engineer (ECDE) • DevSecOps Certifications such as: GCSA, CDP, DevSecOps Foundation / Manager • Microsoft Achieved Certifications such as: AZ-400, AZ-500, AZ-104, AZ-204, SC-900 • Cloud and Identity Security Certifications such as: CCSP • Application Security Certifications such as: CSSLP, GWAPT, CEH • GitHub Certifications such as: GitHub Advanced Security, GitHub Actions, GitHub Administration, GitHub FoundationsDev
📌 DevSecOps Engineer (Contract-To-Hire) (Hyderabad)
🏢 Orcapod Consulting Services
📍 Hyderabad