09 Sep
|
Tata Consultancy Services
|
Hyderabad
09 Sep
Tata Consultancy Services
Hyderabad
Job Title: AWS DevSecOps Engineer | GitHub Actions | GHAS | EKS | Terraform
Location : Pan India
Experience : 10+ Years
Job Summary
We are seeking a highly skilled AWS DevSecOps Engineer with strong expertise in GitHub Actions, GitHub Advanced Security (GHAS), AWS, Kubernetes (EKS), and Infrastructure as Code . The ideal candidate will be responsible for designing and managing secure CI/CD platforms, implementing GitHub Enterprise governance, integrating security controls into development workflows, and enabling scalable cloud-native deployments across multiple environments.
Key Responsibilities
- Design, implement, and maintain GitHub Actions workflows across development, staging, and production environments.
- Build, manage, and optimize self-hosted Actions Runner Controller (ARC) runners on Kubernetes (EKS).
- Implement runner auto-scaling, pod identity, workload isolation, and network security policies.
- Integrate GitHub Advanced Security (GHAS) capabilities, including:
- Secret Scanning
- Push Protection
- CodeQL Scanning
- Dependency Review
- Migrate legacy CI/CD pipelines from Jenkins, TeamCity, AWS CodePipeline, and CodeBuild to GitHub Actions.
- Enforce GitHub governance controls, including branch protection rules, required status checks, deployment approvals, and setting gates.
- Develop reusable GitHub Actions, composite actions, and reusable workflow templates for enterprise-wide adoption.
- Collaborate with Security and Engineering teams to implement SAST, DAST, SCA, and secrets management practices throughout the software delivery lifecycle.
- Manage GitHub Enterprise Cloud (GHEC) or Enterprise Managed Users (EMU) environments.
- Configure user provisioning, access control, SCIM integrations, and Okta-based identity management.
- Monitor CI/CD platforms using Splunk, CloudWatch, Datadog, and logging solutions.
- Support Infrastructure-as-Code deployments using Terraform, CloudFormation, and AWS CDK.
- Drive DevSecOps best practices, automation, compliance, and platform reliability.
Required Skills & Qualifications
Technical Skills
- 10+ years of experience in DevOps, DevSecOps, or Platform Engineering.
- Strong hands-on experience with GitHub Actions and GitHub Enterprise.
- Experience implementing GitHub Advanced Security (GHAS).
- Strong AWS cloud experience.
- Hands-on experience with Kubernetes and Amazon EKS.
- Experience managing self-hosted runners and ARC (Actions Runner Controller).
- Expertise in CI/CD pipeline design and automation.
- Strong understanding of application security concepts including:
- SAST
- DAST
- SCA
- Secrets Management
- Experience with Infrastructure as Code:
- Terraform
- CloudFormation
- AWS CDK
- Experience with monitoring and observability tools such as Splunk, Datadog, and CloudWatch.
- Strong scripting skills using Bash, Python, or PowerShell.
- Experience with GitOps and modern deployment practices.
Preferred Skills
- Experience migrating enterprise CI/CD platforms to GitHub Actions.
- Knowledge of Zero Trust and DevSecOps frameworks.
- Exposure to container security platforms and cloud security tools.
- Experience in regulated or compliance-driven environments.
Education
- Bachelor's Degree in Computer Science, Information Technology, Engineering, or a related field.
Certifications (Preferred)
- AWS Certified DevOps Engineer – Professional
- AWS Certified Solutions Architect
- Certified Kubernetes Administrator (CKA)
- GitHub Actions Certification
- GitHub Advanced Security Certification
- HashiCorp Terraform Certification
📌 AWS DevSecOps Engineer (Hyderabad)
🏢 Tata Consultancy Services
📍 Hyderabad