23 Sep
|
Good Co India
|
India
23 Sep
Good Co India
India
Role & responsibilities
- Lead and manage the organization's DevSecOps strategy, practices, and engineering teams.
- Define and implement secure, scalable, and automated CI/CD pipelines across development, testing, and production environments.
- Integrate security controls throughout the Software Development Life Cycle (SDLC) and establish a strong security-by-design culture.
- Implement and manage SAST, DAST, SCA, container security, secrets management, vulnerability scanning, and security testing solutions.
- Partner with Development, Engineering, Cloud, Infrastructure, Cybersecurity, QA, and Product teams to embed security into application delivery.
- Design and maintain secure cloud-native infrastructure across AWS, Azure, or Google Cloud.
- Establish security standards and controls for Kubernetes, Docker, containers, APIs, microservices, and Infrastructure as Code.
- Drive Infrastructure as Code and automation using tools such as Terraform, Ansible, Helm, and related technologies.
- Establish and monitor DevSecOps KPIs, security metrics, vulnerability SLAs, deployment metrics, and compliance objectives.
- Identify and remediate security vulnerabilities across source code, dependencies, containers, infrastructure, and cloud environments.
- Lead threat modeling, security assessments, risk analysis, and secure architecture reviews for applications and platforms.
- Establish and enforce secure coding, branching, release, secrets-management, and deployment standards.
- Automate security checks and compliance controls within CI/CD pipelines to reduce manual intervention and accelerate secure delivery.
- Work with security and compliance teams to ensure alignment with OWASP, NIST, ISO 27001, SOC 2, and other applicable standards.
- Manage DevSecOps tools, technology vendors, licenses, budgets, and third-party security solutions.
- Support incident response and collaborate with security teams during security incidents, vulnerabilities, and production risks.
- Continuously evaluate emerging cloud security, application security, DevOps, automation, and AI-driven security technologies.
- Recruit, mentor, and develop DevSecOps engineers and security-focused technical professionals.
- Present security posture, risks, improvements, and transformation progress to senior technology and security leadership.
Preferred candidate profile
- 5 to 10 years of experience in DevOps, DevSecOps, Cloud Security, Application Security, Cybersecurity, or a related technology function.
- Proven experience leading DevSecOps teams, security transformation initiatives, and enterprise-scale CI/CD implementations.
- Robust hands-on experience with CI/CD platforms, cloud infrastructure, containers, Kubernetes, Infrastructure as Code, and automation.
- Strong understanding of secure SDLC, DevOps practices, application security, cloud security, and security-by-design principles.
- Experience with AWS, Microsoft Azure, or Google Cloud Platform, including cloud-native security controls.
- Strong knowledge of Docker, Kubernetes, Terraform, Helm, Jenkins, GitLab CI/CD,
GitHub Actions, or Azure DevOps.
- Hands-on experience with security tools covering SAST, DAST, SCA, container security, vulnerability management, secrets management, and code quality.
- Familiarity with tools such as SonarQube, Snyk, Checkmarx, Veracode, Fortify, Trivy, Aqua Security, Prisma Cloud, HashiCorp Vault, or equivalent platforms.
- Strong knowledge of OWASP Top 10, threat modeling, vulnerability management, API security, identity and access management, and cloud security frameworks.
- Experience implementing security automation and policy-as-code within CI/CD and cloud environments.
- Strong understanding of Linux, Git, Python/Bash/PowerShell, networking, APIs, microservices, and distributed systems.
- Experience establishing security governance aligned with NIST, ISO 27001, SOC 2, CIS Controls, or similar frameworks.
- Proven ability to manage security risks, vulnerabilities, compliance requirements, technology vendors, budgets, and operational priorities.
- Strong team leadership, stakeholder management, communication, problem-solving, and strategic-thinking skills.
- Ability to collaborate effectively with engineering, product, security, infrastructure, QA, compliance, and senior leadership teams.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, Computer Engineering, or a related field.
- Relevant certifications such as CISSP, CISM, CEH, Security+, AWS/Azure/GCP Security, Kubernetes, or DevOps certifications are desirable.
- Experience in large enterprises, MNCs, GCCs, SaaS, fintech, cloud-native, or highly regulated environments is an advantage.
📌 DevSecOps Manager (India)
🏢 Good Co India
📍 India