25 Sep
|
Katonic.ai
|
India
Company Description Katonic AI provides an operating system for Sovereign AI, giving enterprises, governments, and service providers full control over their AI infrastructure, data, and intellectual property. The platform can be deployed on-premises, in hybrid environments, or on existing cloud infrastructure, enabling secure and versatile AI adoption.
Role Description The SecOps Engineer will work in a full-time, remote capacity to secure, monitor, and maintain Katonic AI’s sovereign AI platforms and supporting infrastructure. This role involves designing and implementing security controls, managing CI/CD pipeline security, and hardening cloud and on-premises environments. The SecOps Engineer will perform continuous security monitoring, log analysis, vulnerability assessment, and incident response, collaborating closely with DevOps, platform engineering, and product teams to embed security into the development lifecycle.
Responsibilities include creating and maintaining security runbooks, automating security checks, ensuring compliance with relevant standards, and supporting secure deployments across global customer environments.
Responsibilities
- Perform the vulnerability lifecycle for platform images and dependencies: scan, prioritise by exploitability, drive fixes or VEX statements, verify closure with re-scans.
- Maintain supply-chain control: SBOM generation, image signing, admission policy, pinned and mirrored third-party images.
- Harden CI/CD: secret scanning, least-privilege workflow permissions, OIDC over long-lived keys.
- Audit secrets and access on Kubernetes: which Secrets reach which pods, RBAC, NetworkPolicy, Vault injection, credential rotation.
- Support identity reviews across Keycloak realms and service tokens in single and multi-tenant deployments.
- Triage security alerts, participate in on-call, contain through the operator and charts (never ad-hoc cluster mutation), write blameless postmortems.
- Produce customer-facing security evidence: per-release SBOMs, scan reports, signing proof, CVE delta and remediation notes.
- Turn recurring findings into automated gates that fail a PR.
Qualifications
- 2+ years in security engineering, DevOps, SRE with hands-on Kubernetes (manifests and Helm, not just deployments).
- Experience with at least two of: Trivy/Grype, Syft/CycloneDX, cosign, Kyverno/OPA, gitleaks/TruffleHog, Dependabot/Snyk.
- Working knowledge of CVSS/EPSS/CISA KEV and risk-based prioritisation.
- GitHub Actions/GitLab CI at the level of reading and fixing a workflow.
- Understanding of OAuth2/OIDC and JWTs; exposure to Keycloak, Entra ID or similar.
- Python or Bash scripting for automation.
- Clear written communication: you write remediation tickets engineers act on, and record how you verified each change.
Nice to have
- Air-gapped or regulated delivery; multi-tenant isolation as a threat model.
- SOC 2 / ISO 27001 / CIS Kubernetes Benchmark / SLSA familiarity.
- CKS or a cloud security certification.
- Go, enough to read a Kubernetes operator.
Apply here: https://skyh.in/GhsO3h
📌 SecOps Engineer (India)
🏢 Katonic.ai
📍 India