DevOps / Cloud / Security Engineer (Bengaluru)

DevOps / Cloud / Security Engineer (Bengaluru)

30 Sep
|
Acesoft Labs
|
Bengaluru

30 Sep

Acesoft Labs

Bengaluru

Description:

DevOps / Cloud / Security Engineer

Summary about the Role

We are looking for a hands-on DevOps / Cloud / Security Engineer to own our CI/CD pipelines, deployment/release processes, and security tooling on our Azure AKS platform. Platform and cluster maintenance are owned by a separate team; this role is not responsible for platform setup or ongoing cluster administration.

This role sits at the intersection of DevOps, DevSecOps, and release engineering , you'll design and maintain the CI/CD pipelines our engineering teams ship through, execute and support deployments end-to-end, and own the security scanning, vulnerability management, and secrets management processes that keep our systems safe.

What You'll Do

CI/CD & Deployment

- Design, build, and maintain CI/CD pipelines, primarily in GitHub Actions (reusable workflows, matrix builds, self-hosted runner management, OIDC-based authentication).
- Maintain and gradually migrate legacy Jenkins pipelines strong Jenkins knowledge is required
- Support release and deployment processes, including rollout strategies and rollback procedures.
- Own GitOps workflows with ArgoCD: Application CRDs, sync policies, health checks, automated rollback.

Deployment & Troubleshooting (Azure AKS)

- Execute and support application deployments to Azure AKS;this role owns the deployment/release execution, not platform or cluster maintenance (that sits with a separate platform team).
- Be the first line of troubleshooting for deployment and post-deployment issues: failed rollouts, pods not starting, misconfigured services, or a URL/endpoint becoming inaccessible after a release diagnosing root cause (application, ingress, DNS, certificates, config, secrets) and either resolving it or escalating to the right owner.
- Author and maintain Helm charts as our primary IaC tool for deployments (chart authoring, templating, upgrade strategies, helm test, dependency management).
- Use Terraform for Azure infrastructure provisioning tasks tied to deployments, beyond Helm/AKS (secondary tool in the current stack, but required knowledge).
- Work within existing Kubernetes NetworkPolicies and RBAC configurations to deploy and debug applications safely.
- Support autoscaling behavior (KEDA / HPA) for deployed workloads, including scaling based on Kafka lag or custom metrics.

Monitoring & Observability





- Own our Datadog implementation: Agent configuration (including socket mode), reading APM traces, Java library injection, building dashboards and monitors, log pipelines, maintaining the Service Catalog, and configuring Watchdog alerts.
- Understand and be able to articulate why Prometheus endpoints were disabled in favor of Datadog, including the trade-offs of that decision.
- Support the strategic move toward OpenTelemetry (OTEL) as a vendor-agnostic observability standard.

Security & Compliance

- Own the security toolchain and remediation process end-to-end: SonarQube Snyk Lacework Datadog ASM, including managing findings against defined SLAs (Critical: 24h / High: 1 week).
- Administer SonarQube: quality gates, fail-the-build policies, project setup, branch analysis, reporting.
- Run Snyk for container, IaC (Helm/YAML), and dependency scanning in CI/CD; prioritize findings and leverage the Snyk bot for automated fix PRs.
- Use Lacework for CSPM, runtime anomaly detection, and CIS Benchmark compliance reporting, translating findings into actionable Jira tickets.
- Perform threat modeling and manage vulnerability management processes across the stack.
- Integrate OWASP Dependency Check and OWASP ZAP (DAST) as GitHub Actions in CI/CD.
- Implement runtime security with Falco as a complement to Lacework.
- Generate and manage SBOMs (Syft / CycloneDX) and contribute to SLSA supply chain security practices.

Secrets Management

- Manage secrets using Sealed Secrets / kubeseal and External Secrets (rotation, namespace scoping, recovery strategy).
- Manage CI/CD pipeline secrets effectively including lifecycle handling. Should be knowledgeable on CI/CD secrets management from cloud providers

FinOps

- Monitor and optimize AKS cost: right-sizing, resource quotas, spot-node strategy.

AI Experience

- Explore AI-assisted operations tooling (e.g., GitHub Copilot for IaC, Datadog AI Insights / anomaly detection).

What You Bring





- Solid production experience deploying to and operating within Kubernetes / AKS (Azure) ; comfortable diagnosing and resolving deployment and post-deployment issues. (Cluster/platform setup and maintenance are owned by a separate team and are not part of this role.)
- Strong troubleshooting instincts: able to trace a "service/URL not accessible" issue through the stack ingress, DNS, certificates, service/pod health, config, and secrets and resolve or escalate appropriately.
- Strong hands-on skills with Docker and JFrog Artifactory.
- Proven experience building and maintaining CI/CD pipelines in GitHub Actions; solid working knowledge of Jenkins (our current legacy platform, being phased out).
- Strong hands-on experience with Helm as a primary IaC tool; working knowledge of Terraform.
- Strong hands-on experience with ArgoCD and GitOps workflows.
- Experience with Datadog (or comparable APM/monitoring platforms) for monitoring, alerting, and log management.
- Familiarity with Azure DevOps is a plus, though it is not the primary tooling in our current production stack.
- Robust security background: pipeline security scanning, vulnerability management, threat modeling, and remediation processes.
- Experience with SonarQube, Snyk (or similar SCA/container/IaC scanning tools), and cloud security posture management tools (e.g., Lacework).
- Experience with Kubernetes secrets management (Sealed Secrets, External Secrets, Azure Key Vault integration).
- Solid scripting skills (e.g., Bash, Python, or similar).
- Understanding of Kubernetes NetworkPolicies and RBAC.
- Ability to work independently in a fast-moving environment, balancing operational stability with ongoing modernization efforts.

Nice to Have

- Experience with OpenTelemetry (OTEL) migrations.
- Exposure to DAST tooling (e.g., OWASP ZAP) integrated into CI/CD.
- Experience with SBOM generation (Syft/CycloneDX) and SLSA supply chain security frameworks.
- Experience with Backstage.io or other internal developer portal platforms.
- FinOps experience, particularly around Kubernetes/AKS cost optimization.
- Experience with KEDA/HPA autoscaling based on custom or event-driven metrics.
- Experience with Falco or other Kubernetes runtime security tools.
- Interest or experience in applying AI-assisted tooling to DevOps/IaC workflows.

📌 DevOps / Cloud / Security Engineer (Bengaluru)
🏢 Acesoft Labs
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: devops / cloud / security engineer (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: devops / cloud / security engineer (bengaluru) / bengaluru