30 Sep
|
Acesoft Labs
|
Bengaluru
30 Sep
Acesoft Labs
Bengaluru
Description:
DevOps / Cloud / Security Engineer
Summary about the Role
We are looking for a hands-on DevOps / Cloud / Security Engineer to own our CI/CD pipelines, deployment/release processes, and security tooling on our Azure AKS platform. Platform and cluster maintenance are owned by a separate team; this role is not responsible for platform setup or ongoing cluster administration.
This role sits at the intersection of DevOps, DevSecOps, and release engineering , you'll design and maintain the CI/CD pipelines our engineering teams ship through, execute and support deployments end-to-end, and own the security scanning, vulnerability management, and secrets management processes that keep our systems safe.
What You'll Do
CI/CD & Deployment
- Design, build, and maintain CI/CD pipelines, primarily in GitHub Actions (reusable workflows, matrix builds, self-hosted runner management, OIDC-based authentication).
- Maintain and gradually migrate legacy Jenkins pipelines strong Jenkins knowledge is required
- Support release and deployment processes, including rollout strategies and rollback procedures.
- Own GitOps workflows with ArgoCD: Application CRDs, sync policies, health checks, automated rollback.
Deployment & Troubleshooting (Azure AKS)
- Execute and support application deployments to Azure AKS;this role owns the deployment/release execution, not platform or cluster maintenance (that sits with a separate platform team).
- Be the first line of troubleshooting for deployment and post-deployment issues: failed rollouts, pods not starting, misconfigured services, or a URL/endpoint becoming inaccessible after a release diagnosing root cause (application, ingress, DNS, certificates, config, secrets) and either resolving it or escalating to the right owner.
- Author and maintain Helm charts as our primary IaC tool for deployments (chart authoring, templating, upgrade strategies, helm test, dependency management).
- Use Terraform for Azure infrastructure provisioning tasks tied to deployments, beyond Helm/AKS (secondary tool in the current stack, but required knowledge).
- Work within existing Kubernetes NetworkPolicies and RBAC configurations to deploy and debug applications safely.
- Support autoscaling behavior (KEDA / HPA) for deployed workloads, including scaling based on Kafka lag or custom metrics.
Monitoring & Observability
- Own our Datadog implementation: Agent configuration (including socket mode), reading APM traces, Java library injection, building dashboards and monitors, log pipelines, maintaining the Service Catalog, and configuring Watchdog alerts.
- Understand and be able to articulate why Prometheus endpoints were disabled in favor of Datadog, including the trade-offs of that decision.
- Support the strategic move toward OpenTelemetry (OTEL) as a vendor-agnostic observability standard.
Security & Compliance
- Own the security toolchain and remediation process end-to-end: SonarQube Snyk Lacework Datadog ASM, including managing findings against defined SLAs (Critical: 24h / High: 1 week).
- Administer SonarQube: quality gates, fail-the-build policies, project setup, branch analysis, reporting.
- Run Snyk for container, IaC (Helm/YAML), and dependency scanning in CI/CD; prioritize findings and leverage the Snyk bot for automated fix PRs.
- Use Lacework for CSPM, runtime anomaly detection, and CIS Benchmark compliance reporting, translating findings into actionable Jira tickets.
- Perform threat modeling and manage vulnerability management processes across the stack.
- Integrate OWASP Dependency Check and OWASP ZAP (DAST) as GitHub Actions in CI/CD.
- Implement runtime security with Falco as a complement to Lacework.
- Generate and manage SBOMs (Syft / CycloneDX) and contribute to SLSA supply chain security practices.
Secrets Management
- Manage secrets using Sealed Secrets / kubeseal and External Secrets (rotation, namespace scoping, recovery strategy).
- Manage CI/CD pipeline secrets effectively including lifecycle handling. Should be knowledgeable on CI/CD secrets management from cloud providers
FinOps
- Monitor and optimize AKS cost: right-sizing, resource quotas, spot-node strategy.
AI Experience
- Explore AI-assisted operations tooling (e.g., GitHub Copilot for IaC, Datadog AI Insights / anomaly detection).
What You Bring
- Solid production experience deploying to and operating within Kubernetes / AKS (Azure) ; comfortable diagnosing and resolving deployment and post-deployment issues. (Cluster/platform setup and maintenance are owned by a separate team and are not part of this role.)
- Strong troubleshooting instincts: able to trace a "service/URL not accessible" issue through the stack ingress, DNS, certificates, service/pod health, config, and secrets and resolve or escalate appropriately.
- Strong hands-on skills with Docker and JFrog Artifactory.
- Proven experience building and maintaining CI/CD pipelines in GitHub Actions; solid working knowledge of Jenkins (our current legacy platform, being phased out).
- Strong hands-on experience with Helm as a primary IaC tool; working knowledge of Terraform.
- Strong hands-on experience with ArgoCD and GitOps workflows.
- Experience with Datadog (or comparable APM/monitoring platforms) for monitoring, alerting, and log management.
- Familiarity with Azure DevOps is a plus, though it is not the primary tooling in our current production stack.
- Robust security background: pipeline security scanning, vulnerability management, threat modeling, and remediation processes.
- Experience with SonarQube, Snyk (or similar SCA/container/IaC scanning tools), and cloud security posture management tools (e.g., Lacework).
- Experience with Kubernetes secrets management (Sealed Secrets, External Secrets, Azure Key Vault integration).
- Solid scripting skills (e.g., Bash, Python, or similar).
- Understanding of Kubernetes NetworkPolicies and RBAC.
- Ability to work independently in a fast-moving environment, balancing operational stability with ongoing modernization efforts.
Nice to Have
- Experience with OpenTelemetry (OTEL) migrations.
- Exposure to DAST tooling (e.g., OWASP ZAP) integrated into CI/CD.
- Experience with SBOM generation (Syft/CycloneDX) and SLSA supply chain security frameworks.
- Experience with Backstage.io or other internal developer portal platforms.
- FinOps experience, particularly around Kubernetes/AKS cost optimization.
- Experience with KEDA/HPA autoscaling based on custom or event-driven metrics.
- Experience with Falco or other Kubernetes runtime security tools.
- Interest or experience in applying AI-assisted tooling to DevOps/IaC workflows.
📌 DevOps / Cloud / Security Engineer (Bengaluru)
🏢 Acesoft Labs
📍 Bengaluru