Cloud and DevSecOps Engineer (Gota)

Cloud and DevSecOps Engineer (Gota)

30 Sep
|
Drones TechLabs
|
Gota

30 Sep

Drones TechLabs

Gota

The Role: Cloud & DevSecOps Engineer

Day to day, that means designing and running our infrastructure across Google Cloud Platform and AWS, owning our GitLab CI/CD pipelines, and implementing the security controls that protect PHI and financial data.

This role has a deliberate growth path. You will start as the hands-on engineer who builds and secures the platform. Over your first year, you will work alongside the team lead and an external compliance specialist. During that time you will take on increasing ownership of our HIPAA program and SOC 2 Type II attestation, moving from implementing controls to designing and leading them. The goal is that you become our security and compliance lead. We will fund necessary training to get you there.

If you want your infrastructure and security decisions to actually matter, and you want a path from senior engineer to program owner, this is that role.

What You'll Do

Cloud Architecture: GCP and AWS

- Design, deploy, and operate our SaaS infrastructure across GCP and AWS using HIPAA-aligned reference architectures.
- Make sure every workload touching PHI runs only on HIPAA-eligible services. Business Associate Agreements must be signed for each cloud account and project before any PHI lands.
- Implement network segmentation and VPC design, encryption at rest and in transit, KMS key management, and least-privilege IAM across both clouds.
- Build everything as infrastructure-as-code with Terraform. Environments should be reproducible, reviewable, and auditable.

DevOps and GitLab CI/CD

- Own and improve our GitLab CI/CD pipelines end to end: build, test, scan, deploy.
- Integrate security scanning into the pipeline (SAST, dependency and SCA scanning, container and IaC scanning) without turning delivery into a crawl.
- Manage secrets, artifacts, and release processes securely. Keep PHI out of logs, caches, and lower environments.




- Support the development team. Good pipelines make other engineers faster, not slower.

Security Engineering

- Implement and maintain technical safeguards: phishing-resistant MFA, centralized audit logging, monitoring and alerting, vulnerability management, and incident response.
- Enforce bastion or VDI-only production access with no local download of PHI, backed by DLP and egress controls.
- Keep production access minimal and regularly reviewed. Use de-identified or synthetic data in development and test environments.
- Respond to security events and lead post-incident reviews.

Compliance: HIPAA, SOC 2 Type II, Plaid Starting out, you implement and evidence. Over time, you design and lead.

- Implement the technical controls behind our HIPAA Security Rule safeguards and SOC 2 Trust Services Criteria, then take ownership of the program as you grow into the role.
- Operate our compliance automation platform (Vanta, Drata, or Secureframe): keep evidence collection running, monitor for control drift, close gaps.
- Own the security side of our Plaid integration. That means TLS 1.2+ and mTLS where required, encrypted secrets, least-privilege access to financial data, and monitoring for unauthorized access. You will also support Plaid's production access review and security questionnaire. Handling consumer financial data carries GLBA and FTC Safeguards Rule obligations, and you will help us meet them.
- Support penetration tests and audits: help scope them, coordinate with the testers and auditor,



and drive remediation.
- Over time, you will lead the HIPAA risk analysis, own control design, select and manage the external auditor, and carry us through the SOC 2 Type II observation period.

What You Need

- 3+ years in cloud engineering, DevOps, or DevSecOps.
- Hands-on production experience on both GCP and AWS. Not one cloud plus a certification in the other: real production work in both.
- Strong GitLab CI/CD experience, or equivalent CI/CD depth and the ability to move to GitLab quickly.
- Terraform and containerization (Docker, Kubernetes).
- Practical security engineering: IAM and least privilege, encryption, secrets management, network security, logging and monitoring.
- Working exposure to HIPAA or SOC 2 in practice. You should be able to explain what a control is and how you'd evidence it.
- The judgment to handle PHI responsibly and work inside strict access controls.
- Explicit written and spoken English. You will document data flows, controls, and decisions that auditors and customers read.

Nice to Have

- Prior work at a healthcare, fintech, or other regulated SaaS company handling sensitive data.
- Hands-on experience with a compliance automation platform (Vanta, Drata, Secureframe, Sprinto).
- Experience integrating a financial data provider such as Plaid, and awareness of GLBA / FTC Safeguards Rule obligations.
- Any of these certifications: AWS Solutions Architect Professional, AWS Security Specialty, Google Professional Cloud Architect, Google Professional Cloud Security Engineer, CISSP, CCSP, CISM, HITRUST CCSFP.
- Experience working directly with external auditors or remediating penetration test findings.

How To Apply: Share your CV on [email protected] Pay: ₹80,000.00 - ₹100,000.00 per month

Benefits

- Flexible schedule

Work Location: In person

📌 Cloud and DevSecOps Engineer (Gota)
🏢 Drones TechLabs
📍 Gota

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cloud and devsecops engineer (gota) / gota

Subscribe to this job alert:

Get the latest job offers by email for: cloud and devsecops engineer (gota) / gota