Role — DevSecOps
We are hiring a hands-on DevSecOps engineer to own detection, cloud security posture, and security automation across our AWS-primary estate.
Key Responsibilities
1. Detection & triage: own the SIEM (Wazuh), tune rules, and read alerts daily. Feed it cloud audit logs (CloudTrail / Cloud Audit / Azure Monitor), WAF, identity, and EDR signal. You'll take over our Tier-3 decoder chaining for multi-source correlation.
2. Incident response: run the IR runbook under our Contain-First protocol (contain, investigate, document, post-mortem) with defined escalation and authority to act.
3. Hardening as code: encode baselines into IaC guardrails and golden images so config cannot silently drift; target CIS Benchmark Level 2 hardening on golden images.
4. Cloud posture management: own the fortnightly Posture Drift Review (PDR): continuously detect misconfiguration — public storage, over-permissive IAM, open security groups, unencrypted data — and drive it to closure.
5. Vulnerability management: scan OS, dependencies, and cloud resources; assign severity; drive remediation to closed against SLAs.
6. Web app security testing:
wire ZAP baseline scans and Semgrep into CI; advise teams on fixes (delivery teams remediate).
7. Identity & access governance: enforce MFA, least privilege, conditional access, and joiner/mover/leaver hygiene.
8. Secrets management: operate the vault, enforce short-lived credentials, keep secret scanning (Gitleaks / TruffleHog) green, eliminate long-lived keys on laptops.
9. Security policy authoring: draft credential, logging, access, and IR policies; map to ISO 27001 controls (drafts; enforcement sits with management).
10. Security advisory: threat-model new projects, review architectures pre-launch, and run developer security awareness.
Required Skills
1. 3+ years in cloud or application security; hands-on, not advisory-only, with CREST certification.
2. Solid AWS security depth; working knowledge of GCP and Azure (deep in one, learning the others is acceptable).
3. SIEM operations (Wazuh or equivalent), log analysis, and alert tuning.
4. WAF, IAM, network security, and cloud-native security controls.
5. DAST/SAST in CI (ZAP, Semgrep), dependency and secret scanning.
Please share you CVS at
[email protected]
-
📌 DevSec Ops Engineer (Bengaluru)
🏢 Robotico Digital®
📍 Bengaluru