01 Oct
|
Recruitkar
|
Varthur
01 Oct
Recruitkar
Varthur
Job Overview We are looking for an experienced Cloud Security / Dev Sec Ops Engineer to design, implement, and maintain secure cloud infrastructure and deployment pipelines across AWS and Kubernetes environments. The ideal candidate will have robust hands-on experience with AWS security, Kubernetes security, Infrastructure as Code, CI/CD, container security, vulnerability management, and cloud-native security practices. The role will involve working closely with Dev Ops, engineering, and security teams to embed security throughout the software development and deployment lifecycle.
Key Responsibilities Design and implement secure and scalable infrastructure on AWS. Secure and manage Kubernetes clusters and containerized workloads. Implement security controls across the cloud infrastructure, applications, containers, and CI/CD pipelines. Integrate security practices into the Dev Ops lifecycle (Dev Sec Ops). Develop and maintain secure CI/CD pipelines with automated security checks.
Implement
Infrastructure as Code (Ia C) using tools such as Terraform or Cloud Formation. Configure and manage AWS security services including IAM, KMS, Cloud Trail, Guard Duty, Security Hub, WAF, and VPC security controls. Implement identity and access management, least-privilege policies, roles, permissions, and secrets management. Secure container images and Kubernetes workloads through vulnerability scanning and policy enforcement.
Implement
Kubernetes security controls including RBAC, Network Policies, Pod Security, Secrets management, and admission controls. Monitor cloud environments for security threats, vulnerabilities, misconfigurations, and suspicious activity. Perform vulnerability assessments and coordinate remediation of security issues.
Integrate tools such as SAST, DAST, SCA, container scanning, and Ia C scanning into CI/CD pipelines. Investigate and respond to cloud and infrastructure security incidents. Establish security best practices, standards, and reusable controls for engineering teams.
Conduct security reviews of infrastructure, architecture, and deployment configurations.
Automate security processes and compliance checks wherever possible. Maintain documentation related to security architecture, policies, configurations, and incident response.
Required Skills &
Experience Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.3–7 years of experience in Cloud Security, Dev Sec Ops, Dev Ops, or related roles. Strong hands-on experience with AWS cloud infrastructure and security. Strong understanding of Kubernetes and container security.
Proficiency with Linux and networking fundamentals. Strong experience with Infrastructure as Code, preferably Terraform. Hands-on experience with CI/CD platforms such as Jenkins, Git Hub Actions, Git Lab CI, or AWS Code Pipeline.
Good understanding of Docker/containerization.
Strong understanding of: IAM &
- RBACVPC & network security Security groups &
- NACLs Encryption & key management Secrets management Logging & monitoring Vulnerability management Identity and access controls Experience implementing security scanning and controls within CI/CD pipelines. Strong scripting/automation skills using Python, Bash, or similar.
Experience with Git and Git-based development workflows.
Kubernetes Security Skills
Candidates should have practical knowledge of: Kubernetes RBACNetwork Policies Pod Security Standards Kubernetes Secrets Service Accounts Ingress security Container image security Resource limits and security contexts Admission controllers/policies Cluster and workload monitoring Kubernetes vulnerability management Cloud Security Tools &
- Technologies Experience with some of the following is preferred: AWS:
IAM | KMS | Cloud Trail | Guard Duty | Security Hub | WAF | VPC | Cloud Watch | Config Dev Sec Ops: Jenkins | Git Hub Actions | Git Lab CI/CD | Sonar Qube | Snyk | Trivy | Checkmarx | OWASPContainers &
- Kubernetes: Docker | Kubernetes | Helm | EKS | Argo CD | Falco | OPA/Gatekeeper | Kyverno Ia C: Terraform | Cloud Formation | Terragrunt Good to Have Experience securing AWS EKS environments. Knowledge of CSPM/CNAPP solutions.
Experience with SIEM platforms such as Splunk, ELK, or Microsoft Sentinel. Familiarity with Zero Trust architecture.
Experience with security frameworks such as CIS, NIST, ISO 27001, SOC 2, or PCI-DSS.
Relevant certifications such as: AWS Security Specialty AWS Solutions Architect Certified Kubernetes Security Specialist (CKS)Certified Kubernetes Administrator (CKA)Security+/CISSP or equivalent Experience with cloud security automation and policy-as-code. Exposure to incident response and forensic investigation in cloud environments.
Candidate Profile The ideal candidate should have: Strong cloud security and Dev Sec Ops mindset. Excellent troubleshooting and problem-solving skills. Ability to identify and remediate security vulnerabilities independently.
Strong understanding of cloud networking and security architecture. Ability to balance security requirements with development and operational needs. Strong automation mindset and willingness to eliminate repetitive security tasks.
Good communication and collaboration skills. Ability to work effectively with engineering, Dev Ops, infrastructure, and security teams. Key Technologies AWS | Kubernetes | EKS | Docker | Terraform | Linux | CI/CD | Dev Sec Ops | IAM | VPC | Cloud Trail | Guard Duty | Security Hub | KMS | WAF | Git | Jenkins/Git Hub Actions | Trivy/Snyk | Python/Bash Employment Details Experience: 3–7 Years Job Type: Full-time Work Mode: Remote Location: Bengaluru Skills: AWS, Kubernetes, Dev Sec Ops, Terraform, CI/CD, Docker, IAM, Container Security, Vulnerability Management, Python Work mode: Bengaluru Experience: 3–8 years
📌 Cloud Security / Devsecops Engineer (aws + Kubernetes) (Varthur)
🏢 Recruitkar
📍 Varthur