05 Oct
|
Acesoft Labs
|
Bengaluru
05 Oct
Acesoft Labs
Bengaluru
Description:
DevOps / Cloud / Security Engineer
Summary about the Role
We are looking for a hands-on DevOps / Cloud / Security Engineer to own our CI/CD pipelines, deployment/release processes, and security tooling on our Azure AKS platform. Platform and cluster maintenance are owned by a separate team; this role is not responsible for platform setup or ongoing cluster administration.
This role sits at the intersection of DevOps, DevSecOps, and release engineering , you'll design and maintain the CI/CD pipelines our engineering teams ship through, execute and support deployments end-to-end, and own the security scanning, vulnerability management, and secrets management processes that keep our systems safe.
What You'll Do
CI/CD & Deployment
• Design, build, and maintain CI/CD pipelines, primarily in GitHub Actions (reusable workflows, matrix builds, self-hosted runner management, OIDC-based authentication).
• Maintain and gradually migrate legacy Jenkins pipelines strong Jenkins knowledge is required
• Support release and deployment processes, including rollout strategies and rollback procedures.
• Own GitOps workflows with ArgoCD: Application CRDs, sync policies, health checks, automated rollback.
Deployment & Troubleshooting (Azure AKS)
• Execute and support application deployments to Azure AKS; this role owns the deployment/release execution, not platform or cluster maintenance (that sits with a separate platform team).
• Be the first line of troubleshooting for deployment and post-deployment issues: failed rollouts, pods not starting, misconfigured services, or a URL/endpoint becoming inaccessible after a release diagnosing root cause (application, ingress, DNS, certificates, config, secrets) and either resolving it or escalating to the right owner.
• Author and maintain Helm charts as our primary IaC tool for deployments (chart authoring, templating, upgrade strategies, helm test, dependency management).
• Use Terraform for Azure infrastructure provisioning tasks tied to deployments, beyond Helm/AKS (secondary tool in the current stack, but required knowledge).
• Work within existing Kubernetes NetworkPolicies and RBAC configurations to deploy and debug applications safely.
• Support autoscaling behavior (KEDA / HPA) for deployed workloads, including scaling based on Kafka lag or custom metrics.
Monitoring & Observability
• Own our Datadog implementation: Agent configuration (including socket mode), reading APM traces, Java library injection, building dashboards and monitors, log pipelines, maintaining the Service Catalog, and configuring Watchdog alerts.
• Understand and be able to articulate why Prometheus endpoints were disabled in favor of Datadog, including the trade-offs of that decision.
• Support the strategic move toward OpenTelemetry (OTEL) as a vendor-agnostic observability standard.
Security & Compliance
• Own the security toolchain and remediation process end-to-end: SonarQube Snyk Lacework Datadog ASM, including managing findings against defined SLAs (Critical: 24h / High: 1 week).
• Administer SonarQube: quality gates, fail-the-build policies, project setup, branch analysis, reporting.
• Run Snyk for container, IaC (Helm/YAML), and dependency scanning in CI/CD; prioritize findings and leverage the Snyk bot for automated fix PRs.
• Use Lacework for CSPM, runtime anomaly detection, and CIS Benchmark compliance reporting, translating findings into actionable Jira tickets.
• Perform threat modeling and manage vulnerability management processes across the stack.
• Integrate OWASP Dependency Check and OWASP ZAP (DAST) as GitHub Actions in CI/CD.
• Implement runtime security with Falco as a complement to Lacework.
• Generate and manage SBOMs (Syft / CycloneDX) and contribute to SLSA supply chain security practices.
Secrets Management
• Manage secrets using Sealed Secrets / kubeseal and External Secrets (rotation, namespace scoping, recovery strategy).
• Manage CI/CD pipeline secrets effectively including lifecycle handling. Should be knowledgeable on CI/CD secrets management from cloud providers
FinOps
• Monitor and optimize AKS cost: right-sizing, resource quotas, spot-node strategy.
AI Experience
• Explore AI-assisted operations tooling (e.g., GitHub Copilot for IaC, Datadog AI Insights / anomaly detection).
What You Bring
• Solid production experience deploying to and operating within Kubernetes / AKS (Azure) ; comfortable diagnosing and resolving deployment and post-deployment issues. (Cluster/platform setup and maintenance are owned by a separate team and are not part of this role.)
• Strong troubleshooting instincts: able to trace a "service/URL not accessible" issue through the stack ingress, DNS, certificates, service/pod health, config, and secrets and resolve or escalate appropriately.
• Solid hands-on skills with Docker and JFrog Artifactory.
• Proven experience building and maintaining CI/CD pipelines in GitHub Actions; solid working knowledge of Jenkins (our current legacy platform, being phased out).
• Strong hands-on experience with Helm as a primary IaC tool; working knowledge of Terraform.
• Strong hands-on experience with ArgoCD and GitOps workflows.
• Experience with Datadog (or comparable APM/monitoring platforms) for monitoring, alerting, and log management.
• Familiarity with Azure DevOps is a plus, though it is not the primary tooling in our current production stack.
• Strong security background: pipeline security scanning, vulnerability management, threat modeling, and remediation processes.
• Experience with SonarQube, Snyk (or similar SCA/container/IaC scanning tools), and cloud security posture management tools (e.g., Lacework).
• Experience with Kubernetes secrets management (Sealed Secrets, External Secrets, Azure Key Vault integration).
• Solid scripting skills (e.g., Bash, Python, or similar).
• Understanding of Kubernetes NetworkPolicies and RBAC.
• Ability to work independently in a fast-moving environment, balancing operational stability with ongoing modernization efforts.
Nice to Have
• Experience with OpenTelemetry (OTEL) migrations.
• Exposure to DAST tooling (e.g., OWASP ZAP) integrated into CI/CD.
• Experience with SBOM generation (Syft/CycloneDX) and SLSA supply chain security frameworks.
• Experience with Backstage.io or other internal developer portal platforms.
• FinOps experience, particularly around Kubernetes/AKS cost optimization.
• Experience with KEDA/HPA autoscaling based on custom or event-driven metrics.
• Experience with Falco or other Kubernetes runtime security tools.
• Interest or experience in applying AI-assisted tooling to DevOps/IaC workflows.
📌 DevOps / Cloud / Security Engineer (Bengaluru)
🏢 Acesoft Labs
📍 Bengaluru