Senior Cloud Platform / DevSecOps Engineer (Thiruvananthapuram)

Senior Cloud Platform / DevSecOps Engineer (Thiruvananthapuram)

09 Oct
|
MP Dominic
|
Thiruvananthapuram

09 Oct

MP Dominic

Thiruvananthapuram

Role Overview

We are looking for an experienced Senior Cloud Platform / DevSecOps Engineer to design,

automate, secure, and operate enterprise-grade cloud platforms for Foresight Edge and its clients.

The role requires strong hands-on capability across Infrastructure-as-Code, cloud governance

and identity, networking, Kubernetes, CI/CD and GitOps, security controls, observability,

backup/DR, and cloud PaaS and data services.

The successful candidate should be comfortable owning infrastructure from architecture and

Infrastructure-as-Code through deployment, security, observability, operations, and

disaster recovery.

This is a hands-on engineering role suited for someone who can operate independently,

troubleshoot complex platform issues, and work closely with application, data, analytics,

security, and client infrastructure teams.

Key Responsibilities

Cloud Infrastructure & Infrastructure-as-Code

 Design, build, and manage cloud infrastructure using Terraform (Terragrunt or similar

orchestration tools an advantage).

 Develop reusable, well-documented modules and patterns, leveraging

verified/community modules where appropriate.

 Maintain environment-specific infrastructure configurations using Git-based workflows.

 Drive Infrastructure-as-Code standards, peer reviews, testing, and automation.

Cloud Governance & Identity

 Implement and manage cloud governance controls, including:

o Management group / account hierarchy

o Policy-as-code and compliance guardrails

o Role-based access control (RBAC)

o Privileged access management (e.g. Azure PIM)

 Design secure enterprise landing zones and subscription/account structures.

 Manage identity and access using Microsoft Entra ID (or equivalent) — groups, app

registrations, service principals, and enterprise applications.

 Implement OIDC and workload identity federation for passwordless automation and

workloads.

Cloud Networking

 Design and support enterprise cloud networking, including:

o Hub-and-spoke network topologies

o Cloud firewalls and network security groups

o Private DNS

o Private Link / Private Endpoints

o Hybrid connectivity (ExpressRoute, VPN gateways)

o Application gateways and Web Application Firewalls (WAF)

 Implement secure network segmentation and connectivity across cloud and on-premises

environments.

 Troubleshoot routing, DNS, firewall, and private connectivity issues.

Kubernetes & Container Platform Engineering

 Design and operate secure, private Kubernetes clusters (AKS preferred; EKS/GKE also

relevant).

 Configure cluster networking (CNI), node pools, workload identity, ingress, and

storage/CSI drivers.

 Implement Kubernetes security, scaling, resilience, and operational best practices.

 Package and deploy applications and platform components using Helm.

 Manage certificate lifecycle using tools such as cert-manager.

 Troubleshoot Kubernetes workloads, networking, storage, ingress, and cluster-level

issues.

CI/CD, GitOps & Developer Platform





 Administer source control platforms (e.g. GitHub) — organisations, repositories, access

controls, and branch protections.

 Develop and maintain CI/CD pipelines using GitHub Actions, Azure DevOps, or similar

tools.

 Configure and operate self-hosted build runners/agents where required.

 Implement container build, scanning, and release pipelines.

 Deploy and manage workloads through GitOps tooling such as ArgoCD or Flux.

 Establish promotion strategies across development, test, staging, and production

environments.

 Implement secure secrets and configuration management within CI/CD workflows.

Cloud PaaS & Data Platform Services

Hands-on experience managing and automating cloud services such as:

 Container registries and secrets/key management (e.g. Azure Container Registry, Key

Vault)

 Managed relational databases (e.g. PostgreSQL, SQL Server)

 NoSQL / document databases (e.g. Cosmos DB, MongoDB)

 Data lake and object storage (e.g. ADLS Gen2, Blob Storage)

 Data integration and streaming services supporting analytics workloads (e.g. Data

Factory, Kafka, Spark-based platforms)

 PaaS networking and Private Endpoints

 Backup, migration, and data movement tooling

Support data migration activities and the infrastructure required for enterprise data and analytics

workloads.

Observability & Operations

 Implement end-to-end monitoring using tools such as:

o OpenTelemetry

o Grafana / Prometheus

o Azure Monitor / Log Analytics (KQL)

 Build dashboards, alerts, and operational health monitoring.

 Implement distributed tracing, metrics, and centralised logging.

 Perform root cause analysis for platform and application incidents.

 Continuously improve platform reliability, performance, and availability.

Backup, Restore & Disaster Recovery

 Implement Kubernetes backup and restore using tools such as Velero.

 Configure database Point-in-Time Recovery (PITR) and backup policies.

 Design and validate backup, recovery, and disaster-recovery processes.

 Conduct restore testing and document recovery runbooks.

 Ensure workloads meet required RPO and RTO objectives.

Security & DevSecOps

 Integrate security controls across infrastructure and deployment pipelines.

 Work with security scanning tools (e.g. Snyk, Trivy, Checkov, SonarQube) across:

o IaC scanning

o SAST

o Software Composition Analysis (SCA)

o Container image security

 Implement Kubernetes policy enforcement using tools such as OPA/Gatekeeper or

Kyverno.

 Configure and manage application and network security, including WAF rules.

 Apply least-privilege access, secure secret handling,



identity-based authentication, and

policy-driven governance.

 Support compliance with client and industry requirements in regulated sectors (e.g.

finance, healthcare, public sector).

DNS, Edge & Application Access

 Manage DNS and edge services (e.g. Cloudflare, Azure Front Door, Azure DNS) through

Terraform, including:

o DNS zones and records

o Secure tunnels and zero-trust application access

o Edge WAF and DDoS protection

o Global load balancing

 Automate DNS and edge-security configuration through Infrastructure-as-Code.

 Troubleshoot DNS resolution, certificates, edge connectivity, and application access.

Automation & Scripting

Strong hands-on capability with:

 Bash and/or PowerShell (Python an advantage)

 Cloud CLIs (e.g. Azure CLI)

 kubectl and Helm CLI

 Git

 Terraform CLI

Use scripting and automation to reduce manual operational tasks and improve platform

consistency.

Required Skills & Experience

 7+ years of experience in Cloud Engineering, Platform Engineering, DevOps, or SRE

roles.

 Strong hands-on experience with at least one major cloud platform — Microsoft Azure

preferred; AWS or Google Cloud also valued.

 Advanced Terraform / Infrastructure-as-Code expertise.

 Strong knowledge of cloud governance and enterprise landing-zone concepts.

 Hands-on Kubernetes experience in production (AKS, EKS, or GKE).

 Strong CI/CD and GitOps experience.

 Good understanding of enterprise networking and security.

 Solid experience with cloud identity and access management (e.g. Entra ID).

 Experience with observability, monitoring, and production troubleshooting.

 Hands-on experience with security scanning and DevSecOps practices.

 Experience operating production-grade platforms in enterprise environments.

Preferred Experience

 Cloud certifications such as:

o Azure Solutions Architect Expert / Azure DevOps Engineer Expert / Azure

Security Engineer

o AWS Solutions Architect / DevOps Engineer – Professional

o Google Professional Cloud Architect / DevOps Engineer

 Kubernetes certifications such as CKA / CKAD / CKS.

 Experience supporting large, regulated, or mission-critical environments.

 Experience in a consulting or client-facing delivery environment.

 Experience with enterprise data and analytics platforms and cloud migration

programmes.

 Experience working with globally distributed engineering teams.

Personal Attributes

 Strong ownership mindset.

 Excellent troubleshooting and problem-solving capability.

 Comfortable working independently in complex, multi-client environments.

 Able to communicate clearly with engineering, security, architecture, business, and client

stakeholders.

 Strong focus on automation, security, reliability, and operational excellence.

If you are interested please share your updated CV to [HIDDEN TEXT]

Skills: Cloud Engineering, Devops, Microsoft Azure, Kubernetes, Terraform

Experience: 7.00-11.00 Years

📌 Senior Cloud Platform / DevSecOps Engineer (Thiruvananthapuram)
🏢 MP Dominic
📍 Thiruvananthapuram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior cloud platform / devsecops engineer (thiruvananthapuram) / thiruvananthapuram

Subscribe to this job alert:

Get the latest job offers by email for: senior cloud platform / devsecops engineer (thiruvananthapuram) / thiruvananthapuram