Jobgether

DevSecOps Engineer

Jobgether

Google CloudAWSKubernetesCI/CDIAMTerraformGitLabDatadogIstioPython

About the Role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevSecOps Engineer based in India. This is a hands-on DevSecOps opportunity focused on embedding security across cloud infrastructure, software delivery, Kubernetes, and internal endpoints. You will take ownership of security posture across Google Cloud Platform (GCP) and Amazon Web Services (AWS), helping protect highly distributed and cloud-native environments. The role combines cloud security, Kubernetes hardening, CI/CD protection, endpoint security, compliance, threat modeling, and security automation. You will work closely with engineering teams to identify vulnerabilities, reduce attack surfaces, strengthen controls, and improve security without unnecessarily slowing delivery velocity. You will also lead security monitoring, incident response, vulnerability remediation, and compliance activities across regulated environments. Automation will be central to the role, with opportunities to turn security policies, compliance checks, remediation workflows, and observability into scalable engineering solutions. This position is ideal for an experienced security engineer who enjoys solving complex infrastructure challenges and communicating effectively with both technical teams and senior technology leaders. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevSecOps Engineer based in India. This is a hands-on DevSecOps opportunity focused on embedding security across cloud infrastructure, software delivery, Kubernetes, and internal endpoints. You will take ownership of security posture across Google Cloud Platform (GCP) and Amazon Web Services (AWS), helping protect highly distributed and cloud-native environments. The role combines cloud security, Kubernetes hardening, CI/CD protection, endpoint security, compliance, threat modeling, and security automation. You will work closely with engineering teams to identify vulnerabilities, reduce attack surfaces, strengthen controls, and improve security without unnecessarily slowing delivery velocity. You will also lead security monitoring, incident response, vulnerability remediation, and compliance activities across regulated environments. Automation will be central to the role, with opportunities to turn security policies, compliance checks, remediation workflows, and observability into scalable engineering solutions. This position is ideal for an experienced security engineer who enjoys solving complex infrastructure challenges and communicating effectively with both technical teams and senior technology leaders. Accountabilities Own Cloud Security Posture Management (CSPM) across GCP and AWS, continuously assessing environments, identifying misconfigurations, and tracking remediation activities. Design and enforce Identity and Access Management (IAM) policies, service account hygiene, least-privilege access controls, and workload identity across multi-cloud environments. Implement cloud network security controls, including private service access, firewall rules, network policies, ingress and egress restrictions, and Private Google Access. Identify externally exposed services and lead efforts to move unnecessary public endpoints to internal load balancers, private endpoints, VPNs, or dedicated interconnects to reduce the external attack surface. Establish strong secrets management practices using GCP Secret Manager and AWS Secrets Manager, eliminating hardcoded credentials and automating credential rotation. Lead cloud and Kubernetes security incident response, including triage, containment, investigation, remediation, and post-incident improvement. Own security compliance reporting for frameworks and regulations such as SOC 2, HIPAA, and ISO 27001, including evidence collection, gap analysis, and control implementation. Conduct threat modeling, security reviews, and architecture risk assessments to identify and mitigate security risks throughout the development lifecycle. Harden Google Kubernetes Engine (GKE) clusters using CIS benchmarks, Pod Security Standards, admission controls, and other Kubernetes security best practices. Implement and maintain Kubernetes network policies to enforce east-west traffic segmentation between namespaces and services. Deploy and operate runtime security tooling such as Falco to detect and investigate threats within Kubernetes workloads. Manage Kubernetes Role-Based Access Control (RBAC) according to least-privilege principles and continuously audit and remediate over-permissioned service accounts. Secure the container supply chain by integrating image scanning into CI pipelines, enforcing signed images, and maintaining trusted container registry policies. Implement Istio security controls, including mutual TLS (mTLS), authorization policies, and east-west traffic observability. Continuously audit running workloads for security drift, including privileged containers, host path mounts, and secrets exposed through environment variables. Secure GitLab CI/CD environments by protecting runners, restricting pipeline permissions, enforcing branch protection, and requiring appropriate merge request approvals. Integrate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), dependency scanning, container scanning, and secret detection into GitLab pipelines and own associated triage and remediation workflows. Implement Infrastructure as Code (IaC) security scanning using tools such as tfsec and Checkov as mandatory pipeline gates for Terraform changes. Establish GitLab token hygiene practices, including expiry policies, project token rotation, and auditing of personal access token usage. Define and enforce organization-wide CI/CD security policies through policy-as-code approaches. Inventory public endpoints and continuously drive internalization of services that do not require public exposure. Implement and maintain Web Application Firewall (WAF) and Cloud Armor controls to protect externally exposed services. Automate TLS certificate issuance and rotation while enforcing TLS 1.2 or higher across endpoints. Strengthen bastion host security through short-lived certificates, OS Login, Identity-Aware Proxy (IAP), elimination of persistent SSH keys, and administrative session logging. Manage DNS security controls, including DNS Security Extensions (DNSSEC), private DNS zones, and split-horizon DNS where required. Build security automation pipelines for policy enforcement, compliance validation, vulnerability remediation, and other security operations. Develop security monitoring and threat detection dashboards in Datadog and continuously tune alerts for cloud and Kubernetes signals. Create and maintain runbooks covering security incidents, vulnerability response, access reviews, and operational security procedures. Champion security awareness and training while conducting secure code reviews and threat modeling workshops. Requirements Bring 7+ years of experience in DevSecOps, cloud security, infrastructure security engineering, or a closely related field. Demonstrate deep hands-on experience securing production Kubernetes clusters, including RBAC, network policies, Pod Security Standards, admission controls, and runtime protection. Possess strong practical experience with GCP and/or AWS security services, including cloud IAM design and security architecture. Demonstrate strong knowledge of CI/CD security, including pipeline hardening, secrets management, integrated security scanning, and security policy enforcement. Have proven experience internalizing service endpoints and reducing the attack surface of cloud environments. Bring experience working with security and compliance requirements such as HIPAA, SOC 2, or ISO 27001, preferably in regulated environments. Demonstrate the ability to explain complex security risks clearly to different audiences, from engineers implementing remediation to CTO-level stakeholders evaluating business impact. Have hands-on experience with GCP security technologies such as Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager, and Binary Authorization. Have hands-on experience with AWS security services such as GuardDuty, Security Hub, IAM, Key Management Service (KMS), Macie, and AWS Config. Demonstrate strong Kubernetes security expertise covering GKE hardening, Pod Security Standards, network policies, RBAC, and admission controllers. Have strong GitLab security experience covering CI/CD security, SAST/DAST, dependency scanning, secret detection, and pipeline policy management. Possess strong Terraform knowledge, including IaC security scanning with tfsec or Checkov and secure Terraform module design. Have experience using Datadog for security monitoring, threat detection, and alert management. Demonstrate experience securing service meshes with Istio, including mTLS, authorization policies, and related security controls. Experience with tools such as Falco, Open Policy Agent (OPA)/Gatekeeper, HashiCorp Vault, Wiz, Orca, Prisma Cloud, Trivy, or Snyk is advantageous. Experience with Security Information and Event Management (SIEM) platforms such as Splunk or Chronicle is a plus. Proficiency in Python or Go for security automation is beneficial. A Certified Kubernetes Security Specialist (CKS) certification is advantageous. Google Professional Cloud Security Engineer or AWS Certified Security – Specialty certification is a plus. Experience with eBPF-based security technologies such as Cilium or Tetragon is beneficial. Penetration testing, red team experience, or advanced offensive security knowledge is advantageous. Experience with threat modeling methodologies such as STRIDE or PASTA is a plus. Familiarity with service mesh security beyond Istio is beneficial. Benefits Opportunity to work across modern multi-cloud environments spanning GCP and AWS. Hands-on exposure to Kubernetes, GitLab CI/CD, Terraform, Istio, Datadog, cloud security platforms, and security automation. Opportunity to own security initiatives across cloud infrastructure, containerized workloads, software delivery pipelines, and endpoints. Exposure to compliance programs involving SOC 2, HIPAA, and ISO 27001. Opportunity to build scalable security automation and policy-as-code solutions. Collaboration with engineering and technology teams on high-impact security initiatives. Opportunity to influence security architecture, threat modeling, incident response, and vulnerability management practices. Environment focused on strengthening security while maintaining engineering velocity. Opportunity to expand expertise across cloud security, Kubernetes, DevSecOps, and emerging security technologies. Remote working opportunity within India. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

You'll be redirected to Jobgether's application page

Job Details

Salary

Not disclosed

Location

India

Job type

Full-time

Category

DevSecOps

Experience

7+ years

Posted

Today

Job Highlights

  • 7+ years level role
  • 100% Remote — open to candidates in India
  • Full-time position

About Jobgether

This job is hosted by Jobgether. Clicking Apply opens their site.

More jobs from Jobgether on RC9

Remote Work Style

Mixed

Mix of flexible and scheduled meetings

Your Match

See how well your skills line up with this role, and what you're missing.

AI Cover Letter

Generate a cover letter tailored to this job from your profile.