Devops Engineer

Zybisys

Bengaluru

On-site

INR 1,500,000 - 2,300,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Zybisys, a technology company serving banks, FinTechs and stock brokers, seeks a DevOps Engineer to build and automate delivery pipelines across multi-region Azure and hybrid on-prem environments.

You will codify infrastructure with Terraform and Bicep, write Ansible playbooks, implement IaC tests, and drive an automation-first culture to reduce toil and improve release reliability.

Qualifications

  • 5–8 years of IT/DevOps experience with at least 3 years in a dedicated DevOps or platform role.
  • Strong Azure DevOps experience including pipelines, repos, environments, approvals, and service connections.
  • Experience designing multi-stage CI/CD pipelines with environment promotion, approvals, and rollback strategies.
  • Familiarity with Git branching strategies (GitFlow, trunk-based development).
  • Strong Terraform proficiency including module authoring, remote state, and CI/CD integration.
  • Ansible Vault for secrets management within pipelines.
  • Azure ARM templates or Bicep for platform-native resources.
  • IaC testing (Terratest, Kitchen-Terraform) to validate infrastructure.

Responsibilities

  • Design, build, and maintain multi-region CI/CD pipelines and deployment workflows across Azure and hybrid environments.
  • Implement branching strategies, templates, and promotion gates for development to production.
  • Create reusable pipeline templates and libraries for networking, compute, security, and monitoring components.
  • Incorporate automated validation steps: syntax checks, policy checks, security scans, and health verification.
  • Maintain pipeline health, monitor failures, and optimize speed and reliability.
  • Author and maintain Terraform modules and IaC across environments; manage state and drift.
  • Develop IaC for Azure using Terraform, Bicep, and ARM templates; ensure versioning and reviews.
  • Enforce IaC standards, peer reviews, and repository structure.

Skills

Azure DevOps
CI/CD design
Git branching
Automation scripting
Multi-region architecture

Tools

Terraform
Ansible
Bicep
Azure ARM templates
Terraform state management
Prometheus
Grafana
PowerShell
Python
Azure Monitor

Job description

Job Description

Zybisys is a technology company that helps banks, financial institutions, and FinTech businesses build and run secure, reliable, and high-performance technology platforms. We work closely with some of India's leading stock brokers to manage their cloud infrastructure, cybersecurity, platform operations, and observability. With deep expertise in the Capital Markets domain, we focus on simplifying complex technology, improving operational resilience, and helping our customers innovate with confidence.


The DevOps Engineer is a core technical role within the Zybisys Managed Cloud Services practice, responsible for building, automating, and continuously improving the delivery pipelines, infrastructure provisioning workflows, and operational automation across a complex multi-region Azure cloud and hybrid on-premises environment.


This role goes beyond traditional pipeline management. The DevOps Engineer at Zybisys is expected to drive an automation-first culture across the operations team — eliminating manual toil through intelligent automation, codifying infrastructure through IaC, enabling self-service provisioning, and ensuring every deployment and change follows a consistent, repeatable, and auditable process. The ideal candidate is a builder who is equally comfortable writing Terraform modules, designing release pipelines, and instrumenting infrastructure for observability.


Key Responsibilities


  • Design, build, and maintain CI/CD pipelines using Azure DevOps for infrastructure provisioning, configuration management, and application deployment workflows across multi-region Azure and

  • Implement branching strategies, pipeline templates, and environment promotion workflows — ensuring consistent progression from development through staging to production with appropriate approval gates.

  • Build reusable pipeline templates and task libraries to standardise delivery patterns across all managed infrastructure components — networking, compute, security platforms, and monitoring.

  • Integrate automated validation steps into pipelines: syntax checks, policy compliance scans (Azure Policy, Checkov), security scanning, and post-deployment health verification.

  • Maintain pipeline health — monitor build failure rates, pipeline execution times, and flaky tests; continuously tune pipelines for reliability and speed.


Infrastructure as Code (IaC)


  • Author and maintain Terraform modules for all managed Azure infrastructure components — VNets, policies, and API Management.

  • Develop Ansible playbooks and roles for configuration management — OS hardening, package installation, service configuration, and post-provisioning validation across Windows Server and Linux

  • Manage Terraform state — remote state backend design, state locking, workspace strategy for multi-environment deployments, and state drift detection.

  • Write Azure ARM templates or Bicep files for platform-native deployments where Terraform coverage is limited — Azure Monitor diagnostic settings, Policy assignments, and Marketplace

  • Enforce IaC standards and code review practices — peer review all infrastructure code changes, maintain module versioning, and manage the IaC repository structure and branching conventions.


Deployment Automation & Release Management


  • Automate end-to-end deployment workflows for infrastructure changes — from code commit through validation, approval, deployment, and post-change health verification — aligned with the

  • Build and maintain blue-green, canary, and rolling deployment strategies for managed platform components; design rollback automation for rapid recovery from failed deployments.

  • Coordinate with L2 and Specialist Engineers on release scheduling, maintenance window automation, and deployment sequencing to minimise service disruption.

  • Implement deployment readiness checks — pre-flight validation scripts that verify environment state, dependency availability, and capacity before initiating any deployment.

  • Maintain a deployment audit trail — every pipeline run must produce a verifiable log of what changed, who approved it, and what the post-change state is.


Operational Automation & Toil Elimination


  • Identify and automate repetitive manual operational tasks across L1 and L2 — routine health checks, housekeeping jobs, certificate renewals, snapshot management, and scheduled maintenance activities.

  • Build auto-remediation workflows triggered by monitoring alerts — self-healing scripts that can restart failed services, reclaim disk space, rebalance loads, or elevate intelligently when automated resolution is not possible.

  • equivalent tools — triggered by platform events, ITSM tickets, or scheduled cadences.

  • Implement self-service provisioning workflows that allow operations teams to request and receive standard infrastructure components without manual intervention from senior engineers.

  • Track and report toil reduction metrics — measure hours saved through automation and report progress to the Cloud Strategy & Operations Head.


Cloud Cost Optimisation Automation


  • Build automated cost governance workflows — tag compliance enforcement, idle resource detection and alerting, oversized VM rightsizing recommendations, and reserved instance utilisation reporting.

  • Develop dashboards and scheduled reports using Azure Cost Management APIs and Power BI or Grafana integrations to surface real-time cost visibility for operations and client stakeholders.

  • Implement automated budget alerts, anomaly detection, and cost spike notifications with actionable context — identifying the specific resource, owner, and recommended action.

  • Automate FinOps housekeeping tasks — unattached disk cleanup, orphaned resource identification, snapshot retention policy enforcement, and unused public IP release.


Observability as Code & Monitoring Automation


  • Manage Prometheus alerting rules, recording rules, and scrape configurations as code — versioned, peer-reviewed, and deployed through CI/CD pipelines.

  • Build and maintain Grafana dashboards as code using Grafana provisioning or Terraform Grafana provider — ensuring dashboards are version-controlled and reproducible across environments.

  • Automate Azure Monitor diagnostic settings, alert rule deployment, and Log Analytics workspace configuration using IaC — eliminating manual monitoring setup for every new resource deployment.

  • Integrate deployment pipelines with APM tools (Dynatrace, AppDynamics, or Azure Application Insights) — automatically enabling instrumentation as part of the deployment process rather than as a post-deployment manual step.

  • Build synthetic monitoring and availability test automation for critical services — ensuring proactive detection of issues before end users are impacted.

  • Lead the technical planning for new Azure environment builds — subscription design, resource group structure, naming conventions, tagging taxonomy, and access control framework.

  • Manage environment lifecycle — provisioning, configuration, decommission, and cost optimisation across development, staging, and production tiers in multi-region Azure.

  • Implement Azure Policy as Code — author and deploy custom policy definitions, initiatives, and compliance remediation tasks through CI/CD pipelines.

  • Maintain environment parity through IaC — ensuring staging environments accurately reflect production configuration to eliminate environment-specific deployment failures.


DevSecOps & Compliance


  • Integrate security scanning into all CI/CD pipelines — static IaC analysis (Checkov, tfsec), secret detection (git-secrets, Azure Key Vault integration), and dependency vulnerability scanning.

  • Enforce Azure security baselines through pipeline policy gates — no deployment proceeds if it violates defined security or compliance thresholds.

  • Manage Azure Key Vault integration across pipelines — secrets management, certificate rotation automation, and access policy governance for pipeline service principals.

  • Support audit and compliance requirements by maintaining complete, tamper-evident pipeline execution logs and deployment records.


Requirements

Required Skills & Experience


  • 5 – 8 years of overall IT/DevOps experience; minimum 3 years in a dedicated DevOps or platform

  • Strong Azure DevOps experience — pipelines (YAML and classic), repos, artifacts, environments, approvals, and service connections.

  • Experience designing and managing multi-stage CI/CD pipelines with environment promotion, approval gates, and rollback strategies.

  • Familiarity with Git branching strategies — GitFlow, trunk-based development, and feature flag integration.

  • Strong Terraform proficiency — module authoring, remote state management, workspace strategy, provider versioning, and CI/CD integration.

  • and Ansible Vault for secrets.

  • Azure ARM templates or Bicep — for platform-native resources not well-supported by Terraform providers.

  • IaC testing frameworks — Terratest, Kitchen-Terraform, or equivalent for validating infrastructure App Services, AKS (awareness), and platform networking.

  • Azure-native automation services: Azure Automation, Azure Functions, Logic Apps, and Event Grid for event-driven and scheduled automation.

  • Azure Policy, Management Groups, and Blueprints — policy-as-code design and compliance automation.

  • Azure Key Vault — secrets management, certificate lifecycle automation, and managed identity integration with pipelines and applications.

  • Multi-region Azure architecture awareness — understanding of availability zones, region pairs, and geo-redundancy patterns relevant to deployment planning.


Scripting & Automation


  • Strong scripting skills: PowerShell (including Az module), Python, and Bash — for building operational utilities, automation scripts, and pipeline tasks.

  • REST API and SDK usage — Azure REST APIs, Azure Python/PowerShell SDKs for custom automation beyond what native tools support.

  • Experience building auto-remediation and event-driven automation workflows that integrate with monitoring platforms and ITSM systems.


Observability & Monitoring Integration


  • Prometheus and Grafana as code — alerting rules, recording rules, dashboard provisioning, and scrape configuration management through CI/CD.

  • Azure Monitor automation — diagnostic settings, alert rules, and Log Analytics workspace configuration through IaC.

  • APM integration experience — instrumenting applications and infrastructure for Dynatrace, AppDynamics, New Relic, or Azure Application Insights as part of deployment pipelines.


DevSecOps


  • IaC security scanning tools: Checkov, tfsec, or equivalent — integrated into pipelines as mandatory quality gates.

  • Secrets management best practices — Azure Key Vault integration, managed identities, and elimination of hard-coded credentials in all pipeline and automation code.

  • Vulnerability scanning and dependency management — understanding of how to integrate security tooling into delivery workflows without becoming a bottleneck.

  • Experience working within ITSM-governed change management environments — integrating automated deployments with change record creation, approval workflows, and post-change validation.

  • Strong documentation habits — every pipeline, module, and automation script must be accompanied by clear usage documentation and changelog.

  • Collaborative working style — able to translate operational pain points from L1/L2 teams into automation solutions, and communicate deployment risks clearly to operations leads.


Certification (Preferred)


  • Domain

  • Certification

  • Infrastructure

  • AZ-305 (Solution Architect — advantageous)

  • Automation / IaC

  • HashiCorp Terraform Associate | Red Hat Ansible Automation

  • DevSecOps

  • SC-200 (Security Operations) | Checkov / Bridgecrew

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Azure Devops Engineer
Azure Devops Engineer

Zybisys Consulting Services • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Specialist Engineer - L3
Specialist Engineer - L3

Zybisys • India

On-site
INR 3,500,000 - 7,000,000
Cloud Infrastructure & Automation Engineer
Cloud Infrastructure & Automation Engineer

Dupont Specialty Products • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Sr DevOps Engineer II
Sr DevOps Engineer II

MetLife • Maharashtra

On-site
INR 2,500,000 - 4,000,000
Senior Consultant - DevOps
Senior Consultant - DevOps

Value Creed • Hyderabad

On-site
INR 1,200,000 - 2,000,000
Sr. Engineer I - Cloud Engg & AI
Sr. Engineer I - Cloud Engg & AI

Anblicks Inc. • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Azure DevOps Engineer
Azure DevOps Engineer

Shashwath Solution • Pune District

On-site
INR 1,200,000 - 2,000,000
DevOps Engineer
DevOps Engineer

Eurofins • Bengaluru

On-site
INR 2,000,000 - 3,200,000
Azure Devops Engineer
Azure Devops Engineer

Proventeq • Hadapsar

Hybrid
INR 1,200,000 - 2,100,000
Azure DevOps Lead Engineer
Azure DevOps Lead Engineer

Adfolks LLC • Ernakulam

On-site
INR 1,500,000 - 2,500,000