Job Title: DevSecOps Engineer
Experience: 5+ Years
Location: Bangalore, Pune, Noida, Chennai, Coimbatore, Mumbai
Notice Period: 0-30 Days (Immediate Joiners preferred)
Job Summary
We are looking for a skilled DevSecOps Engineer with 5 years of experience to integrate security practices into our CI/CD pipelines and cloud infrastructure. The ideal candidate will ensure secure application delivery by embedding security controls, automating compliance, and collaborating across development, operations, and security teams.
Key Responsibilities
- Integrate security tools and practices into CI/CD pipelines (Shift-Left Security)
- Design and implement secure DevOps pipelines using tools like Jenkins, GitHub Actions, GitLab CI/CD
- Perform SAST, DAST, SCA, and container security scanning
- Manage secrets and credentials using tools like HashiCorp Vault, AWS Secrets Manager
- Implement infrastructure security using IaC tools (Terraform, CloudFormation)
- Ensure compliance with standards such as OWASP, ISO 27001, SOC 2
- Conduct vulnerability assessments and coordinate remediation
- Secure containerized workloads using Docker, Kubernetes
- Monitor systems using SIEM tools and respond to security incidents
- Collaborate with developers to fix security issues early in the SDLC
Required Skills
- Strong experience in DevOps + Security (DevSecOps practices)
- Hands-on with CI/CD tools: Jenkins, GitLab CI/CD, GitHub Actions
- Experience with cloud platforms (AWS / Azure / GCP)
- Knowledge of container security (Docker, Kubernetes)
- Experience with security tools:
- SAST: SonarQube, Checkmarx
- DAST: OWASP ZAP, Burp Suite
- SCA: Snyk, Black Duck
- Proficiency in scripting (Python, Bash)
- Understanding of IAM, encryption, network security
- Familiarity with SIEM tools (Splunk, ELK)
Core Security
- Secure SDLC implementation
- OWASP Top 10 + AppSec tools (SAST, DAST)
- Vulnerability management (Nessus / Qualys)
- IAM basics (RBAC, MFA, Least Privilege)
DevSecOps & CI/CD
- Securing CI/CD pipelines (Jenkins / GitHub Actions / GitLab CI)
- Integrating security scans into pipelines
- Strong scripting (Python / Bash)
Cloud Security (at least one cloud)
- AWS / Azure / GCP security fundamentals (IAM, VPC, Secrets, KMS)
Container Basics
- Docker + Kubernetes security fundamentals