We are seeking a highly motivated DevSecOps Engineer with 5–7 years of experience in cloud-native infrastructure, CI/CD automation, and security integration. The ideal candidate will have hands‑on expertise in building secure software delivery pipelines, implementing Infrastructure as Code (IaC), managing Kubernetes environments, and integrating security controls throughout the SDLC.
This role requires a strong technical background in modern DevOps practices, cloud platforms, automation, and application security, with the ability to collaborate effectively across development, platform, and security teams.
Key Responsibilities
- Design, develop, and maintain CI/CD pipelines to support automated build, testing, security scanning, and deployment processes
- Implement Infrastructure as Code (IaC) using Terraform or OpenTofu
- Deploy, manage, and troubleshoot containerized applications on Kubernetes platforms
- Integrate security tools and controls into CI/CD pipelines following DevSecOps best practices
- Implement and enforce policy-as-code controls for deployment governance and compliance
- Manage artifact repositories and software dependency lifecycle processes
- Automate infrastructure provisioning, application deployment, and operational tasks
- Support vulnerability remediation and security compliance initiatives
- Collaborate with development, cloud, platform, and security teams to improve delivery efficiency and security posture
- Monitor and optimize platform performance, reliability, and scalability
- Participate in incident troubleshooting, root cause analysis, and production support activities
- Maintain technical documentation and operational runbooks
Required Skills
- 5–7 years of experience in DevOps, DevSecOps, Platform Engineering, or Cloud Engineering
- Willing to work in US shifts - Central Timezone
- Strong hands-on expertise with at least one CI/CD platform:
- GitHub Actions
- Jenkins
- Tekton
- ArgoCD
- Experience building and maintaining:
- Automated testing and deployment processes
- Strong hands-on experience with:
- Kubernetes (EKS, AKS, or GKE)
- Container orchestration and deployment automation
- Helm chart deployment and management
- Experience with Infrastructure as Code (IaC):
- Terraform
- OpenTofu
- Hands-on experience with at least one cloud platform:
- AWS
- GCP
- Experience integrating security tools into CI/CD pipelines:
- Container Security: Trivy, Grype, Prisma Cloud
- Experience with Policy-as-Code solutions:
- Open Policy Agent (OPA)
- Rego
- Kyverno
- Knowledge of:
- Security policy enforcement
- Experience with artifact repository platforms:
- Understanding of:
- Artifact promotion workflows
- Vulnerability remediation processes
- Python
- Bash
- PowerShell
- Experience with Git version control and branching strategies
- Good understanding of Linux administration and networking fundamentals
Good to Have Skills
- Experience with GitOps practices and tools such as ArgoCD
- Exposure to Service Mesh technologies (Istio, Linkerd)
- Familiarity with Platform Engineering concepts and Internal Developer Platforms (IDP)
- Experience with:
- Grafana
- OpenTelemetry
- ELK/OpenSearch
- Exposure to cloud security and compliance frameworks
- Knowledge of Site Reliability Engineering (SRE) principles
- Familiarity with container runtime security and Kubernetes security best practices
- Experience working in highly regulated environments
- AWS Solutions Architect Associate