DevSecOps Engineer

Sutherland

India

On-site

INR 3,800,000 - 6,800,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Sutherland is seeking a senior Cloud Security Engineer in India to lead cloud and container security across multi-cloud environments. You will own CSPM, IAM, VPC security, and incident response, ensuring compliance with SOC 2, HIPAA, and ISO 27001.

Strong Kubernetes security and CI/CD security expertise are essential. You will implement IaC security scanning and threat modelling, driving secure architecture decisions and reducing the public attack surface.

Qualifications

  • 7+ years in DevSecOps, cloud security, or infra security engineering.
  • Strong hands-on security experience with Kubernetes production clusters.
  • Proven experience securing GCP and AWS security services and IAM design.
  • Robust CI/CD security knowledge – pipeline hardening, secrets management, and integrated scanning.
  • Experience internalising service endpoints and reducing cloud attack surface.
  • Familiarity with HIPAA, SOC 2, or ISO 27001 compliance.

Responsibilities

  • Own cloud security posture management across GCP and AWS with continuous assessment and remediation tracking.
  • Design IAM policies and least-privilege access controls across multi-cloud environments.
  • Harden and secure Kubernetes workloads and network policies, with runtime protection.
  • Lead security incident response across cloud and Kubernetes stacks.
  • Ensure compliance reporting for SOC 2, HIPAA, and ISO 27001 with evidence collection and gap analysis.

Skills

Cloud security
Kubernetes security
GCP & AWS security
GitLab CI/CD security
Threat modelling
IaC security scanning

Tools

GKE hardening
tfsec / Checkov
Trivy / Snyk
Istio security
Binary Authorization

Job description

Cloud Security
  • Own cloud security posture management (CSPM) across GCP and AWS - continuous assessment, misconfiguration detection, and remediation tracking.
  • Design and enforce IAM policies, service account hygiene, least-privilege access controls, and workload identity across multi-cloud environments.
  • Implement VPC security controls - private service access, firewall rules, network policies, ingress/egress restrictions, and Private Google Access.
  • Internalise and secure service endpoints - move external-facing services to internal load balancers, private endpoints, and VPN/interconnect. Continuously audit and reduce the public attack surface.
  • Manage secrets hygiene - enforce Secret Manager (GCP) and AWS Secrets Manager, eliminate hardcoded credentials, and rotate secrets programmatically.
  • Lead cloud security incident response - triage, contain, investigate, and remediate across cloud and Kubernetes environments.
  • Own compliance reporting for SOC 2, HIPAA, and ISO 27001 - evidence collection, gap analysis, and control implementation.
  • Conduct regular threat modelling, security reviews, and architecture risk assessments.
Kubernetes Security
  • Harden GKE clusters - CIS benchmarks, pod security standards (restricted/baseline), and admission control policies.
  • Implement and manage network policies to enforce east-west traffic segmentation between namespaces and services.
  • Deploy and operate runtime security tooling (e.g. Falco) for threat detection inside cluster workloads.
  • Manage Kubernetes RBAC with least-privilege principles. Audit and remediate overpermissioned service accounts.
  • Secure the container supply chain - image scanning in CI (Trivy/Snyk), enforce signed images, and maintain a trusted registry policy.
  • Implement Istio security controls - mTLS enforcement, authorisation policies, and east-west traffic observability.
  • Continuously audit running workloads for security drift - privileged containers, host path mounts, and secrets in environment variables.
CI/CD & GitLab Security
  • Secure the GitLab CI/CD pipeline end-to-end - protect runner environments, restrict pipeline permissions, enforce branch protection and MR approvals.
  • Integrate SAST, DAST, dependency scanning, container scanning, and secret detection natively into GitLab CI. Own the triage and remediation workflow.
  • Implement IaC security scanning (tfsec, Checkov) as a mandatory pipeline gate for all Terraform changes.
  • Manage GitLab token hygiene - enforce expiry policies, rotate project tokens, and audit personal access token usage.
  • Define and enforce pipeline security policies organization-wide using GitLab security policy-as-code.
Endpoint & Network Security
  • Audit and reduce the external attack surface - inventory all public endpoints and drive internalization of services that do not need to be public.
  • Implement and maintain WAF and Cloud Armor rules to protect externally exposed services.
  • Enforce TLS certificate management - automate issuance, rotation, and enforce TLS 1.2+ across all endpoints.
  • Manage bastion host security - enforce short-lived certificates (OS Login / IAP), eliminate persistent SSH keys, and log all administrative sessions.
  • Own DNS security controls - DNSSEC, private DNS zones for internal services, split-horizon DNS where required.
Security Engineering & Automation
  • Build security automation pipelines - policy enforcement, compliance checks, and vulnerability remediation as code.
  • Instrument security observability in Datadog - threat detection dashboards and alert tuning for cloud and Kubernetes signals.
  • Develop and maintain runbooks for security incidents, vulnerability response, and access reviews.
  • Champion security training and awareness. Conduct secure code reviews and threat modelling workshops.
Tech Stack
Required
  • GCP - Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager, Binary Authorization
  • AWS - GuardDuty, Security Hub, IAM, KMS, Macie, AWS Config
  • Kubernetes - GKE hardening, pod security standards, network policies, RBAC, admission controllers
  • GitLab - CI/CD security, SAST/DAST, dependency scanning, pipeline policy management
  • Terraform - IaC security scanning (tfsec, Checkov), secure module design
  • Datadog - security monitoring, threat detection, alert management
  • Istio - mTLS, authorisation policies, service mesh security
Good to have
  • Falco, OPA/Gatekeeper, HashiCorp Vault, Wiz/Orca/Prisma Cloud, Trivy/Snyk, SIEM (Splunk/Chronicle), Python or Go
Must have
  • 7+ years in DevSecOps, cloud security, or infrastructure security engineering.
  • Deep hands-on experience securing Kubernetes clusters in production - RBAC, network policies, pod security, and runtime protection.
  • Proven experience with GCP and/or AWS security services and IAM design.
  • Strong CI/CD security knowledge - pipeline hardening, secrets management, and integrated scanning.
  • Experience internalising service endpoints and reducing cloud attack surface.
  • Familiarity with HIPAA, SOC 2, or ISO 27001 complian
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

Sutherland Global • Hyderabad

On-site
INR 1,800,000 - 2,600,000
DevsecOps Engineer
DevsecOps Engineer

Mindsprint • Bengaluru, Chennai District

Hybrid
INR 1,600,000 - 2,200,000
VS01689 - DevOps Engineer - GCP
VS01689 - DevOps Engineer - GCP

E4 Software Services Pvt Ltd. • Pune District

On-site
INR 1,400,000 - 2,100,000
DevSecOps Engineer
DevSecOps Engineer

Varaha • Bengaluru

On-site
INR 1,200,000 - 1,500,000
DevSecOps, Product Security Engineer
DevSecOps, Product Security Engineer

Jobtailor • Hyderabad

On-site
INR 1,800,000 - 3,000,000
DevSecOps Professional
DevSecOps Professional

Shashwath Solution • Dadri

On-site
INR 1,200,000 - 2,000,000
Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

JobCubby • Kolkata District

On-site
INR 2,400,000 - 3,600,000
DevSecOps Professional
DevSecOps Professional

Shashwath Solution • Pune District

On-site
INR 1,200,000 - 1,800,000
Aviatrix networking experience
DevOps Engineer
DevOps Engineer

SecLogic.ai • Dadri

On-site
INR 1,200,000 - 2,500,000
Senior Security Engineer
Senior Security Engineer

INDmoney • Bengaluru

On-site
INR 1,500,000 - 2,600,000