Job Search and Career Advice Platform

Enable job alerts via email!

DevSecOps Manager

MoEngage

Bengaluru

On-site

INR 12,00,000 - 18,00,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading technology firm in Bengaluru is seeking an experienced DevSecOps Manager to champion security in software development. You will drive the architecture and execution of a robust DevSecOps framework while ensuring compliance with security standards. Your role includes managing multi-cloud environments, optimizing CI/CD pipelines, and mentoring technical team members. Candidates must have extensive experience in Linux administration, scripting, and cloud security tools. This position offers a dynamic work environment with challenges in high-velocity delivery and security compliance.

Qualifications

  • Experience with managing multi-cloud environments (AWS, GCP).
  • Proficiency in Infrastructure as Code (IaC) using Terraform.
  • Knowledge of cloud security compliance and tool integration.

Responsibilities

  • Lead the architecture and execution of the DevSecOps framework.
  • Manage cloud security posture and ensure compliance.
  • Design production-grade Kubernetes clusters.

Skills

Expert-level Linux administration
Scripting in Python
GitHub security features
Multi-cloud environment management
Containerization skills

Tools

Kubernetes
Terraform
Jenkins
Ansible
Job description

We are seeking a highly experienced DevSecOps Manager to lead the architecture and execution of our entire DevSecOps framework. Your core mission is to champion the "Secure by Design" philosophy and leverage a deep engineering mindset to drive the program. This perspective will be essential for facilitating faster issue identification and building proactive solutions to mitigate potential issues and delivery blockers. You will balance aggressive high-velocity delivery goals with uncompromising security and compliance to build a secure, resilient and highly scalable system.

You will have deep technical ownership of our Multi-Cloud environment (AWS GCP), container orchestration (Kubernetes), and CI/CD workflows, while proactively managing our Cloud Security Posture.

Key Responsibilities
1. Infrastructure Cloud Architecture
  • Facilitate SRE/Engineering teams to create, deploy, and manage secure, scalable infrastructure across AWS and GCP (knowledge of Azure is a plus).
  • Implement Infrastructure as Code (IaC) using Terraform to ensure reproducible, auditable, and compliant environments.
  • Manage and harden Linux-based application servers, ensuring OS-level security and performance tuning.
2. Cloud Security Compliance (New Focus)
  • IAM Governance: Design and enforce strict Identity and Access Management (IAM) policies based on the Principle of Least Privilege (PoLP).
  • CSPM Management: Implement and manage Cloud Security Posture Management tools (eg, AWS Security Hub, GCP Security Command Center, or Wiz) to detect misconfigurations in real-time.
  • Audit Compliance: Ensure infrastructure meets industry benchmarks (CIS Benchmarks, SOC2 etc) and manage automated compliance checks.
  • Encryption: Manage secret lifecycles using HashiCorp Vault or AWS KMS/GCP KMS, ensuring data is encrypted at rest and in transit.
3. Containerization Orchestration
  • Design and maintain production-grade Kubernetes clusters (EKS/GKE).
  • Implement Container Security best practices, including image scanning (Trivy/Clair/Wiz) and runtime security (Falco).
4. CI/CD Automation
  • Build and optimize end-to-end CI/CD pipelines using Jenkins, Harness, or Woodpecker.
  • Write advanced automation scripts using Python and Shell (Bash) to auto-remediate security incidents (eg, automatically isolating a compromised instance).
  • Utilize Configuration Management tools like Ansible to enforce security configurations across all servers.
5. Secure CDN Edge Architecture
  • Design Secure CDN architectures, implementing comprehensive WAF rules and DDoS protection.
  • Ensure "Origin Security" to prevent attackers from bypassing the CDN to hit the servers directly.
6. Observability Reliability
  • Maintain a robust monitoring stack using Prometheus, Grafana, and ELK/Sumologic/Coralogic.
  • Implement security logging and alerting (SIEM integration) to detect anomalies in traffic or access patterns.
7. Project Team Management
  • Drive effective project management for DevSecOps initiatives, defining clear scope, managing dependencies, and ensuring timely, high-quality delivery.
  • Drive end-to-end automation for controls, compliance enforcement, and incident response, striving for self-healing infrastructure and zero-touch operations.
  • Mentor and lead technical team members, fostering a collaborative, knowledge-sharing environment that promotes best practices in security and automation.
Required Technical Skills
Core DevOps Systems:
  • OS: Expert-level Linux administration and hardening [mandatory].
  • Scripting: Python Shell for automation and security tooling integration [mandatory].
  • SCM: GitHub (Security features: Dependabot, CodeQL).
Cloud Security:
  • Cloud Providers: AWS (GuardDuty, Inspector, KMS, WAF) GCP (IAM, VPC Service Controls) [mandatory].
  • Cloud Security: Experience with CSPM tools (Wiz) and Compliance frameworks (CIS).
  • Container Security: Kubernetes Network Policies, Pod Security Standards, Image Signing.
Tools Stack:
  • Orchestration: Kubernetes, Docker.
  • IaC: Terraform.
  • CI/CD: Jenkins, Harness, Woodpecker.
  • Config Mgmt: Ansible, Chef.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.