A complete application in a minute — tailored resume and cover letter, ready to send.
Goodfit is seeking a DevSecOps / Cloud Security Engineer to embed security across cloud infrastructure, container platforms, and CI/CD pipelines. You will lead application security initiatives (SAST, DAST, SCA), enforce policy-as-code in Kubernetes, manage cloud identities and secrets, and coordinate vulnerability management.
You will bridge development and security, ensuring ISO 27001 and DPDP compliance while securing AWS and containerized environments.
We are seeking a DevSecOps / Cloud Security Engineer to embed security across our cloud infrastructure, container platforms, and CI/CD pipelines. In this role, you will lead our application security initiatives (SAST, DAST, SCA), enforce policy-as-code across Kubernetes, manage cloud identity and secrets, and coordinate vulnerability management (VAPT). You will bridge the gap between development and security, ensuring compliance with standards like ISO 27001 and DPDP while securing our AWS and containerized environments.
Integrate automated security scanning into GitLab CI pipelines using SonarQube (SAST), OWASP ZAP (DAST), and Trivy / Grype / Syft (SCA & Container scanning).
Enforce container and image security using Cosign for image signing and verification.
Track security remediations, assist developers in fixing code vulnerabilities (OWASP Top 10), and coordinate third-party VAPT audits.
Design, enforce, and audit cloud identity controls using AWS IAM, least-privilege policies, and AWS Directory Services/SSO.
Manage application secrets and cryptographic keys using AWS Secrets Manager, AWS KMS, and HashiCorp Vault.
Monitor and analyze threat telemetry across AWS Security Hub, GuardDuty, Inspector, CloudTrail, and CloudWatch Logs integrated into SIEM platforms.
Oversee PKI, SSL/TLS certificate lifecycles, and automated renewals using AWS ACM and Vault.
Implement policy-as-code and governance in Kubernetes using Kyverno or OPA/Gatekeeper.
Enforce Kubernetes RBAC, Pod Security Standards, and Linux host hardening best practices across Docker nodes and cloud workloads.
Ensure compliance alignment with ISO 27001 security controls and India DPDP (Digital Personal Data Protection) data privacy guidelines.