Security Engineer

Carpl.AI, Inc.

New Delhi

On-site

INR 1,500,000 - 2,800,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Carpl.AI, Inc. in New Delhi is seeking a Security Engineer to design, implement, and maintain secure systems with a focus on container hardening and Kubernetes security.

This on-site, full-time role requires hands-on expertise to protect cloud-native environments. You will integrate vulnerability scanning into CI/CD, manage security infrastructure, and respond to incidents, collaborating with engineering teams to raise the security posture across the enterprise.

Qualifications

  • Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or a related field (or equivalent professional experience).
  • 2 to 5+ years of proven hands-on experience in a dedicated Security Engineering, DevOps Security, or Infrastructure Security role.
  • Advanced, hands-on experience with Docker containerization and secure image construction (e.g., distroless images, multi-stage builds, rootless execution).
  • Strong expertise managing and securing Kubernetes ecosystems (managed services like EKS/GKE/AKS or self-hosted).
  • Deep understanding of cloud-native security tools, service meshes, and runtime security monitoring (Falco).
  • Experience with scripting languages (Python, Bash, or Go) to automate routine security tasks and threat hunting.
  • Strong expertise in securing public cloud environments (AWS, Azure, or Google Cloud Platform).
  • Work arrangement: on-site full-time.
  • Certifications such as CKS, CISSP, or OSCP preferred.

Responsibilities

  • Container Hardening: Build, maintain, and audit secure, hardened base images (Docker/OCI).
  • Orchestration Security: Enforce security policies in Kubernetes clusters (RBAC, Network Policies, Admission Controllers, pod security).
  • Secure SDLC and DevSecOps: Integrate container vulnerability scanning (Trivy, Clair, Grype) into CI/CD pipelines.
  • Security Infrastructure and Architecture: Design, deploy, manage firewalls, IDS/IPS, SIEM, and data encryption protocols.
  • Vulnerability and Risk Management: Conduct vulnerability assessments, code reviews, and configuration audits (IaC and running).
  • Incident Response: Monitor workloads and network traffic; respond to real-time security breaches.

Skills

Python
Bash
Go
Cloud security

Education

Bachelor's degree in Computer Science, Cyber Security, IT

Tools

Docker
Kubernetes
Trivy
Clair
Grype
Falco

Job description

New Delhi | Onsite | Full time (Engineering)

We are seeking a highly skilled Security Engineer to design, implement, and maintain robust security systems that protect our organization’s digital assets, infrastructure, and networks. In this role, you will focus heavily on securing containerized environments, ensuring orchestrators are locked down, and building trusted, hardened base images. You will be responsible for proactively identifying vulnerabilities, responding to real-time security incidents, and establishing a security-first culture across our engineering teams. This position requires full-time, on-site presence at our office.

Key Responsibilities

Container Hardening: Build, maintain, and audit secure, hardened base images (Docker/OCI). Implement automated workflows to scan and update base layers, minimizing the attack surface before images reach production.

Orchestration Security: Design and enforce security policies within Kubernetes clusters, including Role-Based Access Control (RBAC), Network Policies, Admission Controllers, and pod security standards.

Secure SDLC and DevSecOps: Integrate container vulnerability scanning (e.g., Trivy, Clair, Grype) and static analysis tools directly into CI/CD deployment pipelines.

Security Infrastructure and Architecture: Design, deploy, and manage security systems, including firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), SIEM platforms, and data encryption protocols.

Vulnerability and Risk Management: Conduct regular vulnerability assessments, code reviews, and configuration audits across infrastructure-as-code (IaC) and running environments.

Incident Response: Monitor cluster workloads and network traffic for suspicious activity. Act as a primary responder to mitigate and remediate real-time security breaches.

Requirements and Qualifications

Education: Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or a related field (or equivalent professional experience).

Experience: 2 to 5+ years of proven hands-on experience in a dedicated Security Engineering, DevOps Security, or Infrastructure Security role.

Technical Proficiency: Advanced, hands-on experience with Docker containerization and secure image construction (e.g., distroless images, multi-stage builds, rootless execution).

Strong expertise managing and securing Kubernetes ecosystems (managed services like EKS/GKE/AKS or self-hosted).

Deep understanding of cloud-native security tools, service meshes, and runtime security monitoring (e.g., Falco).

Experience with scripting languages (e.g., Python, Bash, or Go) to automate routine security tasks and threat hunting.

Strong expertise in securing public cloud environments (e.g., AWS, Microsoft Azure, or Google Cloud Platform).

Work Arrangement: Ability to work full-time on-site at our designated office location.

Certifications (Preferred but not mandatory): Industry-recognized credentials such as CKS (Certified Kubernetes Security Specialist), CISSP, or OSCP significantly enhance a candidate's profile.

Analytical Thinking: Exceptional problem-solving and troubleshooting skills to dissect complex, fast-moving system anomalies.

Communication: Ability to articulate complex technical security risks and container vulnerabilities clearly to developers and non-technical business stakeholders.

Adaptability: A continuous learner who proactively stays ahead of emerging cloud-native hacking tactics and vulnerabilities.

Unlock the potential of CARPL platform for optimizing radiology workflows
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

CARPL - Radiology AI Platform • New Delhi

On-site
INR 1,000,000 - 1,800,000
Director – Cloud Security Automation
Director – Cloud Security Automation

S&P Global Market Intelligence • Dadri, Gurugram District

On-site
INR 4,000,000 - 7,000,000
DevSecOps Engineer
DevSecOps Engineer

Sutherland Global • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Sr. DevOps Engineer
Sr. DevOps Engineer

GSTSahay • Ahmedabad District

On-site
INR 1,500,000 - 2,300,000
Cyber Security Engineer
Cyber Security Engineer

Recrew AI • Gurugram District

Hybrid
INR 1,400,000 - 2,100,000
Security ownership
Modern stack
Direct influence
DevSecOps Engineer
DevSecOps Engineer

Persistent Systems • Bengaluru

Hybrid
INR 2,500,000 - 4,200,000
Hybrid work environment
Education sponsorship
Long Service awards
+1
Devsecops Engineer
Devsecops Engineer

Capgemini • Mumbai, Bengaluru

Hybrid
INR 1,800,000 - 2,800,000
Security Engineer
Security Engineer

Aynsoft • Delhi

On-site
INR 1,000,000 - 1,500,000
Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

Practice by Numbers • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Lead Security Specialist
Lead Security Specialist

Goodfit • Delhi

On-site
INR 1,800,000 - 2,400,000