Job Title: Principal DevSecOps Engineer/Architect
Experience: 8-10 Years
Location: Hyderabad, India (On-site)
We are seeking a Principal DevSecOps Engineer/Architect with deep expertise in Terraform, Atlantis, and large-scale multi-cloud environments (200–300+ accounts/subscriptions). This is a client-facing consulting role, responsible for designing and governing secure, scalable infrastructure and CI/CD platforms across enterprise environments.
This role goes beyond implementation, you will define standards, governance models, and automation frameworks for large organizations operating at scale.
Architect and standardize end-to-end DevSecOps platforms
Design secure, scalable CI/CD pipelines using Jenkins & GitHub Actions
Embed security gates (SAST, DAST, SCA, container security) into pipelines
Define reusable pipeline templates across multiple teams/business units
Design and manage large-scale Terraform architecture across 200–300+ cloud accounts
Implement Terraform modules, remote backends, and state isolation strategies
Build and manage Atlantis workflows for automated Terraform plan/apply
Enforce:
Code reviews & approvals for infra changes
Policy-as-code (OPA / Sentinel)
Drift detection & remediation
Architect multi-cloud landing zones and governance frameworks
Manage large account structures:
AWS Organizations (multi-account strategy)
Azure Management Groups / Subscriptions
Implement:
Network segmentation (VPC/VNet design)
Identity federation (SSO, IAM, RBAC)
Cross-account access models
Ensure high availability, scalability, and cost optimization
Implement DevSecOps controls aligned with SOC 2, PCI-DSS, GDPR
Integrate tools like:
JFrog Xray (SCA)
SonarQube (SAST)
Trivy / Prisma / Wiz (container & cloud security)
Build policy-as-code frameworks for compliance enforcement
Automate evidence collection for audits
Architect secure artifact lifecycle using JFrog Artifactory
Implement access control, immutability, and vulnerability scanning
Standardize dependency management across teams
Implement centralized logging/monitoring:
CloudWatch, ELK, Prometheus/Grafana
Define SLOs/SLIs for platform reliability
Reduce MTTR via automation and alerting
Act as a trusted advisor to enterprise clients
Lead architecture discussions and DevSecOps transformation programs
Mentor teams and enforce engineering best practices
Drive platform adoption across multiple business units
Terraform (Expert level)
Atlantis (Hands-on implementation at scale)
Strong experience with multi-account architecture (200–300+ accounts)
Jenkins (advanced pipelines)
GitHub Actions (enterprise workflows)
GitOps practices
AWS (Expert) – Organizations, IAM, VPC, Security services
Experience with Azure or GCP (multi-cloud exposure required)
SAST, DAST, SCA tools integration
Container security & Kubernetes security
Secrets management (Vault / AWS Secrets Manager)
Python / Bash (automation focus)
Experience with Kubernetes (EKS/AKS/GKE) at scale
Knowledge of Zero Trust Architecture
Experience with OPA / Sentinel (policy-as-code)
Familiarity with platform engineering concepts (Internal Developer Platforms)
AWS Solutions Architect – Professional
Terraform Associate / Advanced Terraform certifications
CISSP / CKS (Kubernetes Security)
Ownership of large-scale (200–300 account) cloud environments
Direct impact on enterprise DevSecOps maturity
Client-facing architecture & strategy role (not just execution)
Opportunity to define organization-wide standards