Role Overview
We are seeking a DevSecOps / Cloud Security Engineer to embed security across our cloud infrastructure, container platforms, and CI/CD pipelines. In this role, you will lead our application security initiatives (SAST, DAST, SCA), enforce policy-as-code across Kubernetes, manage cloud identity and secrets, and coordinate vulnerability management (VAPT). You will bridge the gap between development and security, ensuring compliance with standards like ISO 27001 and DPDP while securing our AWS and containerized environments.
Key Responsibilities
Application & Pipeline Security (AppSec / CI/CD)
Integrate automated security scanning into GitLab CI pipelines using SonarQube (SAST), OWASP ZAP (DAST), and Trivy / Grype / Syft (SCA & Container scanning).
Enforce container and image security using Cosign for image signing and verification.
Track security remediations, assist developers in fixing code vulnerabilities (OWASP Top 10), and coordinate third-party VAPT audits.
Cloud Security & Identity (AWS)
Design, enforce, and audit cloud identity controls using AWS IAM, least-privilege policies, and AWS Directory Services/SSO.
Manage application secrets and cryptographic keys using AWS Secrets Manager, AWS KMS, and HashiCorp Vault.
Monitor and analyze threat telemetry across AWS Security Hub, GuardDuty, Inspector, CloudTrail, and CloudWatch Logs integrated into SIEM platforms.
Oversee PKI, SSL/TLS certificate lifecycles, and automated renewals using AWS ACM and Vault.
Kubernetes & Infrastructure Hardening
Implement policy-as-code and governance in Kubernetes using Kyverno or OPA/Gatekeeper.
Enforce Kubernetes RBAC, Pod Security Standards, and Linux host hardening best practices across Docker nodes and cloud workloads.
Ensure compliance alignment with ISO 27001 security controls and India DPDP (Digital Personal Data Protection) data privacy guidelines.