We are looking for a **security-focused DevSecOps Engineer with 1-2 years of experience** to help embed security across the software development lifecycle while maintaining deployment speed, platform reliability, and compliance.
This role will work closely with engineering, infrastructure, and security teams to strengthen CI/CD security, cloud governance, infrastructure automation, vulnerability management, monitoring, and secure deployment practices.
**Roles and Responsibilities**
Secure DevOps & CI/CD
* Build, maintain, and optimize secure CI/CD pipelines for reliability, speed, and controlled releases.
* Implement **shift-left security** by integrating security checks early in the development lifecycle.
* Configure automated quality, vulnerability, and security gates within release pipelines.
* Support secure, zero-downtime deployment strategies and rollback mechanisms.
* Ensure release workflows follow secure SDLC and change-management practices.
Cloud and Infrastructure Security
* Manage and secure cloud environments across AWS, GCP, or Azure.
* Develop and maintain Infrastructure-as-Code using Terraform.
* Package and deploy applications to Kubernetes using Helm.
* Implement cloud security controls, including IAM policies, least-privilege access, network segmentation, and secure configuration management.
* Strengthen Docker and Kubernetes security, including image hardening, access controls, and workload protection.
Application and Platform Security
* Integrate SAST, DAST, SCA, container scanning, and vulnerability assessment tools into CI/CD pipelines.
* Track vulnerabilities, coordinate remediation, and ensure closure within defined timelines.
* Implement secure secrets management, certificate management, and encryption practices.
* Participate in application, infrastructure, and architecture security reviews.
* Support security testing and remediation across applications and platforms.
Compliance, Monitoring and Incident Readiness
* Support compliance with frameworks such as ISO 27001, SOC 2, PCI-DSS, and other regulatory requirements.
* Maintain centralized security logging, monitoring, alerting, and audit trails.
* Track security posture, vulnerabilities, access reviews, and compliance metrics.
* Support incident response readiness, security investigations, and remediation activities.
* Maintain documentation required for audits, risk assessments, and compliance reviews.
Automation and Reliability
* Automate repetitive infrastructure, deployment, and security processes.
* Improve observability through effective logging, monitoring, alerting, and dashboards.
* Support disaster recovery, backup validation, resilience testing, and business continuity initiatives.
* Collaborate with SRE and platform teams to improve availability, scalability, and operational security.
Required Qualifications
* **1-2 years of experience** in DevSecOps, DevOps, Cloud Security, SRE, or a related role.
* Hands-on experience with at least one cloud platform: AWS, GCP, or Azure.
* Strong working knowledge of Terraform for Infrastructure-as-Code.
* Hands-on experience with Kubernetes, Docker, and Helm.
* Experience with CI/CD tools such as Jenkins, GitHub Actions, GitLab CI, Azure DevOps, or similar platforms.
* Practical understanding of DevSecOps, secure SDLC, vulnerability management, and security automation.
* Experience integrating or working with SAST, DAST, SCA, container scanning, or vulnerability management tools.
* Understanding of IAM, least-privilege access, network security, secrets management, and encryption.
* Proficiency in at least one scripting or programming language, such as Python, Go, or Bash.
* Ability to collaborate with engineering teams and drive timely closure of security issues.
Good to Have
* AWS, GCP, Azure, Kubernetes, CKA, or CKAD certification.
* Exposure to ISO 27001, SOC 2, PCI-DSS, HIPAA, or similar compliance frameworks.
* Experience working in healthcare, fintech, or another regulated industry.
* Familiarity with SIEM, CSPM, WAF, cloud-native security tools, and incident-response processes.
* Experience with tools such as SonarQube, Snyk, Trivy, Checkmarx, Veracode, OWASP ZAP, or similar platforms.
Visa sponsorship is not available for this role.