Talent.com
Careerist management Consultants
Lead DevSecOps EngineerCareerist management Consultants • Delhi, IN
Lead DevSecOps Engineer

Lead DevSecOps Engineer

Careerist management Consultants • Delhi, IN
30+ days ago
Job description

Job Description :


We are seeking a highly skilled and experienced Lead DevSecOps Engineer to drive the organization's DevSecOps transformation by embedding security across the software development lifecycle (SDLC).

The ideal candidate will possess deep expertise in CI/CD automation, cloud security, Infrastructure as Code (IaC), container security, Kubernetes, and vulnerability management.

As a Lead DevSecOps Engineer, you will be responsible for designing and implementing secure, scalable, and automated platforms that enable development teams to deliver applications rapidly while maintaining the highest security standards.

You will work closely with Development, Security, Infrastructure, Cloud, and Compliance teams to establish security best practices and ensure adherence to organizational and regulatory requirements.

Key Responsibilities :

- Lead the adoption and implementation of DevSecOps practices across enterprise applications.

- Define security standards, policies, and best practices for CI/CD pipelines and cloud-native environments.

- Mentor DevOps and engineering teams on secure development and deployment practices.

- Drive security automation initiatives to reduce manual intervention and improve delivery efficiency.

- Design, develop, and maintain secure CI/CD pipelines using Jenkins, GitHub Actions, or GitLab CI.

- Integrate security testing tools into CI/CD workflows, including :

1. Static Application Security Testing (SAST)

2. Dynamic Application Security Testing (DAST)

3. Software Composition Analysis (SCA)

- Implement security gates and policy enforcement mechanisms within deployment pipelines.

- Automate security validation before code promotion to higher environments.

Cloud Security & Infrastructure Automation :

- Design and implement secure cloud architectures on AWS, Azure, or GCP.

- Develop Infrastructure as Code (IaC) solutions using Terraform.

- Enforce cloud security best practices, including :

1. Identity & Access Management (IAM)

2. Security Monitoring and Logging

- Build automated compliance and security monitoring frameworks.

Container & Kubernetes Security :

- Implement security controls for Docker containers and Kubernetes environments.

1. RBAC

2. Network Policies

3. Pod Security Standards

4. Secrets Management

5. Runtime Protection

- Conduct container image vulnerability assessments and remediation.

- Automate container security scanning and compliance validation.

Security Tool Integration :

- Integrate and manage security tools such as SonarQube, Checkmarx, Snyk, HashiCorp Vault, Dependency Scanners, and Container Security Platforms.

- Ensure continuous monitoring and reporting of security vulnerabilities.

- Automate remediation workflows wherever feasible.

- Establish vulnerability management processes across applications, infrastructure, and cloud environments.

- Analyze security findings, prioritize remediation activities, and track closure.

- Collaborate with governance and compliance teams to meet regulatory requirements.

- Support security audits, penetration testing, and compliance assessments.

- Implement monitoring and alerting solutions for infrastructure and security events.

- Develop automated incident detection and response workflows.

- Participate in root cause analysis and post-incident reviews.

- Improve platform resilience and operational security.

Required Technical Skills :

- CI/CD & Automation : Jenkins, GitHub Actions, GitLab CI/CD, and CI/CD Security Best Practices.

- Cloud Platforms : AWS / Azure / GCP, Cloud Security Architecture, IAM, Security Groups, and Network Security.

- Infrastructure as Code : Terraform, Infrastructure Automation, and Configuration Management.

- Containers & Orchestration : Docker, Kubernetes, Helm, and Container Security.

- Security Tools : SonarQube, Checkmarx, Snyk, OWASP Dependency Check, and HashiCorp Vault.

- Programming & Scripting : Python, Bash/Shell Scripting, and Automation Development.

- Security Concepts : DevSecOps, Application Security, Cloud Security, Secure SDLC, Threat Modeling, Vulnerability Assessment & Management, Secrets Management, and Compliance & Governance.

- Experience with service mesh technologies (Istio, Linkerd).

- Knowledge of security frameworks such as NIST, CIS Benchmarks, ISO 27001, SOC2.

- Experience with SIEM and security monitoring solutions.

- Exposure to Kubernetes security tools like Trivy, Falco, Aqua Security, Prisma Cloud, or Wiz.

- Experience implementing Zero Trust Security principles.

- Bachelor's or Master's degree in Computer Science, Information Technology, Cyber Security, or related field.

- 9 to 15 years of overall IT experience.

- Minimum 5+ years of hands-on experience in DevOps/DevSecOps engineering.

- Strong experience securing cloud-native applications and enterprise platforms.

(ref:hirist.tech)
Create a job alert for this search

Lead DevSecOps Engineer • Delhi, IN

Similar jobs

Senior Full Stack Engineer

BOLTIndia, Delhi, IN

Full-Stack Development: Design, develop, and maintain backend services in Go and frontend applications in TypeScript to power Bolt’s checkout and merchant dashboard experiences.Merchant Dashboard O... Show more

Senior IT Engineer

BOLTIndia, Delhi, IN

In this role, you'll be a cornerstone of our IT operations, acting as the second line of support for complex technical issues and taking ownership of our core IT systems.We're seeking an engineer w... Show more