Talent.com
DevSecOps

DevSecOps

ConfidentialMumbai
30+ days ago
Job description
  • Compliance and Governance
  • Compliance Standards :
  • Ensure adherence to GDPR, HIPAA, PCI DSS, and other standards.
  • Maintain audit trails with AWS CloudTrail and Bitbucket Activity Logs.
  • Vulnerability Assessment, Penetration Testing (VAPT), and Hardening
  • Assessments : Perform regular vulnerability assessments on AWS resources using tools like AWS Inspector, Nessus, or Qualys.
  • Service Hardening : Apply AWS best practices to secure services like EC2, RDS, and S3.
  • Encryption : Implement encryption in transit and at rest using AWS KMS and SSL / TLS.
  • Infrastructure Security
  • Cloud Security :

    • Use AWS services (Security Hub, GuardDuty, CloudTrail) and GCP tools (Security Command Center, IAM) to harden cloud environments.
    • Automate infrastructure deployment with Terraform or AWS CloudFormation, ensuring security best practices.
    • Scan IaC using Checkov, Terrascan, or AWS Config Rules.
    • Application Security
    • SAST and DAST :
    • Perform SAST during development to identify vulnerabilities early.
    • Conduct DAST in staging or production using tools like Burp Suite, OWASP ZAP, or AppScan.
    • Android Security :
    • Test Android apps using tools like MobSF, QARK, or Drozer.
    • Ensure compliance with OWASP MSTG standards.
    • Ethical Hacking and Ransomware Testing
    • Ransomware Simulation : Simulate ransomware attacks to test recovery capabilities and data resiliency.
    • Ethical Hacking : Perform ethical hacking exercises to assess system vulnerabilities and identify potential breaches
    • Threat Analysis Threat Modeling :
    • Conduct regular threat analysis to evaluate potential risks to cloud infrastructure and applications.
    • Create and maintain threat models for applications, services, and infrastructure to identify attack vectors and mitigation strategies.
    • Use tools like Microsoft Threat Modeling Tool, OWASP Threat Dragon, or custom modeling techniques to identify and prioritize risks.
    • Code Scanning :
    • Use Bitbucket Code Insights for integrated security scan results in PRs.
    • Monitor repositories for exposed credentials or sensitive data.
    • Automate IaC scanning with tools like Checkov.
    • CI / CD and Code Security
    • Secure Pipelines :
    • Integrate Bitbucket Pipelines with AWS services for secure deployments.
    • Automate security checks at each pipeline stage :
    • SAST (Static Application Security Testing) : Use tools like SonarQube.
    • DAST (Dynamic Application Security Testing) : Use tools like OWASP ZAP or Burp Suite.
    • Dependency scanning using tools like OWASP Dependency-Check.
    • Container security scanning for Docker images.
    • Code Scanning :
    • Use Bitbucket Code Insights for integrated security scan results in PRs.
    • Monitor repositories for exposed credentials or sensitive data.
    • Automate IaC scanning with tools like Checkov.
    • WSO2 API Manager Responsibilities
    • API Security :
    • Secure APIs with OAuth2, JWT tokens, and mutual TLS.
    • Implement rate-limiting and throttling to prevent abuse.
    • Integrate APIs with AWS Cognito or other identity providers for authentica
    • Monitoring and Incident Response
    • Monitoring :
    • Use AWS CloudWatch, GuardDuty, and Bitbucket monitoring features.
    • Configure proactive alerts using PagerDuty or Slack for Bitbucket Pipelines.
    • Incident Response :
    • Automate incident response workflows using AWS Systems Manager or AWS Lambda.
    • Conduct regular incident response drills.
    • AWS IAM (Identity and Access Management)
    • Policy Design : Create and enforce least privilege access policies.
    • Audits : Conduct regular audits of IAM roles, groups, and policies to ensure compliance and security.
    • Federated Identity : Configure and manage federated identity with external IdPs (e.g., Okta, Azure AD).
    • Bitbucket Roles and Responsibilities
    • Version Control Security :
    • Manage repository access using roles (Admin, Developer, Read-Only).
    • Enforce branch protection rules for PR reviews.
    • Secure sensitive data using Bitbucket Pipelines environment variables.
    • CI / CD Pipeline Integration :
    • Integrate Bitbucket Pipelines with security tools like SonarQube or Checkmarx.
    • Automate dependency vulnerability checks.
    • Use pre-commit hooks for code quality and security validation.
    • Job Requirement

      Key Tools and Technologies

      Category

      Tools

      Compliance and Governance

      GDPR, HIPAA, PCI DSS / AWS CloudTrail and Bitbucket Activity Logs

      Vulnerability Assessment, Penetration Testing (VAPT), and Hardening

      VAPT

      Infrastructure Security

      AWS services

      Application Security

      SAST / DAST

      Ethical Hacking and Ransomware Testing

      ransomware attacks / system vulnerabilities

      Threat Analysis Threat Modeling

      applications, services, and infrastructure

      Code Scanning

      SonarQube, Checkmarx, OWASP ZAP

      Source Control

      Bitbucket, Git

      CI / CD

      Bitbucket Pipelines, Jenkins, GitLab CI / CD

      Cloud Security

      AWS Security Hub, GuardDuty, GCP Security

      API Management

      WSO2 API Manager, AWS API Gateway

      Skills Required

      cd, Api Management, Cloud Security, SAST, Ci, Threat Analysis, Ethical Hacking

    Create a job alert for this search

    DevSecOps • Mumbai

    Related jobs
    • Promoted
    DevOps Manager

    DevOps Manager

    WorkGeek ServicesMumbai, India
    The purpose of this job is to define and own the overall cloud infrastructure as well as the devops.This includes designing, deploying, and maintaining cloud-based systems.Job Context & Major Chall...Show moreLast updated: 4 days ago
    • Promoted
    Lead DevOps Engineer

    Lead DevOps Engineer

    AptEdgeMumbai, IN
    AptEdge delivers Agentic Technical Support for B2B Enterprises.Our AI-powered Answer Engine, unlike traditional search engines, utilizes natural language processing to provide contextually relevant...Show moreLast updated: 7 days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    Exosphere Interactive LLPmumbai, maharashtra, in
    In this role, you’ll ensure smooth and scalable deployment of real-time systems like matchmaking, player data, analytics, and live events. You’ll design cloud infrastructure that can survive traffic...Show moreLast updated: 5 days ago
    • Promoted
    Principal GCP Devops

    Principal GCP Devops

    inventurus knowledge solnthane, maharashtra, in
    We are seeking a highly experienced and hands-on.DevOps Subject Matter Expert (SME).CI / CD pipelines, cloud-native architectures, MLOps frameworks, and DevSecOps practices.The ideal candidate will b...Show moreLast updated: 29 days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    Alp Consulting Ltd.mumbai city, maharashtra, in
    Good knowledge of AWS technologies including EC2, ECS / EKS (Docker containers), RDS, S3, Lambda, CloudHSM.Cloud stack deployment & upgrade using CloudFormation / Terraform.REST end point development...Show moreLast updated: 26 days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    IntraEdgeKalyan-Dombivli, IN
    Seeking a skilled DevOps Engineer with strong expertise in Amazon Web Services (AWS) to join the engineering team.In this role, you will design, implement, and maintain infrastructure that enables ...Show moreLast updated: 30+ days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    SID Global Solutionsnavi mumbai, maharashtra, in
    Job Description : DevOps Engineer.Design, implement, and maintain CI / CD pipelines to automate build, test, and deployment processes across multiple client projects. Develop and manage infrastructure ...Show moreLast updated: 24 days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    Turgajo Technologies Pvt. Ltd.Kalyan-Dombivli, IN
    We are a product-based company, on a mission to capitalize on the evolution of new technologies and the new opportunities they present. We develop cutting-edge software solutions for the service ind...Show moreLast updated: 30+ days ago
    • Promoted
    Senior / Lead Engineer - DevOps (AWS / Azure / GCP)

    Senior / Lead Engineer - DevOps (AWS / Azure / GCP)

    QBurstmumbai city, maharashtra, in
    We are seeking an experienced and versatile DevOps Engineer.The ideal candidate will have hands-on experience with CI / CD pipelines, Kubernetes, Linux systems, monitoring / logging tools, and Infrastr...Show moreLast updated: 21 days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    go4WorldBusiness.com - Import | Export | Trade | Worldwide.mumbai city, maharashtra, in
    If you love writing scripts more than clicking around dashboards, this role is for you.You’ll be responsible for managing and improving our AWS-based infrastructure, CI / CD pipelines, and monitoring...Show moreLast updated: 7 days ago
    • Promoted
    DevSecOps

    DevSecOps

    CapgeminiMumbai, IN
    Proficiency in securing CI / CD workflows using Github Actions, with hands-on experience designing, implementing, and maintaining automated pipelines. Strong expertise in integrating security measures...Show moreLast updated: 1 day ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    Bipolar FactoryThane, IN
    We’re a team of builders, designers, and problem-solvers using .From automating textile and retail workflows to crafting next-gen tools that push industries forward, we help businesses do more with...Show moreLast updated: 5 days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    NCR Atleosmumbai city, maharashtra, in
    Design, maintain, and optimize CI / CD pipelines using GitHub Actions with a focus on automation and AI-driven insights.Implement and manage Infrastructure as Code (IaC) using Terraform across Azure ...Show moreLast updated: 7 days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    Trackkmumbai, maharashtra, in
    Job Title : DevOps Engineer (4-6 Years Experience – Servers & AWS).Location : [Remote / On-Site / Hybrid].You will be responsible for deploying and maintaining scalable systems, automating infrastruc...Show moreLast updated: 1 day ago
    • Promoted
    Technical Lead - DevSecOps

    Technical Lead - DevSecOps

    Infosys Finaclenavi mumbai, maharashtra, in
    Role : DevSecOps Developer – Secure Coding & Automation.Strong scripting skills in Python, Shell, or similar languages for automation and tooling. Should be able to design, develop, test, and deploy...Show moreLast updated: 7 days ago
    • Promoted
    Senior DevOps Engineer

    Senior DevOps Engineer

    Elestiothane, maharashtra, in
    Elestio is growing, and we’re looking for a DevOps Expert to join our team!.To support our fast growth, we’re looking for someone passionate about DevOps, open-source technologies, and customer suc...Show moreLast updated: 30+ days ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    Interview KickstartThane, IN
    Interviews can be hard, especially at top tech companies like Google, Facebook, and Netflix.Many candidates fall short simply because they aren’t adequately prepared. Our acclaimed courses specializ...Show moreLast updated: 1 day ago
    • Promoted
    DevOps Engineer

    DevOps Engineer

    AccoladeMumbai, IN
    The multifamily real estate industry is undergoing a massive transformation, and Accolade is at the forefront.We are building the industry's first AI-native Operations Centralization Platform, desi...Show moreLast updated: 30+ days ago