Core Solutions (CORE), headquartered in King of Prussia, Pennsylvania, is a leading provider of Electronic Health Record (EHR) solutions specifically designed for the behavioral healthcare industry.
We serve large healthcare providers with comprehensive software solutions that improve patient outcomes and operational efficiency.
With the introduction of our new version and AI solutions, we are positioning ourselves for rapid growth and market expansion.
Position Summary :
We are seeking an experienced Senior DevSecOps Engineer to be part of our technical transformation as we transition to a SaaS-first organization.
This technical role shall be focused on integrating security practices throughout the software development lifecycle, primarily through automation and infrastructure as code.
Senior DevSecOps Engineer shall be responsible for design, implement, and manage secure cloud infrastructure and CI / CD pipelines, ensuring robust security controls and compliance.
This role often involves mentoring junior engineers, leading initiatives, and fostering a culture of continuous :
- Own the security design and implementation of CI / CD pipelines (GitHub Actions, GitHub, Octopus, etc.)
- Design and enforce secure infrastructure-as-code (IaC) patterns (Terraform, Cloudformation).
- Implement policy-as-code frameworks (OPA, Sentinel) across Kubernetes and cloud environments (AWS, GCP, Azure preferably AWS).
- Perform threat modeling and risk assessments across microservices and deployment architecture.
- Drive end-to-end integration of SAST, DAST, SCA, secrets scanning, and container scanning tools into pipelines (e.g, SonarQube, Burpsuite etc).
- Lead initiatives around zero-trust architecture, least privilege IAM automation, and secure baseline enforcement.
- Collaborate with developers, SREs, and product managers to drive a security-first culture.
- Mentor and guide junior DevSecOps and DevOps engineers.
Qualifications :
10+ years of overall experience with over four years in DevOps, Cloud, and Security.Deep expertise in AWS / GCP security services (IAM, KMS, VPC, WAF, Shield, S3, RDS, ECS etc.)Hands-on with IaC and CI / CD (Terraform, Cloudformation etc.)Strong proficiency with scripting (Python, Bash, Powershell, Nodejs etc).Expertise in Container security (Sysdig, SecurityPolicies etc.)Familiar with compliance frameworks (SOC2, HIPAA, NIST etc.) and automating controls.Experience in threat modeling and security risk assessments.Nice to Have :
OSCP, CISSP, AWS Security or GIAC certifications.Experience in building secure SDLC in SaaS-based or multi-tenant platforms.Job Location : Guindy , Chennai.
Work from office 5 days.
Preferred candidates from chennai location.
(ref : hirist.tech)