DevSecOps Engineer
Agency Job via JusRecruit
Agency Job via JusRecruit
About the job
Position: DevSecOps Engineer
Location: Gurgaon
Work Experience- 3- 5 years
Job Description: We are looking for a passionate and skilled DevSecOps Engineer with 3+ years of experience in DevOps and cloud security practices. The ideal candidate should have hands-on experience in implementing security across CI/CD pipelines, cloud infrastructure, containerized environments, and application deployments. The role involves integrating security into every stage of the software development lifecycle (SDLC) while ensuring scalable, reliable, and secure deployments.
Key Responsibilities:
● Implement and maintain secure CI/CD pipelines.
● Integrate security controls into DevOps processes and workflows.
● Perform vulnerability assessments and security scans on applications, containers, and infrastructure.
● Automate security testing within build and deployment pipelines.
● Monitor cloud environments and ensure adherence to security best practices.
● Collaborate with Development, QA, and Infrastructure teams to remediate security vulnerabilities.
● Configure and manage IAM policies, access controls, and secrets management.
● Support compliance initiatives and security audits.
● Monitor, investigate, and respond to security incidents.
● Implement Infrastructure as Code (IaC) security best practices.
● Ensure secure containerization and Kubernetes deployments.
Required Skills:
AWS/Azure/GCP, CI/CD (Jenkins, GitHub Actions, GitLab CI/CD), Docker, Kubernetes, Linux Administration, Shell Scripting, Application Security (AppSec), Vulnerability Management, OWASP Top 10, Security Testing (SAST/DAST), Container Security, Cloud Security, Identity & Access Management (IAM), Secrets Management, Terraform, CloudFormation (Good to Have), SonarQube, Snyk, Trivy, OWASP ZAP, Checkmarx, Veracode, Aqua Security, Prisma Cloud, ELK Stack, Grafana, Prometheus, CloudWatch.
Preferred Qualifications:
● Bachelor's degree in Computer Science, Information Technology, or related field.
● Experience working in Agile/Scrum environments.
● Understanding of Secure SDLC principles.
● Knowledge of security compliance standards such as ISO 27001, SOC 2, PCI-DSS, or GDPR.
Mandatory Skills: DevSecOps | AWS | Azure | GCP | Jenkins | GitHub Actions | GitLab CI/CD | Docker | Kubernetes | Terraform | SonarQube | Snyk | Trivy | OWASP | IAM | Cloud Security | Container Security | Linux | CI/CD | Vulnerability Management.