Senior DevSecOps Engineer
Senior DevSecOps Engineer
Primary focus: Secure software delivery, IAM governance, and security automation
Location: Pune, India
Category | Details |
Function | Production Operations / DevOps |
Reports to | Head of Production Operations |
Global job alignment | DevOps / IT Infrastructure Engineer 4 |
People responsibility | No direct reports |
Employment level / grade | G17 |
Travel | Up to 20% domestic and international travel, as required |
Working model | Hybrid office environment |
General Summary
The Senior DevSecOps Engineer is a hands-on Senior DevOps Engineer with focused responsibility for integrating security into cloud infrastructure, delivery pipelines, developer workflows, and production platform practices across a global technology organization.
The role combines broad AWS, Kubernetes/EKS, Infrastructure as Code, CI/CD, automation, and troubleshooting capability with deep expertise in IAM governance, vulnerability and open-source scanning, static analysis, policy as code, software supply chain security, cloud and container security, and automated compliance evidence.
The job holder enables product teams to deliver securely by translating enterprise requirements into practical, reusable controls rather than relying on manual reviews or end-stage security gates.
The role works closely with Product, Development, Architecture, Security, BISO, Quality, SRE, cloud service owners, and compliance stakeholders, bringing strong communication, sound judgment, and end-to-end ownership.
Primary Duties and Responsibilities
Senior DevOps Engineering Foundation
Design, build, and improve reliable, scalable, and automated AWS, Kubernetes/EKS, Infrastructure as Code, and CI/CD capabilities while applying security as an integrated engineering requirement.
DevSecOps Capability Ownership
Drive practical adoption of secure software delivery practices across product teams, translating enterprise security, architecture, and compliance requirements into reusable engineering controls and implementation patterns.
Secure CI/CD and Policy Enforcement
Embed automated security checks, approvals, evidence, and policy enforcement into GitLab CI/CD and related delivery workflows while keeping controls understandable, maintainable, and proportionate to risk.
Application and Dependency Security
Implement and improve static analysis, software composition and open-source dependency scanning, vulnerability detection, secrets detection, artifact controls, and actionable remediation workflows using approved tools.
Software Supply Chain Security
Strengthen provenance, artifact integrity, dependency governance, build security, access boundaries, and traceability across source, pipeline, registry, deployment, and runtime stages.
IAM Governance and Automation
Engineer reusable IAM patterns, least-privilege controls, role and access lifecycle automation, secrets/configuration management, access reviews, and evidence collection across AWS and delivery platforms.
Cloud, Container, and Infrastructure Security
Implement secure AWS, Kubernetes/EKS, network, workload, container, and Infrastructure as Code patterns, including scanning, hardening, admission controls, policy as code, and remediation automation.
Vulnerability Remediation Enablement
Partner with product teams and security stakeholders to triage findings, clarify ownership and risk, prioritize remediation, remove false-positive noise, track exceptions, and drive high-value actions to verified closure.
Compliance and Audit Readiness
Automate control evidence where practical, improve traceability, support ISO 27001 and related assurance needs, and maintain clear documentation for security controls, exceptions, decisions, and remediation status.
Security Enablement and Influence
Coach engineers, create practical standards and examples, facilitate threat-aware design and secure delivery discussions, and influence teams without becoming a manual approval bottleneck.
Operational Security Partnership
Support investigation and long-term corrective actions for security-related production issues in partnership with SRE, Architecture, Security, and responsible product teams.
Other Duties
Perform other related duties as needed or assigned.
Required Qualifications and Experience
- Bachelor's degree in Computer Science, Software Engineering, Information Technology, or a related technical field, or equivalent practical experience.
- Five or more years of hands-on experience in DevOps, Cloud Engineering, Platform Engineering, Infrastructure Engineering, Software Engineering, or a closely related technical role.
- Strong hands-on experience with AWS services such as EC2, VPC, S3, IAM, RDS/Aurora, Load Balancing, Lambda, and related cloud services.
- Production-level experience with Kubernetes, preferably Amazon EKS, including containerized workloads, networking, security, scalability, upgrades, and operational readiness.
- Strong experience with Infrastructure as Code, preferably Terraform, and infrastructure automation practices.
- Experience designing, building, and improving CI/CD pipelines, preferably GitLab CI/CD, for consistent, secure, and reliable deployments.
- Strong scripting and automation experience in Linux-based or cloud-native environments using Bash, Python, or a similar language.
- Ability to troubleshoot complex infrastructure, application, deployment, networking, security, and operational issues across multiple layers.
- Strong written and verbal English communication skills, including the ability to clarify ambiguity, align stakeholders, document decisions, communicate risk, and influence without formal authority.
- Demonstrated curiosity, ownership, technical judgment, and the ability to balance strategic improvement with hands-on delivery.
- Demonstrated hands-on DevSecOps experience embedding security controls into CI/CD pipelines, cloud infrastructure, container platforms, or developer workflows.
- Strong experience with IAM design and governance, least privilege, access lifecycle controls, secrets management, and security automation in AWS-based environments.
- Experience with static application security testing, software composition analysis, open-source dependency governance, vulnerability management, and secrets detection using enterprise or equivalent tools.
- Experience implementing policy as code, Infrastructure as Code scanning, container or Kubernetes security, and secure software supply chain controls.
- Ability to communicate security risk and remediation expectations clearly to engineers, product stakeholders, architects, and leadership without relying on security jargon or formal authority.
Preferred Qualifications
- Five or more years of experience in DevOps, Cloud, Platform, Infrastructure, Security, or Software Engineering environments.
- Experience working in an enterprise or global organization with distributed teams.
- Experience collaborating with Security, Compliance, Enterprise Architecture, Cloud Platform, SRE, vendor, and product teams.
- Experience with Datadog, CloudWatch, SonarQube/SonarQ, JFrog, Veracode, LaunchDarkly, Helm, Ansible, secrets management, or similar platforms.
- Familiarity with application stacks such as PostgreSQL, .NET, Angular, APIs, or cloud-native microservices.
- Relevant AWS, Kubernetes, Terraform, DevOps, Platform Engineering, or Security certifications.
- Experience mentoring engineers, raising technical standards, and enabling adoption through documentation, coaching, reusable examples, and hands-on collaboration.
- Experience supporting ISO 27001, audit readiness, secure software development lifecycle practices, or regulated environments.
- Experience with Veracode, SonarQube/SonarQ, JFrog, GitLab security capabilities, AWS security services, Open Policy Agent, Gatekeeper, or equivalent tools.
- Familiarity with threat modeling, security architecture reviews, SBOM, artifact signing, provenance, or supply chain security frameworks.
- Relevant Cloud Security, DevSecOps, Application Security, Kubernetes Security, or Information Security certifications.
GCS is acting as an Employment Agency in relation to this vacancy.
Senior DevSecOps Engineer
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- IT Support & Infrastructure
- Engineering
- Controls & Automation
- Data
- Project Management
- BI & Data Analytics
- Network security consultant
- DevOps
- IT Audit & Risk
- Hardware & Electronics
- Testing & QA
- Software Development
LATEST JOBS
- Test Lead
- Senior DevSecOps Engineer
- Product Security Analyst - Vul...
- Application Security Engineer
- Product Owner (Security Cleare...
- Project Manager - Digital & St...
- Controls Technician
- Project Manager - Advertising...
- Project Manager - Ad Sales Cre...
- Fiber Optics Engineer
- Controls Engineer
- machine learning engineer
TOP SEARCHES
LOCATIONS
- Engineer
- Data Scientist
- Senior Data Scientist
- Head of Data Science
- Trainee Data Scientist
- Data Science Graduate
- Senior Financial Accountant
- Management Accountant
- Cost Accountant
- Civil Engineer
- Senior Civil Engineer
- Civil Design Engineer