
DevSecOps Engineer
Sutherland4 days ago
Remote, India or Hyderābād, IndiaSenior
Responsibilities
- Own cloud security posture management across GCP and AWS, including continuous assessment, misconfiguration detection, remediation tracking, IAM, service accounts, workload identity, network controls, secrets, and attack-surface reduction.
- Lead cloud and Kubernetes security incident response, including triage, containment, investigation, and remediation.
- Harden GKE and Kubernetes clusters with CIS benchmarks, pod security standards, admission controls, network policies, RBAC, runtime security, and container supply-chain protections.
- Secure GitLab CI/CD pipelines through runner and permission hardening, branch protection, merge-request approvals, integrated security scanning, token hygiene, and organization-wide policy-as-code.
- Implement Terraform IaC security scanning with tfsec and Checkov as mandatory pipeline gates.
- Maintain endpoint, WAF, Cloud Armor, TLS, bastion host, DNS, VPN/interconnect, and private service security controls.
- Own SOC 2, HIPAA, and ISO 27001 compliance reporting, evidence collection, gap analysis, and control implementation.
- Build security automation and observability using policy enforcement, vulnerability remediation as code, Datadog dashboards, alert tuning, and incident runbooks.
- Conduct threat modeling, architecture risk assessments, secure code reviews, security reviews, and security training and awareness.
Requirements
- 7+ years of experience in DevSecOps, cloud security, or infrastructure security engineering.
- Deep hands-on experience securing production Kubernetes clusters, including RBAC, network policies, pod security, and runtime protection.
- Proven experience with GCP and/or AWS security services and IAM design.
- Strong CI/CD security knowledge, including pipeline hardening, secrets management, and integrated scanning.
- Experience internalizing service endpoints and reducing cloud attack surface.
- Familiarity with HIPAA, SOC 2, or ISO 27001 compliance in regulated environments.
- Clear communication skills, including explaining critical vulnerabilities to a CTO and writing engineering runbooks.
- Preferred: Certified Kubernetes Security Specialist, Google Professional Cloud Security Engineer, or AWS Security Specialty certification.
- Preferred: experience with eBPF-based security tooling such as Cilium or Tetragon, penetration testing, red teaming, STRIDE or PASTA threat modeling, or service mesh security beyond Istio.