2coms
DevSecOps/Secure DevOps Engineer (Kolkata/Hyderabad)
Kolkata, INSur siteCDITemps plein
Publié 27 août 2026
Cet emploi est publié en EN
DevSecOps/Secure DevOps Engineer
About the Role:
We are hiring a hands-on Secure DevOps Engineer to build and secure AWS environments, automate deployments, and own CI/CD, infrastructure as code, containerized workloads, monitoring, and vulnerability remediation across development, UAT, and production. You'll integrate security into delivery pipelines, independently troubleshoot issues, and drive remediation to closure.
Location: Kolkata/Hyderabad
Key Responsibilities
• Build and manage secure AWS infrastructure using EC2, VPC, IAM, S3, RDS, ECR/EKS, ALB, Route 53, CloudWatch, KMS, and related services.
• Design and maintain CI/CD pipelines using Jenkins, GitLab CI, GitHub Actions, or equivalent.
• Manage controlled deployments across Dev/UAT/Production, including configuration management, rollback, and release support.
• Implement Terraform-based Infrastructure as Code with secure state management and version-controlled changes.
• Secure AWS environments using least-privilege IAM, network controls, encryption, secrets management, logging, WAF, CloudTrail, GuardDuty, and Security Hub.
• Manage Docker and Kubernetes/EKS workloads, including image security, RBAC, secrets, and workload access.
• Integrate SAST, DAST, SCA, secrets scanning, IaC scanning, and container vulnerability scanning into CI/CD pipelines.
• Identify, prioritize, remediate, retest, and close Critical/High vulnerabilities and VAPT findings.
• Monitor application infrastructure, troubleshoot deployment/infrastructure incidents, and improve availability and observability.
• Review existing environments for configuration drift, excessive access, exposed services, insecure credentials, manual deployment risks, and monitoring gaps.
• Manage Linux administration, DNS/SSL, backup/recovery, and incident troubleshooting across environments.
• Support VAPT, security reviews, ISO 27001/SOC 2 evidence, technical questionnaires, and client audits.
• Strong practical AWS infrastructure and security experience.
• Hands-on Terraform/Infrastructure-as-Code experience.
• Strong CI/CD and deployment automation experience.
• Hands-on Docker and Kubernetes/EKS experience (practical working knowledge; deep platform engineering only where EKS is a core production dependency).
• Working knowledge of SAST, DAST, SCA, secrets, IaC, and container scanning.
• Experience with SonarQube, Trivy, OWASP ZAP, or equivalent tools.
• Good Linux administration and Bash/Python scripting skills.
• Git/GitLab or equivalent source-control experience.
• Strong troubleshooting, incident handling, vulnerability remediation, deployment rollback, secrets handling, and communication skills
Good to Have
• Azure security exposure such as Defender for Cloud, Entra ID/Azure AD, and Key Vault.
• ISO 27001, SOC 2, or similar compliance exposure.
• AWS, Kubernetes, Terraform, or Security certifications.
• Experience with backup/restore, disaster recovery, and cost optimization.
About the Role:
We are hiring a hands-on Secure DevOps Engineer to build and secure AWS environments, automate deployments, and own CI/CD, infrastructure as code, containerized workloads, monitoring, and vulnerability remediation across development, UAT, and production. You'll integrate security into delivery pipelines, independently troubleshoot issues, and drive remediation to closure.
Location: Kolkata/Hyderabad
Key Responsibilities
• Build and manage secure AWS infrastructure using EC2, VPC, IAM, S3, RDS, ECR/EKS, ALB, Route 53, CloudWatch, KMS, and related services.
• Design and maintain CI/CD pipelines using Jenkins, GitLab CI, GitHub Actions, or equivalent.
• Manage controlled deployments across Dev/UAT/Production, including configuration management, rollback, and release support.
• Implement Terraform-based Infrastructure as Code with secure state management and version-controlled changes.
• Secure AWS environments using least-privilege IAM, network controls, encryption, secrets management, logging, WAF, CloudTrail, GuardDuty, and Security Hub.
• Manage Docker and Kubernetes/EKS workloads, including image security, RBAC, secrets, and workload access.
• Integrate SAST, DAST, SCA, secrets scanning, IaC scanning, and container vulnerability scanning into CI/CD pipelines.
• Identify, prioritize, remediate, retest, and close Critical/High vulnerabilities and VAPT findings.
• Monitor application infrastructure, troubleshoot deployment/infrastructure incidents, and improve availability and observability.
• Review existing environments for configuration drift, excessive access, exposed services, insecure credentials, manual deployment risks, and monitoring gaps.
• Manage Linux administration, DNS/SSL, backup/recovery, and incident troubleshooting across environments.
• Support VAPT, security reviews, ISO 27001/SOC 2 evidence, technical questionnaires, and client audits.
Requirements
• 4-6 years of hands-on DevSecOps experience.• Strong practical AWS infrastructure and security experience.
• Hands-on Terraform/Infrastructure-as-Code experience.
• Strong CI/CD and deployment automation experience.
• Hands-on Docker and Kubernetes/EKS experience (practical working knowledge; deep platform engineering only where EKS is a core production dependency).
• Working knowledge of SAST, DAST, SCA, secrets, IaC, and container scanning.
• Experience with SonarQube, Trivy, OWASP ZAP, or equivalent tools.
• Good Linux administration and Bash/Python scripting skills.
• Git/GitLab or equivalent source-control experience.
• Strong troubleshooting, incident handling, vulnerability remediation, deployment rollback, secrets handling, and communication skills
Good to Have
• Azure security exposure such as Defender for Cloud, Entra ID/Azure AD, and Key Vault.
• ISO 27001, SOC 2, or similar compliance exposure.
• AWS, Kubernetes, Terraform, or Security certifications.
• Experience with backup/restore, disaster recovery, and cost optimization.
Aperçu du poste
Type de poste
Temps plein
Compétences requises
AWS infrastructure and security (EC2, VPC, IAM, S3, RDS, ECR/EKS, ALB, Route 53, CloudWatch, KMS)Terraform / Infrastructure-as-Code with secure state managementCI/CD pipeline design and automation (Jenkins, GitLab CI, GitHub Actions)Docker containerization and image securityKubernetes/EKS operations, RBAC, and workload managementSecrets management and encryption (KMS, secrets handling)Security scanning and integration (SAST, DAST, SCA, IaC scanning, container scanning)Vulnerability remediation and VAPT handling (identify, prioritize, remediate, retest, close)Monitoring, observability and incident troubleshooting (CloudWatch, alerts, availability)Linux system administration and Bash/Python scriptingGit and source-control workflows (GitLab, Git)Compliance and audit support (ISO 27001, SOC 2 evidence, client audits)Azure security exposure (Defender for Cloud, Entra ID/Azure AD, Key Vault)
Emplois similaires
Senior Agentic AI Engineer ID80140
AgileEngine
Kolkata, INSur siteCDITemps plein
il y a 19 heures
Lead Agentic AI Engineer ID80141
AgileEngine
Kolkata, INSur siteCDITemps plein
il y a 19 heures
Electrical Engineer
2coms
Kolkata, INSur siteCDITemps plein
il y a 23 heures
Drilling Assistant / Civil Engineer
2coms
Kolkata, INSur siteCDITemps plein
il y a 23 heures
Automotive painter
2coms
Kolkata, INSur siteCDITemps plein
hier
Salesforce Developer ID85151
AgileEngine
Kolkata, INSur siteCDITemps plein
hier