Job Description: DevSecOps & Cloud Security Engineer
Location: On-site
Type: Full-time
Experience Level: Mid to Senior (3–5+ years)
About the Role
We are looking for a versatile, hands-on DevSecOps & Cloud Security Engineer to design, automate, and secure our entire technology stack—from local endpoints and office networks to cloud-native delivery pipelines.
In this role, you will be the primary technical owner of our security posture. You will manage our all-Ubuntu developer environment, deploy cost-effective open-source security stack solutions (Keycloak, Wazuh, Gitleaks), and architect secure, scalable cloud infrastructure across AWS, GCP, or DigitalOcean without relying on expensive commercial SaaS security platforms.
Key Responsibilities
1. Cloud Infrastructure & Architecture Security
- Secure Infrastructure design: Architect and manage cloud infrastructure using Infrastructure as Code (IaC) (Terraform/OpenTofu or Ansible).
- Cloud Hardening & PoLP: Enforce strict Principle of Least Privilege across AWS/GCP/Azure IAM policies, cloud network isolation (VPCs, private subnets, security groups), and cryptographic storage management.
- Zero-Trust Cloud Access: Build and maintain secure overlay networks (Headscale / WireGuard) to allow developers secure access to cloud-hosted development and staging environments.
- Container & Kubernetes Security: Hardening and securing containerized microservices (Docker) and orchestration environments (Kubernetes/K3s), ensuring minimal attack surfaces and secure image registries.
2. Identity & Access Management (IAM)
- Self-Hosted Identity: Deploy, scale, and maintain a self-hosted Keycloak identity server for Single Sign-On (SSO), RBAC, and WebAuthn/Passkey MFA across internal services and cloud control panels.
- Network Identity: Configure and integrate FreeRADIUS / 802.1X with our central identity directory to enforce individual user authentication on office Wi-Fi networks.
3. Endpoint & Office Infrastructure Security
- Fleet Management: Manage an all-Ubuntu desktop/laptop environment. Enforce mandatory full-disk encryption (LUKS), local firewalls (UFW), and automated OS security patching (unattended-upgrades).
- SIEM & EDR Operations: Deploy and manage a central Wazuh cluster for security monitoring, file integrity monitoring (FIM), and vulnerability scanning across all Ubuntu endpoints and cloud VMs.
4. CI/CD & Software Supply Chain Security
- DevSecOps Pipeline Integration: Embed automated security tools (Gitleaks, Trivy, OSV-Scanner, or Semgrep) directly into developer pre-commit hooks and GitHub Actions / GitLab CI pipelines.
- Secrets & Vulnerability Management: Prevent credential leaks, eliminate known dependencies vulnerabilities (CVEs) before deployment, and manage automated credential rotation.
Required Technical Skills & Qualifications
- Cloud Proficiency: Deep hands-on experience with at least one major cloud provider (AWS, GCP, or Azure), including VPC design, Cloud IAM, KMS, Object Storage security, and CloudTrail/Audit logging.
- Infrastructure as Code (IaC): Advanced proficiency with Terraform, Ansible, or CloudFormation.
- Linux Mastery: Deep expertise in Ubuntu/Debian system administration, systemd, networking (IPTables/Netfilter/UFW, DNS, TLS/mTLS, SSH hardening), and shell scripting (Bash/Python).
- Open-Source Security Stack: Hands-on experience deploying and operating tools such as Keycloak (OIDC/SAML), Wazuh, Fail2ban, and WireGuard / Headscale.
- CI/CD & Containers: Strong experience with GitHub Actions or GitLab CI, Docker container hardening, and static/dynamic security analysis tools (Gitleaks, Trivy, SonarQube).
Nice-to-Have Skills
- Experience with cloud cost optimization alongside security hardening.
- Familiarity with compliance frameworks (SOC 2 Type II, ISO 27001, GDPR) translated into automated policy-as-code controls.
- Experience configuring network hardware, OPNsense/pfSense firewalls, or FreeRADIUS for 802.1X enterprise Wi-Fi.
Pay: ₹1,000,000.00 - ₹2,200,000.00 per year
Benefits:
- Health insurance
- Life insurance
- Provident Fund
- Work from home
Work Location: In person