We are looking for a highly skilled Cloud & DevSecOps Engineer to strengthen the security, reliability, and scalability of our cloud infrastructure while safeguarding the organization's digital assets and data. In this role, you will be responsible for securing our cloud environments, applications, CI/CD pipelines, networks, and infrastructure against evolving cyber threats. You will work closely with engineering, IT, and product teams to embed security throughout the software development lifecycle while ensuring high availability and operational excellence.
Kolkata (Rajarhat-New Town)
We are looking for a highly skilled Cloud & DevSecOps Engineer to strengthen the security, reliability, and scalability of our cloud infrastructure while safeguarding the organization's digital assets and data.
In this role, you will be responsible for securing our cloud environments, applications, CI/CD pipelines, networks, and infrastructure against evolving cyber threats. You will work closely with engineering, IT, and product teams to embed security throughout the software development lifecycle while ensuring high availability and operational excellence.
The ideal candidate combines strong DevOps expertise with hands-on cybersecurity experience and has a proactive mindset toward identifying vulnerabilities, implementing security best practices, and ensuring compliance across the organization.
Experience: 3 - 6 Years
Location: Kolkata (Rajarhat-Newtown).
Mode of Working: Work from Office
Key Responsibilities:
Cloud Infrastructure & DevOps -
Design, implement, and maintain highly available cloud infrastructure across AWS, GCP, and other cloud platforms.
Build and manage Infrastructure as Code (Terraform, CloudFormation).
Develop and maintain CI/CD pipelines using Jenkins, GitHub Actions, GitLab CI, or similar platforms.
Manage Kubernetes clusters (EKS/GKE), Docker containers, and container orchestration.
Monitor infrastructure health, optimize performance, automate deployments, and improve system reliability.
Implement disaster recovery, backup, and business continuity strategies.
Cybersecurity & Cloud Security -
Own and drive the organization's cloud and infrastructure security strategy.
Secure cloud environments following industry best practices and security frameworks.
Implement Zero Trust principles wherever applicable.
Design and enforce Identity & Access Management (IAM), role-based access controls, and least privilege policies.
Conduct vulnerability assessments, security audits, penetration testing coordination, and risk assessments.
Monitor and respond to security incidents, investigate threats, and implement remediation plans.
Build and maintain security monitoring, log management, SIEM integrations, and alerting systems.
Secure Kubernetes workloads, containers, APIs, and CI/CD pipelines.
Perform cloud security posture management and continuous compliance monitoring.
Ensure encryption of data at rest and in transit and manage secrets securely.
Manage Web Application Firewalls (WAF), firewalls, VPNs, endpoint security, and network segmentation.
Collaborate with development teams to integrate security into the SDLC (DevSecOps).
Governance & Compliance -
Establish and maintain security policies, standards, and operational procedures.
Ensure compliance with applicable security standards and industry best practices (ISO 27001, SOC 2, GDPR, OWASP, CIS Benchmarks, NIST, etc.).
Conduct periodic security awareness initiatives and recommend improvements to organizational security practices.
Perform regular security reviews and maintain audit readiness.
Requirements:
3–6 years of hands-on experience in Cloud Security, Cybersecurity, and DevSecOps, with a proven track record of securing enterprise infrastructure, applications, and organizational data.
Hands-on experience implementing and managing security scanning across the SDLC, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Dependency Scanning, Container Image Scanning, and Infrastructure as Code (IaC) Scanning using tools such as Trivy, Checkov, tfsec, Semgrep, SonarQube, OWASP ZAP, Snyk, or equivalent.
Strong expertise in designing and implementing enterprise security architectures, including Zero Trust, Identity & Access Management (IAM), Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and data protection strategies.
Extensive experience performing vulnerability assessments, security audits, penetration testing coordination, threat detection, incident response, digital forensics, and implementing effective remediation measures.
Deep understanding of cloud security best practices across AWS and/or Google Cloud Platform, including security services such as IAM, KMS, WAF, GuardDuty, Security Hub, CloudTrail, CloudWatch, and cloud compliance frameworks.
Strong knowledge of network and infrastructure security, including firewalls, VPNs, IDS/IPS, SSL/TLS, network segmentation, endpoint security, DNS security, and secure hybrid cloud environments.
Hands-on experience implementing DevSecOps practices by integrating security scanning, vulnerability management, secrets management, and compliance checks into CI/CD pipelines using tools such as Jenkins, GitHub Actions, GitLab CI/CD, Terraform, and CloudFormation.
Experience securing containerized and Kubernetes-based environments (Docker, Kubernetes/EKS/GKE), including container image scanning, runtime protection, Kubernetes security policies, and GitOps platforms such as ArgoCD.
Strong proficiency in Linux and Windows Server administration, including Active Directory, IIS, DNS, DHCP, Group Policy, server hardening, patch management, and operating system security.
Proficiency in scripting and automation using Python, Bash, PowerShell, and cloud CLI tools to automate security operations, infrastructure provisioning, compliance validation, and incident response workflows.
Strong understanding of cybersecurity standards and regulatory frameworks such as ISO 27001, SOC 2, NIST Cybersecurity Framework, CIS Benchmarks, GDPR, and OWASP Top 10. Industry certifications such as CISSP, CCSP, AWS Certified Security – Specialty, CKS, CKA, Security+, or CEH will be considered a strong advantage.
Why Join Us:
You'll play a critical role in protecting the organization's cloud infrastructure, applications, and sensitive business data while helping build a secure, scalable, and resilient technology ecosystem. This is an opportunity to influence security strategy, modernize infrastructure, and implement DevSecOps best practices across the organization.
Interview Process:
Application review
5–10 minute initial screening call with the TA team
Practical test conducted in the presence of a panel member
Technical interviews {Domain specific}
Role match & offer