Project Role : Technology Platform Engineer
Project Role Description : Creates production and non-production cloud environments using the proper software tools such as a platform for a project or product. Deploys the automation pipeline and automates environment creation and configuration.
Must have skills : DevSecOps
Good to have skills : Kubernetes, Elastic Stack (ELK)
Minimum 7.5 year(s) of experience is required
Educational Qualification : 15 years full time education
Summary:
As a DevSecOps Lead, a typical day involves embedding security best practices into every stage of the software delivery lifecycle, ensuring that security is integrated seamlessly from development through deployment and operations. This role requires designing, implementing, and maintaining secure CI/CD pipelines, automating security controls, and collaborating with development, operations, and security teams to ensure compliance with organizational security standards. The day also includes monitoring Kubernetes environments, managing log analytics and threat detection using ELK Stack, identifying vulnerabilities, and driving continuous improvements to security posture across cloud-native platforms and delivery pipelines.
Roles & Responsibilities:
Expected to be an SME, collaborate and manage the team to perform.
Responsible for team decisions.
Engage with multiple teams and contribute to key decisions.
Provide solutions to problems for their immediate team and across multiple teams.
Embed security best practices into every stage of the DevOps lifecycle, from development to deployment.
Develop, implement, and maintain security checks and controls within CI/CD pipelines to ensure secure software delivery.
Design and manage security monitoring, logging, and incident response capabilities using ELK Stack.
Secure Kubernetes-based applications and infrastructure through policy enforcement, container security, and vulnerability management.
Collaborate with development, operations, and security teams to identify, assess, and remediate security risks.
Drive automation of security testing, compliance checks, and vulnerability scanning across application and infrastructure layers.
Mentor team members on DevSecOps practices, secure coding principles, and security automation frameworks.
Professional & Technical Skills:
Must To Have Skills: Proficiency in DevSecOps.
Strong experience with Kubernetes administration, security, and containerized application deployments.
Hands-on experience integrating security tools and controls into CI/CD pipelines.
Proficiency in implementing DevSecOps practices, including SAST, DAST, dependency scanning, and container image scanning.
Experience with ELK Stack (Elasticsearch, Logstash, Kibana) for logging, monitoring, and security event analysis.
Knowledge of cloud-native security concepts, container security, secrets management, and policy enforcement.
Strong understanding of vulnerability management, compliance requirements, and risk mitigation strategies.
Experience in automating security controls and infrastructure security using scripting and Infrastructure as Code (IaC) practices.
Ability to collaborate with cross-functional teams to establish and maintain a secure software development lifecycle (SSDLC).
Additional Information:
The candidate should have a minimum of 8 years of experience in DevSecOps and cloud-native security practices.
Experience with Kubernetes security, container orchestration, and ELK Stack implementation is mandatory.
This position is based at our Bengaluru office.
A 15 years full-time education is required.
15 years full time education