414,464open jobs
14,229companies
59,920added this week
Browse all
Salary
$27k – $60k per year (Estimated)
Location
Remote (India)
Seniority
Senior · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevSecOps Engineer based in India.

This is a hands-on DevSecOps opportunity focused on embedding security across cloud infrastructure, software delivery, Kubernetes, and internal endpoints.

You will take ownership of security posture across Google Cloud Platform (GCP) and Amazon Web Services (AWS), helping protect highly distributed and cloud-native environments.

The role combines cloud security, Kubernetes hardening, CI/CD protection, endpoint security, compliance, threat modeling, and security automation.

You will work closely with engineering teams to identify vulnerabilities, reduce attack surfaces, strengthen controls, and improve security without unnecessarily slowing delivery velocity.

You will also lead security monitoring, incident response, vulnerability remediation, and compliance activities across regulated environments.

Automation will be central to the role, with opportunities to turn security policies, compliance checks, remediation workflows, and observability into scalable engineering solutions.

This position is ideal for an experienced security engineer who enjoys solving complex infrastructure challenges and communicating effectively with both technical teams and senior technology leaders.

Accountabilities

    • Own Cloud Security Posture Management (CSPM) across GCP and AWS, continuously assessing environments, identifying misconfigurations, and tracking remediation activities.
    • Design and enforce Identity and Access Management (IAM) policies, service account hygiene, least-privilege access controls, and workload identity across multi-cloud environments.
    • Implement cloud network security controls, including private service access, firewall rules, network policies, ingress and egress restrictions, and Private Google Access.
    • Identify externally exposed services and lead efforts to move unnecessary public endpoints to internal load balancers, private endpoints, VPNs, or dedicated interconnects to reduce the external attack surface.
    • Establish strong secrets management practices using GCP Secret Manager and AWS Secrets Manager, eliminating hardcoded credentials and automating credential rotation.
    • Lead cloud and Kubernetes security incident response, including triage, containment, investigation, remediation, and post-incident improvement.
    • Own security compliance reporting for frameworks and regulations such as SOC 2, HIPAA, and ISO 27001, including evidence collection, gap analysis, and control implementation.
    • Conduct threat modeling, security reviews, and architecture risk assessments to identify and mitigate security risks throughout the development lifecycle.
    • Harden Google Kubernetes Engine (GKE) clusters using CIS benchmarks, Pod Security Standards, admission controls, and other Kubernetes security best practices.
    • Implement and maintain Kubernetes network policies to enforce east-west traffic segmentation between namespaces and services.
    • Deploy and operate runtime security tooling such as Falco to detect and investigate threats within Kubernetes workloads.
    • Manage Kubernetes Role-Based Access Control (RBAC) according to least-privilege principles and continuously audit and remediate over-permissioned service accounts.
    • Secure the container supply chain by integrating image scanning into CI pipelines, enforcing signed images, and maintaining trusted container registry policies.
    • Implement Istio security controls, including mutual TLS (mTLS), authorization policies, and east-west traffic observability.
    • Continuously audit running workloads for security drift, including privileged containers, host path mounts, and secrets exposed through environment variables.
    • Secure GitLab CI/CD environments by protecting runners, restricting pipeline permissions, enforcing branch protection, and requiring appropriate merge request approvals.
    • Integrate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), dependency scanning, container scanning, and secret detection into GitLab pipelines and own associated triage and remediation workflows.
    • Implement Infrastructure as Code (IaC) security scanning using tools such as tfsec and Checkov as mandatory pipeline gates for Terraform changes.
    • Establish GitLab token hygiene practices, including expiry policies, project token rotation, and auditing of personal access token usage.
    • Define and enforce organization-wide CI/CD security policies through policy-as-code approaches.
    • Inventory public endpoints and continuously drive internalization of services that do not require public exposure.
    • Implement and maintain Web Application Firewall (WAF) and Cloud Armor controls to protect externally exposed services.
    • Automate TLS certificate issuance and rotation while enforcing TLS 1.2 or higher across endpoints.
    • Strengthen bastion host security through short-lived certificates, OS Login, Identity-Aware Proxy (IAP), elimination of persistent SSH keys, and administrative session logging.
    • Manage DNS security controls, including DNS Security Extensions (DNSSEC), private DNS zones, and split-horizon DNS where required.
    • Build security automation pipelines for policy enforcement, compliance validation, vulnerability remediation, and other security operations.
    • Develop security monitoring and threat detection dashboards in Datadog and continuously tune alerts for cloud and Kubernetes signals.
    • Create and maintain runbooks covering security incidents, vulnerability response, access reviews, and operational security procedures.
    • Champion security awareness and training while conducting secure code reviews and threat modeling workshops.
    • Requirements

      • Bring 7+ years of experience in DevSecOps, cloud security, infrastructure security engineering, or a closely related field.
      • Demonstrate deep hands-on experience securing production Kubernetes clusters, including RBAC, network policies, Pod Security Standards, admission controls, and runtime protection.
      • Possess strong practical experience with GCP and/or AWS security services, including cloud IAM design and security architecture.
      • Demonstrate strong knowledge of CI/CD security, including pipeline hardening, secrets management, integrated security scanning, and security policy enforcement.
      • Have proven experience internalizing service endpoints and reducing the attack surface of cloud environments.
      • Bring experience working with security and compliance requirements such as HIPAA, SOC 2, or ISO 27001, preferably in regulated environments.
      • Demonstrate the ability to explain complex security risks clearly to different audiences, from engineers implementing remediation to CTO-level stakeholders evaluating business impact.
      • Have hands-on experience with GCP security technologies such as Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager, and Binary Authorization.
      • Have hands-on experience with AWS security services such as GuardDuty, Security Hub, IAM, Key Management Service (KMS), Macie, and AWS Config.
      • Demonstrate strong Kubernetes security expertise covering GKE hardening, Pod Security Standards, network policies, RBAC, and admission controllers.
      • Have strong GitLab security experience covering CI/CD security, SAST/DAST, dependency scanning, secret detection, and pipeline policy management.
      • Possess strong Terraform knowledge, including IaC security scanning with tfsec or Checkov and secure Terraform module design.
      • Have experience using Datadog for security monitoring, threat detection, and alert management.
      • Demonstrate experience securing service meshes with Istio, including mTLS, authorization policies, and related security controls.
      • Experience with tools such as Falco, Open Policy Agent (OPA)/Gatekeeper, HashiCorp Vault, Wiz, Orca, Prisma Cloud, Trivy, or Snyk is advantageous.
      • Experience with Security Information and Event Management (SIEM) platforms such as Splunk or Chronicle is a plus.
      • Proficiency in Python or Go for security automation is beneficial.
      • A Certified Kubernetes Security Specialist (CKS) certification is advantageous.
      • Google Professional Cloud Security Engineer or AWS Certified Security - Specialty certification is a plus.
      • Experience with eBPF-based security technologies such as Cilium or Tetragon is beneficial.
      • Penetration testing, red team experience, or advanced offensive security knowledge is advantageous.
      • Experience with threat modeling methodologies such as STRIDE or PASTA is a plus.
      • Familiarity with service mesh security beyond Istio is beneficial.
      • Benefits

        • Opportunity to work across modern multi-cloud environments spanning GCP and AWS.
        • Hands-on exposure to Kubernetes, GitLab CI/CD, Terraform, Istio, Datadog, cloud security platforms, and security automation.
        • Opportunity to own security initiatives across cloud infrastructure, containerized workloads, software delivery pipelines, and endpoints.
        • Exposure to compliance programs involving SOC 2, HIPAA, and ISO 27001.
        • Opportunity to build scalable security automation and policy-as-code solutions.
        • Collaboration with engineering and technology teams on high-impact security initiatives.
        • Opportunity to influence security architecture, threat modeling, incident response, and vulnerability management practices.
        • Environment focused on strengthening security while maintaining engineering velocity.
        • Opportunity to expand expertise across cloud security, Kubernetes, DevSecOps, and emerging security technologies.
        • Remote working opportunity within India.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
414,464 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$23k – $55k per year (Estimated) • Remote • Full-Time • 8+ years exp
DevOps
Terraform
GCP
Azure
AWS
Kubernetes
Amazon EKS
Azure AKS
Apply
$17k – $40k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
DevOps
GCP
Cybersecurity
GDPR
Apply
PAM - Cyberark SME 1 day ago
In office • Full-Time • Bachelor's Degree • Madrid
Python
PowerShell
DevOps
Rest API
Ansible
GCP
Azure
CI/CD
AWS
Docker
Incident Management
IAM
Cybersecurity
CyberArk
HashiCorp Vault
Zero Trust
Cryptography
Vault
Apply
$53k – $133k per year (Estimated) • In office • Full-Time • 2+ years exp • Bath
DevOps
GCP
Apply
$36k – $91k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Madrid
DevOps
Terraform
AWS
Cybersecurity
ISO 27001
PCI DSS
GDPR
Apply
$23k – $55k per year (Estimated) • Remote • Full-Time • 8+ years exp
DevOps
Terraform
GCP
Azure
AWS
Kubernetes
Amazon EKS
Azure AKS
Apply
$26k – $71k per year (Estimated) • Remote • Full-Time • 7+ years exp
Analytics
A/B Testing
Apply
$21k – $47k per year (Estimated) • Equity • Remote • Full-Time • 4+ years exp • Bachelor's Degree
Python
SQL
Analytics
Power BI
Apply
$19k – $44k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree
JavaScript
DevOps
Azure
AWS
Bitbucket
Management
Confluence
Jira
Apply
$25k – $55k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
SQL
AI/ML
Reinforcement Learning
Edge AI
Apply
See all jobs
This is one of many
414,464 more open roles from verified company boards, updated every day.