386,888open jobs
10,207companies
47,741added this week
Browse all
Salary
$28k – $63k per year (Estimated)
Location
Remote (India)
Seniority
Senior · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Sutherland is an American business process and digital transformation company founded in 1986 that runs customer operations, back-office processing and analytics for large organisations. It works across healthcare, banking, insurance, telecommunications, retail and technology clients, combining offshore and nearshore delivery centres with automation and artificial intelligence intended to reduce the headcount those processes require. Headquartered in Pittsford, New York and privately held, it employs tens of thousands of people across more than a dozen countries and competes with the large Indian and Filipino outsourcing providers.

Sutherland is seeking an experienced DevSecOps Engineer who will embed security into every layer of our cloud infrastructure and software delivery pipeline. Your primary responsibility is to ensure our GCP and AWS environments, Kubernetes clusters, CI/CD pipelines, and internal endpoints are secure, compliant, and hardened - without slowing down engineering velocity

Cloud Security - Primary

  • Own cloud security posture management (CSPM) across GCP and AWS - continuous assessment, misconfiguration detection, and remediation tracking.
  • Design and enforce IAM policies, service account hygiene, least-privilege access controls, and workload identity across multi-cloud environments.
  • Implement VPC security controls - private service access, firewall rules, network policies, ingress/egress restrictions, and Private Google Access.
  • Internalise and secure service endpoints - move external-facing services to internal load balancers, private endpoints, and VPN/interconnect. Continuously audit and reduce the public attack surface.
  • Manage secrets hygiene - enforce Secret Manager (GCP) and AWS Secrets Manager, eliminate hardcoded credentials, and rotate secrets programmatically.
  • Lead cloud security incident response - triage, contain, investigate, and remediate across cloud and Kubernetes environments.
  • Own compliance reporting for SOC 2, HIPAA, and ISO 27001 - evidence collection, gap analysis, and control implementation.
  • Conduct regular threat modelling, security reviews, and architecture risk assessments.

Kubernetes Security - Primary

  • Harden GKE clusters - CIS benchmarks, pod security standards (restricted/baseline), and admission control policies.
  • Implement and manage network policies to enforce east-west traffic segmentation between namespaces and services.
  • Deploy and operate runtime security tooling (e.g. Falco) for threat detection inside cluster workloads.
  • Manage Kubernetes RBAC with least-privilege principles. Audit and remediate overpermissioned service accounts.
  • Secure the container supply chain - image scanning in CI (Trivy/Snyk), enforce signed images, and maintain a trusted registry policy.
  • Implement Istio security controls - mTLS enforcement, authorisation policies, and east-west traffic observability.
  • Continuously audit running workloads for security drift - privileged containers, host path mounts, and secrets in environment variables.

CI/CD & GitLab Security - Primary

  • Secure the GitLab CI/CD pipeline end-to-end - protect runner environments, restrict pipeline permissions, enforce branch protection and MR approvals.
  • Integrate SAST, DAST, dependency scanning, container scanning, and secret detection natively into GitLab CI. Own the triage and remediation workflow.
  • Implement IaC security scanning (tfsec, Checkov) as a mandatory pipeline gate for all Terraform changes.
  • Manage GitLab token hygiene - enforce expiry policies, rotate project tokens, and audit personal access token usage.
  • Define and enforce pipeline security policies organization-wide using GitLab security policy-as-code.

Endpoint & Network Security - Primary

  • Audit and reduce the external attack surface - inventory all public endpoints and drive internalization of services that do not need to be public.
  • Implement and maintain WAF and Cloud Armor rules to protect externally exposed services.
  • Enforce TLS certificate management - automate issuance, rotation, and enforce TLS 1.2+ across all endpoints.
  • Manage bastion host security - enforce short-lived certificates (OS Login / IAP), eliminate persistent SSH keys, and log all administrative sessions.
  • Own DNS security controls - DNSSEC, private DNS zones for internal services, split-horizon DNS where required.

Security Engineering & Automation

  • Build security automation pipelines - policy enforcement, compliance checks, and vulnerability remediation as code.
  • Instrument security observability in Datadog - threat detection dashboards and alert tuning for cloud and Kubernetes signals.
  • Develop and maintain runbooks for security incidents, vulnerability response, and access reviews.
  • Champion security training and awareness. Conduct secure code reviews and threat modelling workshops.

TECH STACK

Required

  • GCP - Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager, Binary Authorization
  • AWS - GuardDuty, Security Hub, IAM, KMS, Macie, AWS Config
  • Kubernetes - GKE hardening, pod security standards, network policies, RBAC, admission controllers
  • GitLab - CI/CD security, SAST/DAST, dependency scanning, pipeline policy management
  • Terraform - IaC security scanning (tfsec, Checkov), secure module design
  • Datadog - security monitoring, threat detection, alert management
  • Istio - mTLS, authorisation policies, service mesh security

Good to have

  • Falco, OPA/Gatekeeper, HashiCorp Vault, Wiz/Orca/Prisma Cloud, Trivy/Snyk, SIEM (Splunk/Chronicle), Python or Go

Must have

  • 7+ years in DevSecOps, cloud security, or infrastructure security engineering.
  • Deep hands-on experience securing Kubernetes clusters in production - RBAC, network policies, pod security, and runtime protection.
  • Proven experience with GCP and/or AWS security services and IAM design.
  • Strong CI/CD security knowledge - pipeline hardening, secrets management, and integrated scanning.
  • Experience internalising service endpoints and reducing cloud attack surface.
  • Familiarity with HIPAA, SOC 2, or ISO 27001 compliance in regulated environments.
  • Clear communication skills - able to explain a critical vulnerability to a CTO and write a runbook for an engineer.

Nice to have

  • Certified Kubernetes Security Specialist (CKS).
  • Google Professional Cloud Security Engineer or AWS Security Specialty certification.
  • eBPF-based security tooling (Cilium, Tetragon), penetration testing, or red team experience.
  • Threat modelling using STRIDE or PASTA. Service mesh security beyond Istio.

All your information will be kept confidential according to EEO guidelines.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
386,888 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hyderabad
$70k – $177k per year (Estimated) • Remote/Hybrid • Full-Time • Melbourne • Sydney
Go
Java
Python
TypeScript
Databases
Amazon Neptune
Neo4j
AI/ML
AI Agents
DevOps
AWS
Azure
CI/CD
GCP
Platform Engineering
Analytics
ETL/ELT
Apply
$92k – $220k per year (Estimated) • In office • Full-Time • Sydney
Java
Python
Scala
Python
pySpark
Databases
Apache Kafka
Kafka
Snowflake
AI/ML
ChatGPT
Claude
Copilot
dbt
Hadoop
LangChain
LangGraph
OpenAI Codex
Spark
DevOps
Amazon Kinesis
Amazon S3
AWS
CI/CD
Apply
$87k – $198k per year (Estimated) • In office • Contractor • Sydney
SQL
Databases
Oracle
Snowflake
AI/ML
dbt
DevOps
CI/CD
Git
Apply
$23k – $58k per year (Estimated) • Remote • Full-Time • 8+ years exp • Hyderabad
DevOps
Amazon EKS
AWS
Azure AKS
GCP
Kubernetes
Terraform
Azure
Apply
$70k – $170k per year • Remote
JavaScript
PHP
DevOps
CI/CD
Apply
$23k – $58k per year (Estimated) • Remote • Full-Time • 8+ years exp • Hyderabad
DevOps
Amazon EKS
AWS
Azure AKS
GCP
Kubernetes
Terraform
Azure
Apply
Remote • Full-Time • 7+ years exp • Sofia
Mobile
Twilio
DevOps
Azure
Azure DevOps
Cybersecurity
GDPR
HIPAA
PCI DSS
Management
Jira
Apply
$24k – $57k per year (Estimated) • Remote • Full-Time • 12+ years exp • Master's Degree • Chennai
Python
SQL
Databases
Microsoft Fabric
DevOps
Azure
Analytics
ETL/ELT
Power BI
Apply
$31k – $61k per year (Estimated) • In office • Full-Time • 12+ years exp • Chennai
SQL
DevOps
AWS
Azure
Azure DevOps
CI/CD
GCP
Platform Engineering
Rest API
Management
Confluence
Jira
Microsoft Project
Apply
$41k – $89k per year (Estimated) • In office • Full-Time • 10+ years exp • Chennai
Databases
DynamoDB
AI/ML
AI Agents
AWS Bedrock
AWS Bedrock AgentCore
DevOps
Amazon S3
AWS
AWS Fargate
AWS Lambda
Azure
Apply
$26k – $73k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad
Python
Apply
Security Architect 1 day ago
$34k – $84k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
DevOps
AWS
Apply
$33k – $88k per year (Estimated) • In office • Full-Time • 6+ years exp • Bengaluru • Mumbai • Hyderabad • Pune
SQL
Databases
Amazon Redshift
Databricks
DevOps
Amazon Kinesis
AWS
Azure
Azure DevOps
GitHub
Incident Management
Analytics
ETL/ELT
Apply
$39k – $83k per year (Estimated) • In office • Full-Time • 15+ years exp • Bachelor's Degree • Hyderabad
Python
SQL
DevOps
GCP
Apply
In office • Full-Time • Bachelor's Degree • Hyderabad
SQL
Apply
See all jobs
This is one of many
386,888 more open roles from verified company boards, updated every day.