Bangalore, Karnataka, India
Information Technology
Full-Time
GreyOrange
Overview
Responsibilities
- Design and implement security automation across CI/CD pipelines.
- Own and evolve the organisation's DevSecOps strategy and security-as-code practices.
- Collaborate with devs and SREs to embed threat modelling, SAST, DAST, and IaC scanning.
- Establish and own relevant healthy DevOps processes and practices within the team.
- Define secure cloud architecture standards for GCP-based services.
- Continuously assess risks, vulnerabilities, and compliance gaps through tooling and processes.
- Establish and champion secure coding and deployment practices.
- Lead incident response and create playbooks for security incidents.
- 6+ years in DevOps using Cloud Native Technologies.
- 2+ years focused on DevSecOps/Security Engineering.
- Strong experience in CI/CD tools (Jenkins, GitLab CI, ArgoCD, etc. ) with security integrations.
- Hands-on with infrastructure as code (Terraform, Helm) and security linters.
- Expertise in container security (Docker, Kubernetes, Aqua/Trivy/Anchore).
- Ability to implement and maintain SAST, IaC, SCA, DAST, IAST, Container Runtime Security, and Runtime SCA.
- Familiarity with threat modelling, attack surface reduction, and vulnerability management.
- Experience with REST APIs and GraphQL API design and development.
- Proficient in GCP security services.
- Experience with compliance (SOC2 ISO27001) and policy-as-code (OPA, Sentinel).
Similar Jobs
View All
Talk to us
Feel free to call, email, or hit us up on our social media accounts.
Email
info@antaltechjobs.in