Actively hiringPosted today

Cloud Security / DevSecOps Engineer (AWS + Kubernetes)

RecruitKarBengaluru

Skills we’re looking for

AWSKubernetesDevSecOpsTerraformCI/CDDockerIAMContainer SecurityVulnerability ManagementPython

About this role

Job Overview

We are looking for an experienced Cloud Security / DevSecOps Engineer to design, implement, and maintain secure cloud infrastructure and deployment pipelines across AWS and Kubernetes environments.

The ideal candidate will have strong hands-on experience with AWS security, Kubernetes security, Infrastructure as Code, CI/CD, container security, vulnerability management, and cloud-native security practices. The role will involve working closely with DevOps, engineering, and security teams to embed security throughout the software development and deployment lifecycle.

Key Responsibilities

Design and implement secure and scalable infrastructure on AWS.

Secure and manage Kubernetes clusters and containerized workloads.

Implement security controls across the cloud infrastructure, applications, containers, and CI/CD pipelines.

Integrate security practices into the DevOps lifecycle (DevSecOps).

Develop and maintain secure CI/CD pipelines with automated security checks.

Implement Infrastructure as Code (IaC) using tools such as Terraform or CloudFormation.

Configure and manage AWS security services including IAM, KMS, CloudTrail, GuardDuty, Security Hub, WAF, and VPC security controls.

Implement identity and access management, least-privilege policies, roles, permissions, and secrets management.

Secure container images and Kubernetes workloads through vulnerability scanning and policy enforcement.

Implement Kubernetes security controls including RBAC, Network Policies, Pod Security, Secrets management, and admission controls.

Monitor cloud environments for security threats, vulnerabilities, misconfigurations, and suspicious activity.

Perform vulnerability assessments and coordinate remediation of security issues.

Integrate tools such as SAST, DAST, SCA, container scanning, and IaC scanning into CI/CD pipelines.

Investigate and respond to cloud and infrastructure security incidents.

Establish security best practices, standards, and reusable controls for engineering teams.

Conduct security reviews of infrastructure, architecture, and deployment configurations.

Automate security processes and compliance checks wherever possible.

Maintain documentation related to security architecture, policies, configurations, and incident response.

Required Skills & Experience

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.

3–7 years of experience in Cloud Security, DevSecOps, DevOps, or related roles.

Strong hands-on experience with AWS cloud infrastructure and security.

Strong understanding of Kubernetes and container security.

Proficiency with Linux and networking fundamentals.

Strong experience with Infrastructure as Code, preferably Terraform.

Hands-on experience with CI/CD platforms such as Jenkins, GitHub Actions, GitLab CI, or AWS CodePipeline.

Good understanding of Docker/containerization.

Strong understanding of:

IAM & RBAC

VPC & network security

Security groups & NACLs

Encryption & key management

Secrets management

Logging & monitoring

Vulnerability management

Identity and access controls

Experience implementing security scanning and controls within CI/CD pipelines.

Strong scripting/automation skills using Python, Bash, or similar.

Experience with Git and Git-based development workflows.

Kubernetes Security Skills

Candidates should have practical knowledge of:

Kubernetes RBAC

Network Policies

Pod Security Standards

Kubernetes Secrets

Service Accounts

Ingress security

Container image security

Resource limits and security contexts

Admission controllers/policies

Cluster and workload monitoring

Kubernetes vulnerability management

Cloud Security Tools & Technologies

Experience with some of the following is preferred:

AWS:

IAM | KMS | CloudTrail | GuardDuty | Security Hub | WAF | VPC | CloudWatch | Config

DevSecOps:

Jenkins | GitHub Actions | GitLab CI/CD | SonarQube | Snyk | Trivy | Checkmarx | OWASP

Containers & Kubernetes:

Docker | Kubernetes | Helm | EKS | ArgoCD | Falco | OPA/Gatekeeper | Kyverno

IaC:

Terraform | CloudFormation | Terragrunt

Good to Have

Experience securing AWS EKS environments.

Knowledge of CSPM/CNAPP solutions.

Experience with SIEM platforms such as Splunk, ELK, or Microsoft Sentinel.

Familiarity with Zero Trust architecture.

Experience with security frameworks such as CIS, NIST, ISO 27001, SOC 2, or PCI-DSS.

Relevant certifications such as:

AWS Security Specialty

AWS Solutions Architect

Certified Kubernetes Security Specialist (CKS)

Certified Kubernetes Administrator (CKA)

Security+/CISSP or equivalent

Experience with cloud security automation and policy-as-code.

Exposure to incident response and forensic investigation in cloud environments.

Candidate Profile

The ideal candidate should have:

Strong cloud security and DevSecOps mindset.

Excellent troubleshooting and problem-solving skills.

Ability to identify and remediate security vulnerabilities independently.

Strong understanding of cloud networking and security architecture.

Ability to balance security requirements with development and operational needs.

Strong automation mindset and willingness to eliminate repetitive security tasks.

Good communication and collaboration skills.

Ability to work effectively with engineering, DevOps, infrastructure, and security teams.

Key Technologies

AWS | Kubernetes | EKS | Docker | Terraform | Linux | CI/CD | DevSecOps | IAM | VPC | CloudTrail | GuardDuty | Security Hub | KMS | WAF | Git | Jenkins/GitHub Actions | Trivy/Snyk | Python/Bash

Employment Details

Experience: 3–7 Years

Job Type: Full-time

Work Mode: Remote

Location: Bengaluru