Cloud Security / DevSecOps Engineer (AWS + Kubernetes)
RecruitKarBengaluru
Skills we’re looking for
About this role
Job Overview
We are looking for an experienced Cloud Security / DevSecOps Engineer to design, implement, and maintain secure cloud infrastructure and deployment pipelines across AWS and Kubernetes environments.
The ideal candidate will have strong hands-on experience with AWS security, Kubernetes security, Infrastructure as Code, CI/CD, container security, vulnerability management, and cloud-native security practices. The role will involve working closely with DevOps, engineering, and security teams to embed security throughout the software development and deployment lifecycle.
Key Responsibilities
Design and implement secure and scalable infrastructure on AWS.
Secure and manage Kubernetes clusters and containerized workloads.
Implement security controls across the cloud infrastructure, applications, containers, and CI/CD pipelines.
Integrate security practices into the DevOps lifecycle (DevSecOps).
Develop and maintain secure CI/CD pipelines with automated security checks.
Implement Infrastructure as Code (IaC) using tools such as Terraform or CloudFormation.
Configure and manage AWS security services including IAM, KMS, CloudTrail, GuardDuty, Security Hub, WAF, and VPC security controls.
Implement identity and access management, least-privilege policies, roles, permissions, and secrets management.
Secure container images and Kubernetes workloads through vulnerability scanning and policy enforcement.
Implement Kubernetes security controls including RBAC, Network Policies, Pod Security, Secrets management, and admission controls.
Monitor cloud environments for security threats, vulnerabilities, misconfigurations, and suspicious activity.
Perform vulnerability assessments and coordinate remediation of security issues.
Integrate tools such as SAST, DAST, SCA, container scanning, and IaC scanning into CI/CD pipelines.
Investigate and respond to cloud and infrastructure security incidents.
Establish security best practices, standards, and reusable controls for engineering teams.
Conduct security reviews of infrastructure, architecture, and deployment configurations.
Automate security processes and compliance checks wherever possible.
Maintain documentation related to security architecture, policies, configurations, and incident response.
Required Skills & Experience
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
3–7 years of experience in Cloud Security, DevSecOps, DevOps, or related roles.
Strong hands-on experience with AWS cloud infrastructure and security.
Strong understanding of Kubernetes and container security.
Proficiency with Linux and networking fundamentals.
Strong experience with Infrastructure as Code, preferably Terraform.
Hands-on experience with CI/CD platforms such as Jenkins, GitHub Actions, GitLab CI, or AWS CodePipeline.
Good understanding of Docker/containerization.
Strong understanding of:
IAM & RBAC
VPC & network security
Security groups & NACLs
Encryption & key management
Secrets management
Logging & monitoring
Vulnerability management
Identity and access controls
Experience implementing security scanning and controls within CI/CD pipelines.
Strong scripting/automation skills using Python, Bash, or similar.
Experience with Git and Git-based development workflows.
Kubernetes Security Skills
Candidates should have practical knowledge of:
Kubernetes RBAC
Network Policies
Pod Security Standards
Kubernetes Secrets
Service Accounts
Ingress security
Container image security
Resource limits and security contexts
Admission controllers/policies
Cluster and workload monitoring
Kubernetes vulnerability management
Cloud Security Tools & Technologies
Experience with some of the following is preferred:
AWS:
IAM | KMS | CloudTrail | GuardDuty | Security Hub | WAF | VPC | CloudWatch | Config
DevSecOps:
Jenkins | GitHub Actions | GitLab CI/CD | SonarQube | Snyk | Trivy | Checkmarx | OWASP
Containers & Kubernetes:
Docker | Kubernetes | Helm | EKS | ArgoCD | Falco | OPA/Gatekeeper | Kyverno
IaC:
Terraform | CloudFormation | Terragrunt
Good to Have
Experience securing AWS EKS environments.
Knowledge of CSPM/CNAPP solutions.
Experience with SIEM platforms such as Splunk, ELK, or Microsoft Sentinel.
Familiarity with Zero Trust architecture.
Experience with security frameworks such as CIS, NIST, ISO 27001, SOC 2, or PCI-DSS.
Relevant certifications such as:
AWS Security Specialty
AWS Solutions Architect
Certified Kubernetes Security Specialist (CKS)
Certified Kubernetes Administrator (CKA)
Security+/CISSP or equivalent
Experience with cloud security automation and policy-as-code.
Exposure to incident response and forensic investigation in cloud environments.
Candidate Profile
The ideal candidate should have:
Strong cloud security and DevSecOps mindset.
Excellent troubleshooting and problem-solving skills.
Ability to identify and remediate security vulnerabilities independently.
Strong understanding of cloud networking and security architecture.
Ability to balance security requirements with development and operational needs.
Strong automation mindset and willingness to eliminate repetitive security tasks.
Good communication and collaboration skills.
Ability to work effectively with engineering, DevOps, infrastructure, and security teams.
Key Technologies
AWS | Kubernetes | EKS | Docker | Terraform | Linux | CI/CD | DevSecOps | IAM | VPC | CloudTrail | GuardDuty | Security Hub | KMS | WAF | Git | Jenkins/GitHub Actions | Trivy/Snyk | Python/Bash
Employment Details
Experience: 3–7 Years
Job Type: Full-time
Work Mode: Remote
Location: Bengaluru