Padmi

Lead Security & DevOps Engineer

IndiaPosted 2 months ago
CybersecuritySeniorFull Time; Regular
Apply at Petpooja

Opens the source posting on shine.com

Source description

About the role

View original

Job Description We're looking for a highly capable Lead Security & DevSecOps Engineer who will own the organization's security posture across infrastructure, applications, cloud platforms, and engineering practices. This role reports directly to the CTO and will be responsible for driving day-to-day security operations while partnering closely with Engineering, Infrastructure, Product, and external security vendors. This is not a CISO role. It is a hands-on technical leadership position for someone who enjoys building secure systems, improving engineering practices, and leading security initiatives across the organization. What You'll Do Security Strategy & Operations Own the organization's day-to-day security operations. Build, implement, and continuously improve enterprise security practices. Define security standards, policies, and operational procedures. Lead incident response, forensic investigations, root cause analysis, and post-incident reviews. Maintain and continuously improve the organization's overall security posture. Cloud & Infrastructure Security Secure AWS infrastructure and cloud services. Design and implement IAM best practices and least-privilege access. Manage encryption, secrets management, key rotation, and certificate lifecycle. Secure VPCs, networking, WAFs, CloudFront, load balancers, VPNs, and public-facing services. Perform periodic security reviews of cloud architecture. DevSecOps Integrate security throughout the CI/CD pipeline. Automate security testing and policy enforcement. Implement SAST, DAST, dependency scanning, container image scanning, and Infrastructure-as-Code security. Work closely with engineering teams to ensure security is embedded into the Software Development Lifecycle (SDLC). Establish security gates before production deployments. Security Monitoring & SOC Management Own Security Operations Center (SOC) activities. Manage with third-party SOC vendors. Build centralized logging, monitoring, alerting, and threat detection capabilities. Define security dashboards and KPIs. Manage SIEM platforms and continuously improve alert quality. Coordinate investigations and remediation of security incidents. Vulnerability & Risk Management Manage vulnerability assessments and remediation programs. Coordinate external penetration testing engagements. Track remediation SLAs and ensure timely closure of findings. Maintain the organization's security risk register. Conduct periodic threat modeling and security architecture reviews. Third-Party Security & Compliance Act as the primary technical point of contact for: SOC providers Penetration testing firms External auditors Cloud vendors Security consultants Compliance partners Review third-party security reports and coordinate remediation. Support compliance initiatives such as ISO 27001, SOC 2, PCI DSS, and customer security assessments. Engineering Collaboration Partner with engineering teams to build secure-by-design architectures. Conduct architecture and code security reviews. Mentor developers on secure coding practices. Build reusable security frameworks, automation, and tooling. Promote a strong security culture across engineering teams. Required Experience 7 - 12 years of overall experience in Infrastructure, DevOps, Cloud Engineering, or Information Security. At least 3 - 5 years of hands-on experience in Security or DevSecOps. Strong experience securing production AWS environments. Experience building and managing security operations for cloud-native applications. Experience implementing secure SDLC practices. Hands-on experience with incident response and vulnerability management. Strong understanding of modern application security principles. Technical Skills AWS Security IAM & Identity Management Linux Administration Docker & Kubernetes Security Terraform / Infrastructure as Code CI/CD Security Network Security WAF & CDN Security SIEM Platforms Endpoint Detection & Response (EDR) SAST / DAST Tools Secrets Management Vulnerability Assessment Threat Modeling Incident Response OWASP Top 10 Job Description We're looking for a highly capable Lead Security & DevSecOps Engineer who will own the organization's security posture across infrastructure, applications, cloud platforms, and engineering practices. This role reports directly to the CTO and will be responsible for driving day-to-day security operations while partnering closely with Engineering, Infrastructure, Product, and external security vendors. This is not a CISO role. It is a hands-on technical leadership position for someone who enjoys building secure systems, improving engineering practices, and leading security initiatives across the organization. What You'll Do Security Strategy & Operations Own the organization's day-to-day security operations. Build, implement, and continuously improve enterprise security practices. Define security standards, policies, and operational procedures. Lead incident response, forensic investigations, r

One address, no account. We’ll tell you when matching roles go live.

More at Petpooja

Related open roles

View all roles
Lead Security & DevOps Engineer at Petpooja · Padmi