Padmi

Cloud Security Policy-as-Code (PaC) Engineer | OPA Gatekeeper | Rego

Delhi NCRPosted 1 month ago
CybersecuritySeniorFull Time; Regular
Apply at Supple Soft Pvt.Ltd.

Opens the source posting on shine.com

Source description

About the role

View original

About the Role SuppleSoft Private Limited is looking for an experienced Cloud Security Policy-as-Code (PaC) Engineer to join our DevSecOps and Cloud Security team. In this role, you will design, develop, and implement enterprise-grade security policies for Kubernetes platforms using OPA Gatekeeper, Rego, and Terraform Sentinel. You will work closely with Cloud Engineering, Information Security, Platform Engineering, and Application teams to build secure, scalable, and compliant cloud-native environments. If you are passionate about Kubernetes security, Policy-as-Code, and cloud platform security, we'd love to hear from you. Key ResponsibilitiesDesign and implement enterprise security policies using OPA Gatekeeper and Rego.Develop and maintain ConstraintTemplates, Constraints, and reusable policy libraries.Create admission control policies to validate Kubernetes resources before deployment.Implement secure-by-default Kubernetes controls, including:RBACNetwork PoliciesPod Security StandardsWorkload IdentitySecurity ContextsSecret ManagementDevelop policies to enforce:Internal CIDR/IP restrictionsContainer image validationNamespace restrictionsResource limitsLabel and annotation complianceIstio Service Mesh securityWrite and execute policy tests using Gator and OPA Test.Integrate Policy-as-Code into CI/CD and GitOps workflows.Support Kubernetes platforms running on AWS EKS, Google GKE, and Red Hat OpenShift.Collaborate with DevOps, Security, and Platform Engineering teams to improve cloud security posture.Perform security assessments against CIS Benchmarks and enterprise compliance standards.Participate in code reviews, pull requests, and technical design discussions.Required SkillsKubernetesKubernetes ArchitecturePods, Deployments, ServicesNamespacesRBACNetwork PoliciesPod Security StandardsAdmission ControllersCRDsService AccountsWorkload IdentityOPA Gatekeeper & RegoOPA GatekeeperRego Policy DevelopmentConstraintTemplatesConstraintsAdmission Control PoliciesPolicy TestingGatorOPA CLICloud PlatformsAWS (EKS)Google Cloud Platform (GKE)Red Hat OpenShiftMulti-cloud security best practicesInfrastructure as CodeTerraformTerraform SentinelHelmKustomizeYAMLDevSecOps & CI/CDJenkinsGitHub ActionsGitLab CIAzure DevOpsArgo CDGitOpsNetworking & SecurityCIDR and IP AddressingVPC NetworkingKubernetes NetworkingNetwork SegmentationService Mesh (Istio)mTLSZero Trust ArchitectureCloud IAMSecure Communication PatternsContainer SecurityDockerImage ScanningRuntime SecurityVulnerability ManagementTrivy (preferred)Required Experience6+ years of experience in Cloud Engineering, DevSecOps, or Cloud Security.3+ years of hands-on experience with Kubernetes security.Experience developing Policy-as-Code using OPA Gatekeeper and Rego.Strong understanding of Kubernetes networking, RBAC, and workload security.Experience integrating security into CI/CD pipelines.Experience working in Agile/Scrum environments.Excellent troubleshooting and problem-solving skills.Preferred QualificationsExperience with Terraform Sentinel or similar policy frameworks.Experience with Istio Service Mesh.Knowledge of CIS Kubernetes Benchmarks, NIST, and Cloud Control Matrix (CCM).Experience with GitOps platforms such as Argo CD or Flux.Familiarity with Python or Bash scripting. .

One address, no account. We’ll tell you when matching roles go live.

More at Supple Soft Pvt.Ltd.

Related open roles

View all roles