Padmi

Cloud & DevSecOps Engineer (Cloud Infrastructure & Cybersecurity)

IndiaPosted 1 month ago
CybersecurityMid-levelFull Time; Regular
Apply at Web Spiders

Opens the source posting on shine.com

Source description

About the role

View original

We are looking for a highly skilled Cloud & DevSecOps Engineer to strengthen the security, reliability, and scalability of our cloud infrastructure while safeguarding the organization's digital assets and data. In this role, you will be responsible for securing our cloud environments, applications, CI/CD pipelines, networks, and infrastructure against evolving cyber threats. You will work closely with engineering, IT, and product teams to embed security throughout the software development lifecycle while ensuring high availability and operational excellence. Location Kolkata (Rajarhat-New Town) Type Full Time Department Technology We are looking for a highly skilled Cloud & DevSecOps Engineer to strengthen the security, reliability, and scalability of our cloud infrastructure while safeguarding the organization's digital assets and data. In this role, you will be responsible for securing our cloud environments, applications, CI/CD pipelines, networks, and infrastructure against evolving cyber threats. You will work closely with engineering, IT, and product teams to embed security throughout the software development lifecycle while ensuring high availability and operational excellence. The ideal candidate combines strong DevOps expertise with hands-on cybersecurity experience and has a proactive mindset toward identifying vulnerabilities, implementing security best practices, and ensuring compliance across the organization. Experience: 3 - 6 Years Location: Kolkata (Rajarhat-Newtown). Mode of Working: Work from Office Key Responsibilities: Cloud Infrastructure & DevOps - Design, implement, and maintain highly available cloud infrastructure across AWS, GCP, and other cloud platforms. Build and manage Infrastructure as Code (Terraform, CloudFormation). Develop and maintain CI/CD pipelines using Jenkins, GitHub Actions, GitLab CI, or similar platforms. Manage Kubernetes clusters (EKS/GKE), Docker containers, and container orchestration. Monitor infrastructure health, optimize performance, automate deployments, and improve system reliability. Implement disaster recovery, backup, and business continuity strategies. Cybersecurity & Cloud Security - Own and drive the organization's cloud and infrastructure security strategy. Secure cloud environments following industry best practices and security frameworks. Implement Zero Trust principles wherever applicable. Design and enforce Identity & Access Management (IAM), role-based access controls, and least privilege policies. Conduct vulnerability assessments, security audits, penetration testing coordination, and risk assessments. Monitor and respond to security incidents, investigate threats, and implement remediation plans. Build and maintain security monitoring, log management, SIEM integrations, and alerting systems. Secure Kubernetes workloads, containers, APIs, and CI/CD pipelines. Perform cloud security posture management and continuous compliance monitoring. Ensure encryption of data at rest and in transit and manage secrets securely. Manage Web Application Firewalls (WAF), firewalls, VPNs, endpoint security, and network segmentation. Collaborate with development teams to integrate security into the SDLC (DevSecOps). Governance & Compliance - Establish and maintain security policies, standards, and operational procedures. Ensure compliance with applicable security standards and industry best practices (ISO 27001, SOC 2, GDPR, OWASP, CIS Benchmarks, NIST, etc.). Conduct periodic security awareness initiatives and recommend improvements to organizational security practices. Perform regular security reviews and maintain audit readiness. Requirements: 36 years of hands-on experience in Cloud Security, Cybersecurity, and DevSecOps, with a proven track record of securing enterprise infrastructure, applications, and organizational data. Hands-on experience implementing and managing security scanning across the SDLC, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Dependency Scanning, Container Image Scanning, and Infrastructure as Code (IaC) Scanning using tools such as Trivy, Checkov, tfsec, Semgrep, SonarQube, OWASP ZAP, Snyk, or equivalent. Strong expertise in designing and implementing enterprise security architectures, including Zero Trust, Identity & Access Management (IAM), Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and data protection strategies. Extensive experience performing vulnerability assessments, security audits, penetration testing coordination, threat detection, incident response, digital forensics, and implementing effective remediation measures. Deep understanding of cloud security best practices across AWS and/or Google Cloud Platform, including security services such as IAM, KMS, WAF, GuardDuty, Security Hub, CloudTrail, CloudWatch, and cloud compliance frameworks. Strong knowledge of network and infrastructure We are lo

One address, no account. We’ll tell you when matching roles go live.

More at Web Spiders

Related open roles

View all roles