Job Responsibilities:
We are looking for a highly skilled DevSecOps Engineer to join our Cloud Security team and help secure large-scale cloud infrastructure powering global FinTech products. You will work across AWS, Kubernetes, CI/CD pipelines, and cloud-native platforms to identify security risks, implement automated security controls, and build scalable security solutions integrated into the software development lifecycle.
The ideal candidate should have a strong engineering mindset, hands-on cloud security expertise, and experience building secure, production-grade platforms in a product-based startup environment.
Key Responsibilities:
- Secure AWS cloud infrastructure, Kubernetes clusters, and containerized workloads.
- Design and implement cloud security guardrails including IAM, network security, secrets management, and infrastructure hardening.
- Integrate security scanning and compliance checks into CI/CD pipelines.
- Automate vulnerability detection, secrets scanning, dependency scanning, and infrastructure security validation.
- Conduct threat modeling, security architecture reviews, and risk assessments.
- Investigate security incidents, perform root cause analysis, and implement preventive controls.
- Build internal security automation tools using Python, Go, or similar languages.
- Secure Infrastructure-as-Code (Terraform) deployments and cloud configurations.
- Collaborate with engineering teams to embed security throughout the software development lifecycle.
- Drive security best practices, vulnerability management, and continuous security improvements.
Mandatory Skills:
- AWS Cloud Security (IAM, VPC, Security Groups, CloudTrail, GuardDuty, IAM Hardening)
- Kubernetes &
- Container Security
- DevSecOps &
- CI/CD Security
- Terraform (Infrastructure as Code)
- Cloud Security Architecture
- Vulnerability Management &
- Threat Modeling
- Secrets Management
- Python / Go scripting for security automation
- Infrastructure Hardening
- Logging, Monitoring &
- Security Observability
Required Experience:
- 48 years of experience in Cloud Security, DevSecOps, or Security Engineering.
- Strong hands-on expertise securing AWS cloud environments.
- Experience securing Kubernetes clusters and containerized applications.
- Experience integrating automated security controls into CI/CD pipelines.
- Hands-on experience with Infrastructure-as-Code using Terraform.
- Strong understanding of cloud security threats, privilege escalation, credential leakage, network exposure, and supply chain security.
- Experience building security automation using Python, Go, or similar languages.
- Excellent communication and cross-functional collaboration skills.
Preferred Skills:
- Penetration Testing
- Security Research
- Bug Bounty Participation
- Open-source Security Contributions
- Leadership or mentoring experience