AWS DevSecOps Sr. Engineer

2 days ago


India Photon Group Full time ₹ 12,00,000 - ₹ 36,00,000 per year
Description

About the Role:

We are seeking an experienced and highly motivated Senior AWS DevSecOps Engineer / Tester with expertise in policy development, security automation, and infrastructure-as-code (IaC). The ideal candidate will have a strong background in AWS cloud environments, DevSecOps principles, and security policy mapping and enforcement. This role will focus on creating and automating security policies, mapping them to cloud infrastructure, and ensuring that our security posture remains strong and compliant across all stages of the software development lifecycle.

You will work closely with cross-functional teams to define security requirements, integrate security tools and processes into the CI/CD pipeline, and continuously improve the security automation framework.

Key Responsibilities:

Policy Development & Mapping:

  • Design, develop, and maintain security policies for AWS environments, ensuring compliance with industry standards (e.g., NIST, CIS, ISO
  • Map and integrate security policies into infrastructure and applications deployed on AWS using Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, and AWS CDK.
  • Create automated processes for security policy enforcement, auditing, and monitoring.
  • Develop security rules and guardrails using AWS native services (AWS Config, AWS Security Hub, AWS GuardDuty, etc.) and third-party security tools.

DevSecOps Engineering:

  • Build and maintain the CI/CD pipeline with embedded security testing (SAST, DAST, IAST) and automated compliance checks.
  • Automate security vulnerability assessments and remediation in the AWS environment using tools like AWS Inspector, Qualys, and other static and dynamic analysis tools.
  • Collaborate with development teams to implement security in the software development lifecycle (SDLC), shifting security left and automating security testing.
  • Create and maintain AWS security best practices, security controls, and infrastructure standards.

Testing & Vulnerability Management:

  • Conduct manual and automated penetration testing, vulnerability assessments, and code reviews focused on AWS-based applications and infrastructure.
  • Implement automated testing frameworks that validate security policies and configurations (e.g., infrastructure misconfigurations, exposed secrets).
  • Identify security gaps or vulnerabilities in AWS deployments and work with DevOps and development teams to remediate.
  • Continuously assess new threats, vulnerabilities, and attack vectors in AWS environments.

Collaboration & Reporting:

  • Work closely with DevOps, Development, and IT teams to ensure proper integration of security into cloud infrastructure and applications.
  • Provide regular security assessments, risk analysis reports, and security findings to senior leadership and relevant stakeholders.
  • Participate in incident response planning and execution, providing expertise in security issues related to AWS environments.
  • Train development teams on secure coding practices, security testing tools, and best practices for AWS security.

Continuous Improvement & Innovation:

  • Stay current with emerging trends in DevSecOps, cloud security, and AWS services.
  • Continuously improve security policies, tools, and processes to adapt to evolving threats.
  • Contribute to the creation and implementation of security automation frameworks for improved DevSecOps practices.

Required Qualifications:

Experience:

  • 5+ years of experience in AWS cloud environments with a focus on security, DevSecOps, and automation.
  • At least 3+ years of hands-on experience in security policy development and mapping for cloud infrastructure, specifically AWS.
  • Deep knowledge of AWS security tools and services, including AWS IAM, AWS KMS, AWS Config, AWS GuardDuty, AWS Shield, AWS WAF, and others.
  • Strong experience with infrastructure-as-code tools such as Terraform, AWS CloudFormation, and AWS CDK.
  • Experience with security testing tools (e.g., static and dynamic analysis, penetration testing, vulnerability scanning) and frameworks.
  • Hands-on experience with CI/CD pipeline security integration, GitOps, and container security (e.g., Docker, Kubernetes, EKS).

Technical Skills:

  • Proficiency in programming/scripting languages such as Python, Bash, or Go.
  • Experience with AWS Security Hub, AWS Inspector, AWS Trusted Advisor, and other AWS security services.
  • Familiarity with security testing frameworks (e.g., OWASP, SANS, NIST) and cloud security best practices.
  • Experience with integrating security tools into CI/CD pipelines (e.g., Jenkins, GitLab, CircleCI, etc.).
  • Strong knowledge of common security vulnerabilities (e.g., OWASP Top 10, CVE management) and how to mitigate them in cloud environments.

Certifications (Preferred):

  • AWS Certified Security – Specialty.
  • Certified DevSecOps Professional (CDP) or other related certifications.
  • CISSP, CISM, or equivalent security certifications are a plus.

Soft Skills:

  • Excellent problem-solving and analytical skills, with a keen attention to detail.
  • Strong communication skills, able to present complex security issues to both technical and non-technical audiences.
  • Ability to work independently and collaboratively in a fast-paced, dynamic environment.
  • Proactive mindset with a passion for automation, security, and continuous improvement.
  • Strong documentation skills, with the ability to create clear, concise, and actionable security reports.

Preferred Qualifications:

  • Experience with container security tools like Aqua Security, Twistlock, or Falco.
  • Hands-on experience with serverless architectures and security concerns in AWS Lambda, API Gateway, and other serverless services.
  • Familiarity with cloud-native security architectures and concepts (e.g., Zero Trust, defense in depth).
  • Experience with compliance frameworks and regulations (e.g., GDPR, HIPAA, SOC 2, PCI DSS).

  • DevSecOps Engineer

    2 weeks ago


    India lowtouch.ai Full time

    Company Description lowtouch.ai empowers businesses by providing no-code AI agents that automate processes, improve customer experiences, and optimize IT operations while ensuring data privacy and security within their own infrastructure. Our platform enhances business processes through AI-driven workflows, transforms help desk and customer support with...

  • DevSecOps Engineer

    2 weeks ago


    India lowtouch.ai Full time

    Company Description lowtouch.ai empowers businesses by providing no-code AI agents that automate processes, improve customer experiences, and optimize IT operations while ensuring data privacy and security within their own infrastructure. Our platform enhances business processes through AI-driven workflows, transforms help desk and customer support with...

  • DevSecOps Engineer

    2 weeks ago


    India lowtouch.ai Full time

    Company Description lowtouch.ai empowers businesses by providing no-code AI agents that automate processes, improve customer experiences, and optimize IT operations while ensuring data privacy and security within their own infrastructure. Our platform enhances business processes through AI-driven workflows, transforms help desk and customer support with...


  • Pune, India 3Pillar Full time

    Job Description We are seeking a highly motivated and experienced DevOps Engineer to join our team and champion a DevSecOps culture. This role will be focused on designing, building, and maintaining our CI/CD pipelines, with a specific focus on secure Java application builds, branching strategies, and automated deployments. The ideal candidate will be...

  • DevSecOps Engineer

    2 days ago


    Indore, Madhya Pradesh, , India HRhelpdesk Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Title - DevSecOps Engineer Location -Indore(On Site) Experience Years ​ Job Summary - We are seeking a DevSecOps Security Engineer with a focus on OWASP, MITRE, SOC 2, andNIST philosophy and compliance. The candidate should have experience with GitHub, GitHubActions, Dependabot, Azure, and AWS with at least basic familiarity with PHP and Ruby onRails....

  • DevSecOps Engineer

    5 days ago


    India Sycomp Full time

    About the Company Sycomp is a global IT services and logistics provider with extensive expertise in cloud, data center, endpoint management and security solutions. Sycomp’s diverse team of consultants and engineers deliver on the company’s mission to tackle challenging global IT projects through its state-of-the-art integration and warehouse centers and...

  • DevSecOps Engineer

    4 days ago


    India Sycomp Full time

    About the Company Sycomp is a global IT services and logistics provider with extensive expertise in cloud, data center, endpoint management and security solutions. Sycomp’s diverse team of consultants and engineers deliver on the company’s mission to tackle challenging global IT projects through its state-of-the-art integration and warehouse centers and...

  • DevSecOps Engineer

    4 weeks ago


    Hyderabad, Telangana, India, Telangana Intellect Design Arena Ltd Full time

    Job Summary:We are seeking a highly skilled DevSecOps Engineer to join our team and help integrate security at every phase of the software development lifecycle. The ideal candidate will have a strong background in DevOps, cloud infrastructure, and cybersecurity, with a focus on automation, continuous integration/continuous delivery (CI/CD), and secure...


  • Bengaluru, India HDFC Bank Full time

    Job Description Role Summary As a Lead DevSecOps Engineer, you will be responsible for embedding security practices within our DevOps processes. You'll work closely with development, operations, and security teams to ensure that security is built into our CI/CD pipelines, infrastructure, and applications from the ground up. Key Responsibilities - Integrate...


  • Bengaluru, Karnataka, India, Karnataka HDFC Bank Full time

    Role Summary As a Lead DevSecOps Engineer, you will be responsible for embedding security practices within our DevOps processes. You'll work closely with development, operations, and security teams to ensure that security is built into our CI/CD pipelines, infrastructure, and applications from the ground up. Key Responsibilities Integrate security tools and...