Engineering
178 days ago

DevOps Engineer

Oolka · Bangalore, Karnataka, India
This job has been flagged as a Not American
Pay
$15k–35k
Setting
On-site

Responsibilities:

  • Conduct Assessments and Testing: Perform regular vulnerability assessments, threat modeling, and penetration testing on applications and infrastructure to identify and mitigate risks.
  • Manage Infrastructure as Code (IaC) Security: Ensure secure configuration and management of cloud and on-premise infrastructure using IaC tools like Terraform or CloudFormation.
  • Monitor and Respond to Incidents: Set up and manage security monitoring and observability solutions (e. g., SIEM, ELK stack, and Grafana) to detect and respond to security incidents in real-time.
  • Ensure Compliance: Work with compliance teams to implement and enforce security policies and regulatory standards (e. g., GDPR, HIPAA, PCI-DSS, SOC 2).
  • Collaborate and Educate: Foster a security-aware culture by collaborating with cross-functional teams and providing guidance and training on secure coding practices and emerging threats.
  • Integrate Security: Embed security testing, reviews, and best practices into all phases of the development lifecycle.
  • Automate Security Processes: Design, implement, and maintain security automation tools (e. g., SAST, DAST, SCA, and secrets scanning) within the CI/CD pipelines to detect vulnerabilities early and efficiently.


Requirements:

  • Experience: Proven experience in a DevSecOps, DevOps, or a related role (typically 4+ years, more for senior positions).


Technical Proficiency:

  • CI/CD Tools: Jenkins, GitLab CI, GitHub Actions.
  • Cloud Platforms: Deep understanding of security on AWS.
  • Scripting/Programming: Proficiency in languages like Python, Bash, Shell, or Go for automation and custom tool development.
  • IaC and Containerization: Experience with Docker, Kubernetes, and Terraform.
  • Security Tools: Familiarity with vulnerability scanning, static/dynamic analysis, and secrets management tools (e. g., SonarQube, Snyk, HashiCorp Vault, OWASP ZAP).
  • Experience with AI/ML-based security tools for threat detection and risk forecasting.
Listed by Oolka for a position based in the United States. Employers on this board attest they are hiring domestically.