Supple Soft Pvt.Ltd.
Website:
supplesoft.com
Job details:
About the Role
SuppleSoft Private Limited is looking for an experienced Cloud Security Policy-as-Code (PaC) Engineer to join our DevSecOps and Cloud Security team. In this role, you will design, develop, and implement enterprise-grade security policies for Kubernetes platforms using OPA Gatekeeper, Rego, and Terraform Sentinel. You will work closely with Cloud Engineering, Information Security, Platform Engineering, and Application teams to build secure, scalable, and compliant cloud-native environments.
If you are passionate about Kubernetes security, Policy-as-Code, and cloud platform security, we'd love to hear from you.
Key Responsibilities
- Design and implement enterprise security policies using OPA Gatekeeper and Rego.
- Develop and maintain ConstraintTemplates, Constraints, and reusable policy libraries.
- Create admission control policies to validate Kubernetes resources before deployment.
- Implement secure-by-default Kubernetes controls, including:
- RBAC
- Network Policies
- Pod Security Standards
- Workload Identity
- Security Contexts
- Secret Management
- Develop policies to enforce:
- Internal CIDR/IP restrictions
- Container image validation
- Namespace restrictions
- Resource limits
- Label and annotation compliance
- Istio Service Mesh security
- Write and execute policy tests using Gator and OPA Test.
- Integrate Policy-as-Code into CI/CD and GitOps workflows.
- Support Kubernetes platforms running on AWS EKS, Google GKE, and Red Hat OpenShift.
- Collaborate with DevOps, Security, and Platform Engineering teams to improve cloud security posture.
- Perform security assessments against CIS Benchmarks and enterprise compliance standards.
- Participate in code reviews, pull requests, and technical design discussions.
Required SkillsKubernetes
- Kubernetes Architecture
- Pods, Deployments, Services
- Namespaces
- RBAC
- Network Policies
- Pod Security Standards
- Admission Controllers
- CRDs
- Service Accounts
- Workload Identity
OPA Gatekeeper & Rego
- OPA Gatekeeper
- Rego Policy Development
- ConstraintTemplates
- Constraints
- Admission Control Policies
- Policy Testing
- Gator
- OPA CLI
Cloud Platforms
- AWS (EKS)
- Google Cloud Platform (GKE)
- Red Hat OpenShift
- Multi-cloud security best practices
Infrastructure as Code
- Terraform
- Terraform Sentinel
- Helm
- Kustomize
- YAML
DevSecOps & CI/CD
- Jenkins
- GitHub Actions
- GitLab CI
- Azure DevOps
- Argo CD
- GitOps
Networking & Security
- CIDR and IP Addressing
- VPC Networking
- Kubernetes Networking
- Network Segmentation
- Service Mesh (Istio)
- mTLS
- Zero Trust Architecture
- Cloud IAM
- Secure Communication Patterns
Container Security
- Docker
- Image Scanning
- Runtime Security
- Vulnerability Management
- Trivy (preferred)
Required Experience
- 6+ years of experience in Cloud Engineering, DevSecOps, or Cloud Security.
- 3+ years of hands-on experience with Kubernetes security.
- Experience developing Policy-as-Code using OPA Gatekeeper and Rego.
- Strong understanding of Kubernetes networking, RBAC, and workload security.
- Experience integrating security into CI/CD pipelines.
- Experience working in Agile/Scrum environments.
- Excellent troubleshooting and problem-solving skills.
Preferred Qualifications
- Experience with Terraform Sentinel or similar policy frameworks.
- Experience with Istio Service Mesh.
- Knowledge of CIS Kubernetes Benchmarks, NIST, and Cloud Control Matrix (CCM).
- Experience with GitOps platforms such as Argo CD or Flux.
- Familiarity with Python or Bash scripting.
Click on Apply to know more.