GCS
Website:
gcstechtalent.com
Job details:
Senior DevSecOps Engineer
Location: Pune, India
Function: DevOps / Production Operations
Reports to: Senior Production Operations Leadership
Working Model: Hybrid
People Responsibility: No direct reports
Role Summary
We are seeking a hands-on Senior DevSecOps Engineer to strengthen secure software delivery, cloud infrastructure, IAM governance and security automation across a global technology environment.
This role combines strong DevOps and cloud engineering expertise across AWS, Kubernetes/EKS, Infrastructure as Code, CI/CD, automation and troubleshooting with practical DevSecOps capability spanning IAM governance, vulnerability management, open-source scanning, static analysis, policy as code, software supply chain security, cloud and container security, and automated compliance evidence.
The successful candidate will enable product and engineering teams to deliver securely by translating enterprise security and compliance requirements into practical, reusable engineering controls rather than relying on manual reviews or end-stage security gates.
The role works closely with Product, Development, Architecture, Security, SRE, Quality, cloud platform and compliance stakeholders and requires strong communication, technical judgement and end-to-end ownership.
Responsibilities
- Senior DevOps engineering: Design, build and continuously improve reliable, scalable and automated AWS, Kubernetes/EKS, Infrastructure as Code and CI/CD capabilities while integrating security throughout the engineering lifecycle.
- DevSecOps capability ownership: Drive practical adoption of secure software delivery practices across product teams, translating security, architecture and compliance requirements into reusable engineering controls and implementation patterns.
- Secure CI/CD and policy enforcement: Embed automated security checks, approvals, evidence collection and policy enforcement into GitLab CI/CD and related delivery workflows while ensuring controls remain maintainable and proportionate to risk.
- Application and dependency security: Implement and improve SAST, Software Composition Analysis, open-source dependency scanning, vulnerability detection, secrets detection and artifact controls, alongside actionable remediation workflows.
- Software supply chain security: Strengthen provenance, artifact integrity, dependency governance, build security, access boundaries and traceability across source code, pipelines, registries, deployment and runtime environments.
- IAM governance and automation: Engineer reusable IAM patterns, least-privilege controls, role and access lifecycle automation, secrets and configuration management, access reviews and evidence collection across AWS and delivery platforms.
- Cloud, container and infrastructure security: Implement secure AWS, Kubernetes/EKS, network, workload, container and Infrastructure as Code patterns, including scanning, hardening, admission controls, policy as code and remediation automation.
- Vulnerability remediation: Partner with product teams and security stakeholders to triage findings, clarify ownership and risk, prioritise remediation, reduce false-positive noise, track exceptions and drive high-value actions through to verified closure.
- Compliance and audit readiness: Automate security-control evidence where practical, improve traceability and support ISO 27001 and related assurance requirements.
- Security enablement: Coach engineers, create practical standards and reusable examples and facilitate threat-aware design and secure delivery conversations without becoming a manual approval bottleneck.
- Operational security: Support investigations and long-term corrective actions for security-related production issues in partnership with SRE, Architecture, Security and responsible product teams.
- Maintain clear documentation covering security controls, exceptions, technical decisions and remediation status.
- Perform other related duties where required.
Required Qualifications & Experience
- Bachelor’s degree in Computer Science, Software Engineering, Information Technology or a related technical field, or equivalent practical experience.
- 5+ years of hands-on experience in DevOps, cloud engineering, platform engineering, infrastructure engineering, software engineering or a closely related technical role.
- Strong hands-on experience with AWS, including services such as EC2, VPC, S3, IAM, RDS/Aurora, load balancing, Lambda and related cloud services.
- Production-level experience with Kubernetes, ideally Amazon EKS, including containerised workloads, networking, security, scalability, upgrades and operational readiness.
- Strong experience with Infrastructure as Code, preferably Terraform, and infrastructure automation practices.
- Experience designing, building and improving CI/CD pipelines, preferably using GitLab CI/CD, for consistent, secure and reliable deployments.
- Strong scripting and automation skills within Linux-based or cloud-native environments using Bash, Python or similar languages.
- Ability to troubleshoot complex infrastructure, application, deployment, networking, security and operational issues across multiple layers.
- Demonstrated hands-on DevSecOps experience embedding security controls into CI/CD pipelines, cloud infrastructure, container platforms or developer workflows.
- Strong experience with IAM design and governance, least privilege, access lifecycle controls, secrets management and security automation within AWS environments.
- Experience with SAST, SCA, open-source dependency governance, vulnerability management and secrets detection using enterprise or equivalent tooling.
- Experience implementing policy as code, Infrastructure as Code scanning, container/Kubernetes security and secure software supply chain controls.
- Strong written and verbal English communication skills.
- Ability to explain security risks and remediation requirements clearly to engineers, product stakeholders, architects and leadership.
- Strong technical judgement, curiosity and ownership, with the ability to balance strategic improvement with hands-on engineering delivery.
- Ability to influence stakeholders and engineering teams without formal authority.
Preferred Qualifications & Experience
- Experience working within a global or enterprise technology environment with distributed teams.
- Experience collaborating with Security, Compliance, Enterprise Architecture, Cloud Platform, SRE, Product and vendor teams.
- Experience with technologies such as:
- Datadog
- AWS CloudWatch
- SonarQube
- JFrog
- Veracode
- LaunchDarkly
- Helm
- Ansible
- Secrets-management platforms or equivalent technologies
- Familiarity with application stacks such as PostgreSQL, .NET, Angular, APIs and cloud-native microservices.
- Experience with security technologies such as GitLab security capabilities, AWS security services, Open Policy Agent (OPA), Gatekeeper or equivalent tooling.
- Familiarity with threat modelling, security architecture reviews, SBOMs, artifact signing, provenance and software supply chain security frameworks.
- Experience supporting ISO 27001, audit readiness, secure SDLC practices or regulated environments.
- Experience mentoring engineers, improving technical standards and enabling adoption through documentation, coaching, reusable examples and hands-on collaboration.
- Relevant certifications across AWS, Kubernetes, Terraform, DevOps, platform engineering, cloud security, DevSecOps, application security or information security would be advantageous.
Click on Apply to know more.