
Senior Cloud Site Reliability Engineer, Actimize(SecOps Engineer)
- Pune, Maharashtra
- Permanent
- Full-time
- Security Architecture & Implementation
- Design and implement security controls across AWS infrastructure and CI/CD pipelines.
- Ensure compliance with industry standards (e.g., ISO 27001, SOC 2, GDPR).
- Threat Detection & Response
- Proactively monitor, detect, and respond to security threats using modern alerting and SIEM tools.
- Develop and maintain automated threat intelligence and anomaly detection systems.
- Incident Response
- Lead and coordinate incident response efforts, including investigation, containment, and remediation.
- Maintain and continuously improve incident response playbooks and runbooks.
- Conduct post-incident reviews and root cause analyses to strengthen security posture.
- Automation & Infrastructure as Code
- Build and maintain automated security checks and remediation workflows using tools like Terraform, CloudFormation, and AWS Config.
- Integrate security into CI/CD pipelines using tools like GitHub Actions, Jenkins, or GitLab CI.
- Networking & Cloud Security
- Manage and secure VPCs, subnets, security groups, and firewalls.
- Implement secure API gateways, load balancers, and IAM policies.
- Security Awareness & Collaboration
- Work closely with engineering teams to embed security best practices into development workflows.
- Conduct regular security reviews, audits, and penetration tests.
- 4+ years of experience in DevSecOps, Cloud Security, or related roles.
- Strong hands-on experience with AWS services (EC2, S3, IAM, Lambda, CloudTrail, GuardDuty, etc.).
- Proficiency in networking concepts (TCP/IP, DNS, VPN, firewalls).
- Experience with automation tools (Terraform, Ansible, Python, Bash).
- Familiarity with security monitoring tools (e.g., Datadog, Splunk, AWS Security Hub).
- Knowledge of DevOps practices and CI/CD pipelines.
- Excellent problem-solving and communication skills.
- Be able to attend on
- AWS Security Specialty or other relevant certifications.
- Experience with container security (e.g., Docker, Kubernetes).
- Knowledge of zero-trust architecture and secure software development lifecycle (SSDLC).