
DevSecOps Engineer - GOV2
- Gurgaon, Haryana
- Permanent
- Full-time
- Design, implement, and manage CI/CD pipelines using tools like Jenkins, GitHub etc.
- Integrate and manage security tools such as Snyk, SonarQube, JFrog etc., to detect vulnerabilities early in the development lifecycle.
- Automate security testing and compliance checks as part of the DevOps process.
- Collaborate with development teams to remediate identified vulnerabilities.
- Ensure infrastructure as code (IaC) is securely designed and deployed.
- Drive container security and orchestration using tools like Docker, Kubernetes, Trivy, etc.
- Maintain compliance with security standards (e.g., OWASP, NIST, ISO 27001).
- Contribute to monitoring and incident response automation.
- Strong hands-on experience with Jenkins, Snyk, SonarQube, and static/dynamic code analysis tools.
- Proficiency in scripting languages (e.g., Python, Bash).
- Experience with version control systems like Git.
- Working knowledge of container security, IaC (Terraform, CloudFormation), and secrets management tools (e.g., Vault, AWS Secrets Manager).
- Familiarity with security practices in cloud environments (AWS, Azure, or GCP).
- Certifications such as Certified DevSecOps Professional, AWS Security, or Azure Security Engineer.
- Knowledge of compliance frameworks (SOC 2, HIPAA, GDPR).
- Experience in threat modeling and risk assessment.