Platform Security & DevSecOps Engineer in India at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Platform Security & DevSecOps Engineer based in India.
This role offers the opportunity to embed security throughout the software development lifecycle and cloud infrastructure.
You will help build secure, resilient platforms while automating security controls across modern engineering environments.
The position combines DevSecOps, cloud security, vulnerability management, and compliance in a highly technical setting.
You will work hands-on with CI/CD pipelines, containers, infrastructure-as-code, identity controls, and security tooling.
Your work will directly contribute to protecting sensitive data and reducing security risks across critical platforms.
The ideal environment is proactive and automation-focused, with security treated as an integral part of engineering rather than an afterthought.
This is a strong opportunity for an experienced security professional looking to make a measurable impact across cloud-native technology.
- Integrate and manage automated Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) solutions within CI/CD pipelines.
- Assess, configure, and harden cloud environments, including IAM policies, VPC security groups, encryption mechanisms, and secrets management.
- Conduct regular vulnerability assessments and coordinate penetration testing activities across applications, infrastructure, and dependencies.
- Identify, prioritize, and support the rapid remediation of vulnerabilities affecting infrastructure, applications, dependencies, and infrastructure-as-code.
- Implement security controls and automated threat-detection capabilities across cloud and DevOps environments.
- Strengthen container security across Docker and Kubernetes environments, ensuring secure deployment and runtime practices.
- Support incident-response workflows and contribute to the detection, investigation, and mitigation of security threats.
- Help maintain compliance with applicable security and privacy frameworks, including GDPR, India's DPDP Act, and SOC 2.
- Monitor security risks and continuously improve the organization's security posture, processes, and automation.
- Collaborate with engineering and infrastructure teams to embed security practices into development and deployment workflows.
- 4–7 years of professional experience in information security, cloud security, cloud architecture, DevSecOps, or a closely related engineering discipline.
- Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related field.
- Strong knowledge of Linux security and secure system administration practices.
- Hands-on experience with container security technologies, particularly Docker and Kubernetes.
- Solid understanding of infrastructure-as-code security and experience using automated scanning approaches.
- Good knowledge of network protocols and fundamental networking security concepts.
- Experience implementing security testing and automated security controls within CI/CD pipelines.
- Practical understanding of cloud security concepts, including identity and access management, network controls, encryption, and secrets management.
- Experience with vulnerability assessment, remediation, and penetration-testing coordination.
- Familiarity with security and privacy frameworks such as GDPR, DPDP Act, and SOC 2.
- Experience developing or implementing automated threat detection and incident-response workflows.
- Proactive, security-first mindset with strong analytical and problem-solving abilities.
- Ability to collaborate effectively with engineering and technical teams while communicating security risks clearly.
- Strong attention to detail and the ability to prioritize security issues based on business and technical impact.
- Annual compensation: INR 1,500,000–2,200,000.
- Work arrangement: Fully remote within India.
- Employment: Full-time, mid-senior-level position.
- Experience range: 4–7 years.
- Opportunity to work across cloud security, DevSecOps, vulnerability management, container security, and compliance.
- Hands-on exposure to modern cloud-native infrastructure and security automation.
- Opportunity to influence security practices across the software development lifecycle.
- Collaborative environment focused on building secure, scalable, and resilient technology platforms.