ServCrust
Formatting this description...
We are Hiring DevSecOps Engineer Hyderabad | Onsite | Full-time Role Overview: We’re looking for a technically strong and security-focused DevSecOps Engineer to embed, automate, and operationalize security across our CI/CD pipelines and cloud-native environments. You will act as the bridge between engineering and security teams ensuring that security controls, guardrails, and best practices are integrated throughout the SDLC. This role is hands-on, involving daily monitoring, pipeline security enforcement, vulnerability triage, and supporting development teams with secure delivery practices. Key Responsibilities: Secure DevOps Operation: Monitor CI/CD pipelines for policy violations, secret leakage, insecure configs, and bypass attempts. Review SAST/DAST/IAST scan results (SonarQube, Checkmarx, ZAP, OWASP Dependency-Check) and work with developers to prioritize fixes. Analyze container security reports and recommend base-image hardening updates. Perform IaC security reviews for Terraform and CloudFormation templates. Maintain and enforce pipeline security guardrails (code signing, mandatory static analysis, approval stages). Monitor cloud and pipeline security dashboards for abnormal behavior. Respond to real-time security findings in CI/CD and cloud workloads. Security Automation and Collaboration: Implement automated security checks, quality gates, and policy-as-code controls within CI/CD. Maintain a JIRA vulnerability board and track remediation SLAs. Write automation scripts (Python, Bash, Groovy) to reduce manual security tasks. Collaborate with dev and platform teams on secure coding, dependency hygiene, and secure deployments. Participate in threat modelling, architecture reviews, and secure design discussions. Document pipeline security procedures, runbooks, and developer guidance. Evaluate new security tools, run POCs, and integrate selected solutions. Qualifications 2-4 years of experience in DevSecOps, AppSec, or Security Engineering. Strong understanding of CI/CD workflows and security integration. Hands-on scripting/automation experience (Python, Bash, Groovy, YAML pipelines). Familiarity with cloud-native deployments and vulnerability management. Knowledge of secure coding practices and SDLC best practices. Understanding of OWASP Top 10, SANS CWE 25, container security benchmarks. #Hiring #DevSecOps #AppSec #CloudSecurity #AWS #SecurityEngineer #CyberSecurityJobs #HyderabadJobs #OnsiteJobs #TechJobs #Cantellat #PipelineSecurity #Automation #SecureSDLC #NowHiring #jobs #hiring #DevOpsEngineer #CloudEngineering #DevOpsJobs #Terraform #Kubernetes #Docker #InfrastructureAsCode #CI_CD #TechCareers Show more