DevSecOps Engineer
Sutherland · Remote; Hyderabad, TS, India
- Senior
- Full-time
- Posted 2026-09-04
- Confirmed live on 25 September 2026
Job description
Job Description
Cloud Security — Primary
• Own cloud security posture management (CSPM) across GCP and AWS — continuous assessment, misconfiguration detection, and remediation tracking.
• Design and enforce IAM policies, service account hygiene, least-privilege access controls, and workload identity across multi-cloud environments.
• Implement VPC security controls — private service access, firewall rules, network policies, ingress/egress restrictions, and Private Google Access.
• Internalise and secure service endpoints — move external-facing services to internal load balancers, private endpoints, and VPN/interconnect. Continuously audit and reduce the public attack surface.
• Manage secrets hygiene — enforce Secret Manager (GCP) and AWS Secrets Manager, eliminate hardcoded credentials, and rotate secrets programmatically.
• Lead cloud security incident response — triage, contain, investigate, and remediate across cloud and Kubernetes environments.
• Own compliance reporting for SOC 2, HIPAA, and ISO 27001 — evidence collection, gap analysis, and control implementation.
• Conduct regular threat modelling, security reviews, and architecture risk assessments.
Kubernetes Security — Primary
• Harden GKE clusters — CIS benchmarks, pod security standards (restricted/baseline), and admission control policies.
• Implement and manage network policies to enforce east-west traffic segmentation between namespaces and services.
• Deploy and operate runtime security tooling (e.g. Falco) for threat detection inside cluster workloads.
• Manage Kubernetes RBAC with least-privilege principles. Audit and remediate overpermissioned service accounts.
• Secure the container supply chain — image scanning in CI (Trivy/Snyk), enforce signed images, and maintain a trusted registry policy.
• Implement Istio security controls — mTLS enforcement, authorisation policies, and east-west traffic observability.
• Continuously audit running workloads for security drift — privileged containers, host path mounts, and secrets in environment variables.
CI/CD & GitLab Security — Primary
• Secure the GitLab CI/CD pipeline end-to-end — protect runner environments, restrict pipeline permissions, enforce branch protection and MR approvals.
• Integrate SAST, DAST, dependency scanning, container scanning, and secret detection natively into GitLab CI. Own the triage and remediation workflow.
• Implement IaC security scanning (tfsec, Checkov) as a mandatory pipeline gate for all Terraform changes.
• Manage GitLab token hygiene — enforce expiry policies, rotate project tokens, and audit personal access token usage.
• Define and enforce pipeline security policies organization-wide using GitLab security policy-as-code.
Endpoint & Network Security — Primary
• Audit and reduce the external attack surface — inventory all public endpoints and drive internalization of services that do not need to be public.
• Implement and maintain WAF and Cloud Armor rules to protect externally exposed services.
• Enforce TLS certificate management — automate issuance, rotation, and enforce TLS 1.2+ across all endpoints.
• Manage bastion host security — enforce short-lived certificates (OS Login / IAP), eliminate persistent SSH keys, and log all administrative sessions.
• Own DNS security controls — DNSSEC, private DNS zones for internal services, split-horizon DNS where required.
Security Engineering & Automation
• Build security automation pipelines — policy enforcement, compliance checks, and vulnerability remediation as code.
• Instrument security observability in Datadog — threat detection dashboards and alert tuning for cloud and Kubernetes signals.
• Develop and maintain runbooks for security incidents, vulnerability response, and access reviews.
• Champion security training and awareness. Conduct secure code reviews and threat modelling workshops.
TECH STACK
Required
• GCP — Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager, Binary Authorization
• AWS — GuardDuty, Security Hub, IAM, KMS, Macie, AWS Config
• Kubernetes — GKE hardening, pod security standards, network policies, RBAC, admission controllers
• GitLab — CI/CD security, SAST/DAST, dependency scanning, pipeline policy management
• Terraform — IaC security scanning (tfsec, Checkov), secure module design
• Datadog — security monitoring, threat detection, alert management
• Istio — mTLS, authorisation policies, service mesh security
Good to have
• Falco, OPA/Gatekeeper, HashiCorp Vault, Wiz/Orca/Prisma Cloud, Trivy/Snyk, SIEM (Splunk/Chronicle), Python or Go
Qualifications
Must have
• 7+ years in DevSecOps, cloud security, or infrastructure security engineering.
• Deep hands-on experience securing Kubernetes clusters in production — RBAC, network policies, pod security, and runtime protection.
• Proven experience with GCP and/or AWS security services and IAM design.
• Strong CI/CD security knowledge — pipeline hardening, secrets management, a
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at Sutherland
- Architect – Azure DR -Lead · Remote; Hyderabad, TS, India
- Deutschsprachige Kundenbetreuer/-innen · Pristina, 1, Kosovo
- Bilingual Spanish Customer Service- Insurance Billing/Self Pay · Remote; Charlotte, NC, United States
- French Customer Service · Cairo, Cairo Governorate, Egypt
- French speakers needed · Cairo, Cairo Governorate, Egypt
- Credit Operations Analyst · Barranquilla, Atlantico, Colombia
- Test 09222026 AI interview · Bogotá, Bogota, Colombia
- Scrum Master · Bengaluru, KA, India