远程工作雷达

DevSecOps工程师

DevSecOps Engineer

开发工程未标注地域
公司Sutherland
薪资未公开
工作地点Hyderabad, TS, India
地域资格未标注地域
时区要求无特别要求
用工类型Full-time
发布时间12 天前
数据来源SmartRecruiters
前往企业招聘页投递 →

Sutherland 正在寻找一位经验丰富的 DevSecOps 工程师,该工程师将把安全嵌入到我们的云基础设施和软件交付流水线的每一层。您的主要职责是确保我们的 GCP 和 AWS 环境、 Kubernetes 集群、 CI/CD 流水线和内部端点安全、合规且具备抗攻击能力,同时不降低工程效率

云安全 — 主要职责
· 负责跨 GCP 和 AWS 的云安全态势管理 (CSPM) — 持续评估、错误配置检测和修复跟踪。
· 设计并实施 IAM 策略、服务账户卫生、最小权限访问控制以及多云环境中的工作负载身份。
· 实施 VPC 安全控制 — 私有服务访问、防火墙规则、网络策略、入站/出站限制和私有 Google 访问。
· 内化并保护服务端点 — 将面向外部的服务迁移到内部负载均衡器、私有端点和 VPN/互连。持续审计并减少公共攻击面。
· 管理密钥卫生 — 强制使用 Secret Manager (GCP) 和 AWS Secrets Manager,消除硬编码凭证,并以程序化方式轮换密钥。
· 领导云安全事件响应 — 在云和 Kubernetes 环境中进行优先级排序、遏制、调查和修复。
· 负责 SOC 2、HIPAA 和 ISO 27001 合规报告 — 收集证据、分析差距并实施控制措施。
· 定期进行威胁建模、安全审查和架构风险评估。
Kubernetes 安全 — 主要职责
· 加固 GKE 集群 — 符合 CIS 基准、Pod 安全标准(受限/基线)和准入控制策略。
· 实施和管理网络策略,以在命名空间和服务之间强制东西向流量分段。
· 部署并运行运行时安全工具(如 Falco),用于集群工作负载中的威胁检测。
· 使用最小权限原则管理 Kubernetes RBAC。审计并修复过度授权的服务账户。
· 保护容器供应链 — 在 CI 中进行镜像扫描(Trivy/Snyk),强制使用签名镜像,并维护受信任的注册表策略。
· 实施 Istio 安全控制 — 强制 mTLS、授权策略和东西向流量可观测性。
· 持续审计运行中的工作负载,查找安全偏差 — 特权容器、主机路径挂载和环境变量中的密钥。
CI/CD 与 GitLab 安全 — 主要职责
· 端到端保护 GitLab CI/CD 流水线 — 保护运行器

查看英文原文

Sutherland is seeking an experienced DevSecOps Engineer who will embed security into every layer of our cloud infrastructure and software delivery pipeline. Your primary responsibility is to ensure our GCP and AWS environments, Kubernetes clusters, CI/CD pipelines, and internal endpoints are secure, compliant, and hardened — without slowing down engineering velocity

Cloud Security — Primary
· Own cloud security posture management (CSPM) across GCP and AWS — continuous assessment, misconfiguration detection, and remediation tracking.
· Design and enforce IAM policies, service account hygiene, least-privilege access controls, and workload identity across multi-cloud environments.
· Implement VPC security controls — private service access, firewall rules, network policies, ingress/egress restrictions, and Private Google Access.
· Internalise and secure service endpoints — move external-facing services to internal load balancers, private endpoints, and VPN/interconnect. Continuously audit and reduce the public attack surface.
· Manage secrets hygiene — enforce Secret Manager (GCP) and AWS Secrets Manager, eliminate hardcoded credentials, and rotate secrets programmatically.
· Lead cloud security incident response — triage, contain, investigate, and remediate across cloud and Kubernetes environments.
· Own compliance reporting for SOC 2, HIPAA, and ISO 27001 — evidence collection, gap analysis, and control implementation.
· Conduct regular threat modelling, security reviews, and architecture risk assessments.
Kubernetes Security — Primary
· Harden GKE clusters — CIS benchmarks, pod security standards (restricted/baseline), and admission control policies.
· Implement and manage network policies to enforce east-west traffic segmentation between namespaces and services.
· Deploy and operate runtime security tooling (e.g. Falco) for threat detection inside cluster workloads.
· Manage Kubernetes RBAC with least-privilege principles. Audit and remediate overpermissioned service accounts.
· Secure the container supply chain — image scanning in CI (Trivy/Snyk), enforce signed images, and maintain a trusted registry policy.
· Implement Istio security controls — mTLS enforcement, authorisation policies, and east-west traffic observability.
· Continuously audit running workloads for security drift — privileged containers, host path mounts, and secrets in environment variables.
CI/CD & GitLab Security — Primary
· Secure the GitLab CI/CD pipeline end-to-end — protect runner environments, restrict pipeline permissions, enforce branch protection and MR approvals.
· Integrate SAST, DAST, dependency scanning, container scanning, and secret detection natively into GitLab CI. Own the triage and remediation workflow.
· Implement IaC security scanning (tfsec, Checkov) as a mandatory pipeline gate for all Terraform changes.
· Manage GitLab token hygiene — enforce expiry policies, rotate project tokens, and audit personal access token usage.
· Define and enforce pipeline security policies organization-wide using GitLab security policy-as-code.
Endpoint & Network Security — Primary
· Audit and reduce the external attack surface — inventory all public endpoints and drive internalization of services that do not need to be public.
· Implement and maintain WAF and Cloud Armor rules to protect externally exposed services.
· Enforce TLS certificate management — automate issuance, rotation, and enforce TLS 1.2+ across all endpoints.
· Manage bastion host security — enforce short-lived certificates (OS Login / IAP), eliminate persistent SSH keys, and log all administrative sessions.
· Own DNS security controls — DNSSEC, private DNS zones for internal services, split-horizon DNS where required.
Security Engineering & Automation
· Build security automation pipelines — policy enforcement, compliance checks, and vulnerability remediation as code.
· Instrument security observability in Datadog — threat detection dashboards and alert tuning for cloud and Kubernetes signals.
· Develop and maintain runbooks for security incidents, vulnerability response, and access reviews.
· Champion security training and awareness. Conduct secure code reviews and threat modelling workshops.
TECH STACK
Required
· GCP — Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager, Binary Authorization
· AWS — GuardDuty, Security Hub, IAM, KMS, Macie, AWS Config
· Kubernetes — GKE hardening, pod security standards, network policies, RBAC, admission controllers
· GitLab — CI/CD security, SAST/DAST, dependency scanning, pipeline policy management
· Terraform — IaC security scanning (tfsec, Checkov), secure module design
· Datadog — security monitoring, threat detection, alert management
· Istio — mTLS, authorisation policies, service mesh security
Good to have
· Falco, OPA/Gatekeeper, HashiCorp Vault, Wiz/Orca/Prisma Cloud, Trivy/Snyk, SIEM (Splunk/Chronicle), Python or Go

Must have
· 7+ years in DevSecOps, cloud security, or infrastructure security engineering.
· Deep hands-on experience securing Kubernetes clusters in production — RBAC, network policies, pod security, and runtime protection.
· Proven experience with GCP and/or AWS security services and IAM design.
· Strong CI/CD security knowledge — pipeline hardening, secrets management, and integrated scanning.
· Experience internalising service endpoints and reducing cloud attack surface.
· Familiarity with HIPAA, SOC 2, or ISO 27001 compliance in regulated environments.
· Clear communication skills — able to explain a critical vulnerability to a CTO and write a runbook for an engineer.
 
Nice to have
· Certified Kubernetes Security Specialist (CKS).
· Google Professional Cloud Security Engineer or AWS Security Specialty certification.
· eBPF-based security tooling (Cilium, Tetragon), penetration testing, or red team experience.
· Threat modelling using STRIDE or PASTA. Service mesh security beyond Istio.

All your information will be kept confidential according to EEO guidelines.

本页面信息整理自 SmartRecruiters,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位