DL
DevOps Enginner -- Chennai
Diverse Lynx India
- 🇮🇳 India
- On-site
- 19 hours ago
- Devops
- CI/CD
- GitHub Actions
- GitLab CI
- Azure DevOps
- Jenkins
- SAST
- DAST
- SonarQube
- Snyk
- Burp Suite
- Dependabot
- Nexus
- Secrets Management
- Azure
- Key Vault
- AWS
- GCP
- triage
- Trivy
- Grype
- Prisma
- cosign
- Sigstore
- IaC
- Python
- Bash
- Terraform
- Ansible
- NIST
- Kubernetes
- GKE
- AKS
- EKS
19 hours ago
Skill Set:7 – 12 Years (with strong focus on CI/CD engineering, pipeline security controls, automated testing gates, and Policy as Code)
Must-Have (Candidates must demonstrate depth in core DevOps engineering and a blend/combination of the following specialisms)
• Secure CI/CD Pipeline Engineering: Extensive hands-on experience designing, automating, and maintaining resilient CI/CD pipelines across enterprise platforms (GitHub Actions, GitLab CI, Azure DevOps, Jenkins, Harness).
• Application Security Testing (SAST / DAST / SCA): Practical experience embedding and operationalising automated security scanners natively into pipeline workflows: Static Application Security Testing (SonarQube, Checkmarx, Snyk Code, Veracode), Dynamic Application Security Testing (ZAP, Burp Suite, Rapid7, StackHawk), and Software Composition Analysis / Dependency Scanning (Snyk Open Source, Black Duck, Dependabot, Nexus Lifecycle).
• Policy as Code & Automated Quality Gates: Proven track record authoring and enforcing declarative compliance policies and release gates using Open Policy Agent (OPA), Rego, Checkov, tfsec, Terrascan, or Kyverno to block non-compliant code before deployment.
• Secrets Detection & Management: Experience implementing automated pre-commit and pipeline secrets detection (GitGuardian, TruffleHog, Gitleaks) and integrating enterprise secrets management systems (HashiCorp Vault, Azure Key Vault, AWS Secrets Manager, GCP Secret Manager).
• Secure Software Delivery & Container Security: Deep understanding of container image scanning, vulnerability triage, runtime security baselines, and artifact signing (Trivy, Grype, Prisma Cloud, Cosign / Sigstore).
• Scripting & Infrastructure as Code: Strong proficiency in Python, Bash, or Go for automation scripting, coupled with hands-on Terraform / Ansible experience for reproducible infrastructure provisioning.
Good-to-Have
• Understanding of enterprise Secure Software Development Lifecycle (SSDLC) operating models, specifically Inner Loop (developer workstation/IDE feedback) vs. Outer Loop (governed platform gates and continuous compliance) paradigms.
• Knowledge of Software Bill of Materials (SBOM) generation, supply chain integrity frameworks (SLSA, NIST SSDF), and artifact provenance tracking.
• Exposure to multi-cloud landing zones and Kubernetes orchestration (GKE, AKS, EKS).
DevOps Enginner -- Chennai · Diverse Lynx India