
DevSecOps Engineer
- DevSecOps
- CI/CD
- Vulnerability Management
- Devops
- Change Management
- AWS
- GCP
- Azure
- IaC
- Terraform
- Kubernetes
- Helm
- IAM
- Configuration Management
- Docker
- SAST
- DAST
- Secrets Management
- ISO 27001
- SOC2
- PCI DSS
- Incident Response
- Disaster Recovery
- Jenkins
- GitHub Actions
- GitLab CI
- Azure DevOps
- Network Security
- Python
- Bash
- CKA
- HIPAA
- SIEM
- WAF
- SonarQube
- Snyk
- Trivy
- OWASP ZAP
About Clinikally
India's Telemedicine Platform & Online Pharmacy for Dermatology Care
The role
We are looking for a **security-focused DevSecOps Engineer with 1-2 years of experience** to help embed security across the software development lifecycle while maintaining deployment speed, platform reliability, and compliance.This role will work closely with engineering, infrastructure, and security teams to strengthen CI/CD security, cloud governance, infrastructure automation, vulnerability management, monitoring, and secure deployment practices.**Roles and Responsibilities**Secure DevOps & CI/CD* Build, maintain, and optimize secure CI/CD pipelines for reliability, speed, and controlled releases.* Implement **shift-left security** by integrating security checks early in the development lifecycle.* Configure automated quality, vulnerability, and security gates within release pipelines.* Support secure, zero-downtime deployment strategies and rollback mechanisms.* Ensure release workflows follow secure SDLC and change-management practices.Cloud and Infrastructure Security* Manage and secure cloud environments across AWS, GCP, or Azure.* Develop and maintain Infrastructure-as-Code using Terraform.* Package and deploy applications to Kubernetes using Helm.* Implement cloud security controls, including IAM policies, least-privilege access, network segmentation, and secure configuration management.* Strengthen Docker and Kubernetes security, including image hardening, access controls, and workload protection.Application and Platform Security* Integrate SAST, DAST, SCA, container scanning, and vulnerability assessment tools into CI/CD pipelines.* Track vulnerabilities, coordinate remediation, and ensure closure within defined timelines.* Implement secure secrets management, certificate management, and encryption practices.* Participate in application, infrastructure, and architecture security reviews.* Support security testing and remediation across applications and platforms.Compliance, Monitoring and Incident Readiness* Support compliance with frameworks such as ISO 27001, SOC 2, PCI-DSS, and other regulatory requirements.* Maintain centralized security logging, monitoring, alerting, and audit trails.* Track security posture, vulnerabilities, access reviews, and compliance metrics.* Support incident response readiness, security investigations, and remediation activities.* Maintain documentation required for audits, risk assessments, and compliance reviews.Automation and Reliability* Automate repetitive infrastructure, deployment, and security processes.* Improve observability through effective logging, monitoring, alerting, and dashboards.* Support disaster recovery, backup validation, resilience testing, and business continuity initiatives.* Collaborate with SRE and platform teams to improve availability, scalability, and operational security.Required Qualifications* **1-2 years of experience** in DevSecOps, DevOps, Cloud Security, SRE, or a related role.* Hands-on experience with at least one cloud platform: AWS, GCP, or Azure.* Strong working knowledge of Terraform for Infrastructure-as-Code.* Hands-on experience with Kubernetes, Docker, and Helm.* Experience with CI/CD tools such as Jenkins, GitHub Actions, GitLab CI, Azure DevOps, or similar platforms.* Practical understanding of DevSecOps, secure SDLC, vulnerability management, and security automation.* Experience integrating or working with SAST, DAST, SCA, container scanning, or vulnerability management tools.* Understanding of IAM, least-privilege access, network security, secrets management, and encryption.* Proficiency in at least one scripting or programming language, such as Python, Go, or Bash.* Ability to collaborate with engineering teams and drive timely closure of security issues.Good to Have* AWS, GCP, Azure, Kubernetes, CKA, or CKAD certification.* Exposure to ISO 27001, SOC 2, PCI-DSS, HIPAA, or similar compliance frameworks.* Experience working in healthcare, fintech, or another regulated industry.* Familiarity with SIEM, CSPM, WAF, cloud-native security tools, and incident-response processes.* Experience with tools such as SonarQube, Snyk, Trivy, Checkmarx, Veracode, OWASP ZAP, or similar platforms.Location: Sector 44, Gurgaon
DevSecOps Engineer ยท Clinikally