- Knowledge of cloud platforms (AWS, Azure, GCP) and containerization technologies (Docker, Kubernetes, OpenShift).
- Implement security tools and best practices within CI/CD pipelines to automate security testing, vulnerability assessments, and ethical hacking.
- Design, deploy, and manage secure infrastructure using Infrastructure as Code (IaC) principles and tools like Terraform, CloudFormation, or Ansible.
- Lead and perform ethical hacking, penetration testing, and security audits to identify vulnerabilities, assess risks, and recommend mitigation strategies.
- Conduct penetration testing on applications, networks, and cloud environments using tools like Burp Suite, Metasploit, Nmap, and Kali Linux.
- Develop, maintain, and enhance security-focused regression testing frameworks to proactively identify and address security vulnerabilities.
- Monitor and respond to security threats, perform regular security assessments, and implement remediation strategies using SIEM tools like Splunk, ELK, or AWS Security Hub.
- Participate in incident response and post-incident analysis, contributing to continuous improvement and learning.
- Collaborate with cross-functional teams to define and implement best practices for secure DevOps processes.
- Ensure adherence to security compliance frameworks (e.g., NIST, CIS, ISO 27001, SOC 2) and assist in security audits.
- Implement security hardening techniques for applications, networks, and infrastructure.
- Develop and enforce security policies for secrets management, identity & access management (IAM), and role-based access control (RBAC).
- Automate security scanning, configuration management, and patch management processes.
- Conduct threat modeling and risk assessment to improve security posture.
- Work with developers to integrate security best practices into the software development lifecycle (SDLC).
- Stay updated with the latest security threats, vulnerabilities, and industry trends.
Required Qualification:
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field.
Required Experience:
- Minimum 2 years of experience in DevSecOps, Security Engineering, or a related field.
- Hands-on experience in penetration testing, ethical hacking, and security automation.
Required Skills:
- Cloud Security: AWS, Azure, GCP
- Security Frameworks &Compliance: NIST, CIS, ISO 27001, SOC 2
- CI/CD Security: Jenkins, GitLab CI, GitHub Actions, Azure DevOps
- Infrastructure as Code (IaC): Terraform, CloudFormation, Ansible
- Container Security: Docker, Kubernetes, OpenShift, Istio
- Web Security & Penetration Testing: OWASP Top 10, Burp Suite, Metasploit, Kali Linux, Nmap, SQL Injection, XSS, CSRF
- Network Security: VPNs, Firewalls, IDS/IPS, Network Penetration Testing
- Monitoring & Incident Response: Splunk, ELK, AWS Security Hub, SIEM tools
- Scripting & Automation: Python, Bash, PowerShell
- IAM & Secrets Management: AWS IAM, HashiCorp Vault, AWS Secrets Manager, Azure Key Vault
- Threat Modeling & Risk Assessment: STRIDE, DREAD, MITRE ATT&CK
Experience:
What are we offering?
- Health Insurance
- Provident Fund
- Annual Paid Leaves
- Compensation Plans
- Paid Certifications & Training
- Car Finance Program
- Bike Finance Program
- Child Education Program
- Two Annual Trips
- Stars Of the Month Rewards
- Quarterly Meetups
- Referral Bonuses
- Birthday & Eid Gifts
Skills:
Incident Response, CI, CD Security, Security Frameworks, Communication Skills,