About the Role
We're looking for a seasoned engineer who bridges deep cloud infrastructure expertise with a security-first mindset. Your goal is to embed security into every stage of the development lifecycle — not bolt it on at the end.
What You'll Be Doing:
Architect and maintain fault-tolerant infrastructure across AWS and Azure using Terraform, with a focus on modular design and immutable infrastructure principles
Implement automated IaC policy checks (Checkov, Tfsec, OPA/Rego) to surface misconfigurations as early as the code review stage
Build and harden end-to-end CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI) with integrated SAST/DAST, container scanning, secret detection, and software composition analysis
Apply zero-trust principles through a well-structured IAM strategy, RBAC, and centralized secrets management (HashiCorp Vault, Azure Key Vault)
Deploy and secure containerized workloads on Kubernetes clusters (EKS / AKS)
Automate the baking of EDR agents, vulnerability scanners, and observability tooling into golden base images (AMIs, Azure Golden Images)
Continuously audit cloud posture via AWS Security Hub and Azure Defender, maintaining alignment with SOC2, ISO 27001, and CIS Benchmarks
Build automated workflows that collect security findings, score them by risk, and route them into engineering backlogs (Jira)
Centralize application, container, and infrastructure log delivery into SIEM systems to enable real-time threat detection
Act as a bridge between Security and Engineering — delivering developer-friendly remediation guidance and maintaining reusable secure-by-default templates (Terraform modules, Helm charts)
What We're Looking For:
3+ years in Cloud Operations, DevOps, or DevSecOps with hands-on production experience across both AWS and Azure
Proven track record of building and securing CI/CD pipelines at scale
Strong proficiency with Terraform (modular architecture), and familiarity with Bicep or CloudFormation
Scripting skills in Python, Bash, or PowerShell
Solid understanding of Docker and Kubernetes (EKS/AKS): security hardening, service mesh, and container runtime defense
Hands-on experience with security tooling such as SonarQube, Prisma Cloud, Wiz, Snyk, CrowdStrike, Microsoft Sentinel, or equivalents
Practical knowledge of cloud network security, encryption, and end-to-end vulnerability management
Nice-to-Have Certifications:
Certified DevSecOps Professional (CDP) or Practical DevSecOps
AWS Certified Security – Specialty / Azure Security Engineer Associate
CKA or CKS (Kubernetes)


