- Design implement and maintain secure CI/CD pipelines using tools such as Jenkins GitLab CI or GitHub Actions.
- Integrate automated security scanning tools (SAST DAST SCA IaC scanning) into development workflows.
- Collaborate with development and operations teams to embed security practices early in the SDLC (Shift-Left Security).
- Develop and enforce security policies standards and compliance frameworks across cloud and on-premise environments.
- Automate security controls using Infrastructure as Code (IaC) tools like Terraform CloudFormation and Ansible.
- Monitor and respond to security incidents within the deployment pipeline; conduct root cause analysis and remediation.
- Ensure compliance with regulatory standards such as ISO 27001 SOC 2 GDPR and PCI-DSS.
- Lead security audits vulnerability assessments and penetration testing coordination.
- Provide guidance and training to engineering teams on secure coding practices and tool usage.
- Stay current with emerging threats security trends and DevSecOps innovations to continuously improve the security posture.
Requirements
- Bachelors degree in Computer Science Information Security or a related field; advanced certification (e.g. CISSP CISM AWS Certified Security Specialty DevSecOps Engineer) is a plus.
- 510 years of hands-on experience in DevOps SRE or security engineering with a strong focus on security automation.
- Proficiency in scripting languages (Python Bash PowerShell) and configuration management tools (Ansible Puppet Chef).
- Expertise in containerization and orchestration technologies (Docker Kubernetes) and cloud platforms (AWS Azure or GCP).
- Deep understanding of CI/CD pipeline security including secrets management artifact signing and vulnerability scanning.
- Experience with security tools such as SonarQube Checkmarx Snyk Aqua Security HashiCorp Vault and Wiz.
- Strong knowledge of network security identity and access management (IAM) and zero-trust principles.
- Demonstrated ability to work in agile environments and collaborate across cross-functional teams.
- Excellent problem-solving skills attention to detail and a proactive approach to risk mitigation.
- Experience in large-scale high-availability systems and microservices architectures is highly desirable.
Benefits
At Mitigata were not just building productswere building Indias digital defence layer.
We combine security compliance and insurance to protect businesses end-to-end.
Work on high-impact real-world problems
Be part of a first-of-its-kind company
High ownership fast growth and steep learning curve
Competitive compensation ESOPs
Required Skills:
Career in software testing
Required Education:
(CSE IT)
Design implement and maintain secure CI/CD pipelines using tools such as Jenkins GitLab CI or GitHub Actions.Integrate automated security scanning tools (SAST DAST SCA IaC scanning) into development workflows.Collaborate with development and operations teams to embed security practices early in the ...
- Design implement and maintain secure CI/CD pipelines using tools such as Jenkins GitLab CI or GitHub Actions.
- Integrate automated security scanning tools (SAST DAST SCA IaC scanning) into development workflows.
- Collaborate with development and operations teams to embed security practices early in the SDLC (Shift-Left Security).
- Develop and enforce security policies standards and compliance frameworks across cloud and on-premise environments.
- Automate security controls using Infrastructure as Code (IaC) tools like Terraform CloudFormation and Ansible.
- Monitor and respond to security incidents within the deployment pipeline; conduct root cause analysis and remediation.
- Ensure compliance with regulatory standards such as ISO 27001 SOC 2 GDPR and PCI-DSS.
- Lead security audits vulnerability assessments and penetration testing coordination.
- Provide guidance and training to engineering teams on secure coding practices and tool usage.
- Stay current with emerging threats security trends and DevSecOps innovations to continuously improve the security posture.
Requirements
- Bachelors degree in Computer Science Information Security or a related field; advanced certification (e.g. CISSP CISM AWS Certified Security Specialty DevSecOps Engineer) is a plus.
- 510 years of hands-on experience in DevOps SRE or security engineering with a strong focus on security automation.
- Proficiency in scripting languages (Python Bash PowerShell) and configuration management tools (Ansible Puppet Chef).
- Expertise in containerization and orchestration technologies (Docker Kubernetes) and cloud platforms (AWS Azure or GCP).
- Deep understanding of CI/CD pipeline security including secrets management artifact signing and vulnerability scanning.
- Experience with security tools such as SonarQube Checkmarx Snyk Aqua Security HashiCorp Vault and Wiz.
- Strong knowledge of network security identity and access management (IAM) and zero-trust principles.
- Demonstrated ability to work in agile environments and collaborate across cross-functional teams.
- Excellent problem-solving skills attention to detail and a proactive approach to risk mitigation.
- Experience in large-scale high-availability systems and microservices architectures is highly desirable.
Benefits
At Mitigata were not just building productswere building Indias digital defence layer.
We combine security compliance and insurance to protect businesses end-to-end.
Work on high-impact real-world problems
Be part of a first-of-its-kind company
High ownership fast growth and steep learning curve
Competitive compensation ESOPs
Required Skills:
Career in software testing
Required Education:
(CSE IT)
View more
View less