H2O.ai logo
H2O.aiPosted 1 month ago

Devops Engineer

HybridColombo, Western Province, Sri Lanka

Full TimeMediumArtificial Intelligence

Job Summary

Own and lead analysis and triage of vulnerability scan results from multiple security tools, investigating findings to understand actual risk and exploitability in context. Work directly with engineering teams to understand remediation options, evaluate fix approaches, and coordinate timely resolution of security issues. Remediate vulnerabilities hands-on: upgrade dependencies, rebuild container images with patched components, and contribute fixes directly to product codebases. Test fixes thoroughly and verify remediation by re-scanning before and after deployment. Route vulnerabilities to component owners and actively track remediation progress, following up to ensure completion within required timeframes. Support FedRAMP continuous monitoring processes, including monthly POA&M management and compliance reporting. Engage with customer security teams to address vulnerability findings, reconcile scan results, and support deployment approvals. Maintain and extend our vulnerability management tooling and automation infrastructure. Build automations and processes that eliminate manual work and support continuous security improvement across the platform. Assess risk levels and communicate security findings to technical and non-technical stakeholders. Support container image security controls and Kubernetes security policies across customer environments. Contribute to security documentation, runbooks, and compliance artifacts for customer audits. Participate in security incident response and customer escalations as needed. This position is based in Sri Lanka.

Required Qualifications

  • 2-4 years of experience in application security, product security, or DevSecOps roles
  • 3+ years of software engineering experience
  • Strong coding skills in at least 2 languages (Python, JavaScript, Go, Ruby, Java, etc.)
  • Comfortable reading, writing, debugging, and deploying code
  • Experience with dependency management (npm, pip, maven, bundler, etc.)
  • CI/CD experience (GitHub Actions, GitLab CI, Jenkins, CircleCI, etc.)
  • Git proficiency (branching, PRs, code review)
  • Testing mindset (write and run tests to validate fixes)
  • Strong understanding of container security, vulnerability management, and CVE assessment
  • Ability to analyze vulnerability findings deeply - understanding exploit paths, affected components, and contextual risk
  • Hands-on experience with security scanning tools
  • Familiarity with Kubernetes security concepts and best practices
  • Experience with compliance frameworks (FedRAMP, SOC2, ISO 27001, or banking regulations)
  • Excellent written and verbal communication skills for cross-functional coordination with engineering teams
  • Strong follow-through and ability to drive remediation efforts across multiple teams
  • Detail-oriented mindset with ability to manage multiple priorities and deadlines
  • Customer-focused approach with ability to translate technical security findings into business context
  • Self-motivated and able to work effectively in a remote-first environment
  • This position is based in Sri Lanka

Desired Qualifications

  • Experience with compliance frameworks (FedRAMP, SOC2, ISO 27001, or banking regulations) preferred

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce