Lead Engineer - Cloud IND
On-siteBengaluru, Karnataka, India
Job Summary
Implement and optimize DevSecOps processes, tools, and security measures in Azure and multi-cloud environments to support engineering teams. Collaborate with the Cloud Security Architect and other teams to define security objectives, integrating best practices into the development lifecycle and managing associated risks. Develop security-as-code for compute services, container platforms, and CI/CD pipelines, while automating security scanning and compliance checks using tools like SonarQube, OWASP ZAP, and Checkov. Own the lifecycle of AKS clusters, including provisioning, scaling, monitoring, patching, and enforcing zero-trust architecture policies. Monitor and remediate security vulnerabilities, maintain logging and threat detection systems, and advocate for shift-left security practices across the organization.
Required Qualifications
- 5–8 years of experience
- Strong hands-on expertise in Azure DevOps or any other cloud, Primarily on Azure
- Strong experience with Helm, Terraform, and Kubernetes
- Experience working with Azure Repos/ Git repository, Azure Pipelines, Azure Artefact Feeds, Azure Key Vault, Azure Kubernetes Service (AKS), and Azure Container Registry
- Ability to create threat models (STRIDE/MITRE ATT&CK) and define application controls/mitigations
- Basic understanding of Apache Kafka, including topic-level security, brokers, and integration patterns in a microservices environment
Desired Qualifications
- Experience with integrated security tools (e.g., SAST, DAST, SCA)
- Experience automating security scanning and compliance checks into pipelines (e.g., using tools like SonarQube, OWASP ZAP, Checkov, Jib, Trivy, Snyk etc.)
- Experience developing and enforcing Infrastructure as Code (IaC) security policies using Terraform, Bicep, or ARM templates
- Experience enabling Secrets management and key rotation using Azure Key Vault and related tooling
- Experience collaborating with Security teams to align security posture with enterprise guidelines
- Experience integrating identity and access management (IAM) into CI/CD workflows using Azure AD, RBAC, and Conditional Access Policies
- Experience monitoring and responding to security alerts, performing vulnerability assessments
- Experience maintaining logging, monitoring, and threat detection systems (e.g., Microsoft Defender for Cloud, Sentinel, Log Analytics)
- Experience advocating for shift-left security and supporting development teams with secure coding and DevSecOps training
- Experience owning the entire lifecycle of AKS clusters: provisioning, upgrading, scaling, monitoring, and patching (control plane & node pools)
- Experience managing, monitoring, and securing Azure Kubernetes Service (AKS) clusters including node pools, scaling, network policies, and pod security standards
- Experience enabling RBAC, network policies, and service mesh configurations to enforce zero-trust architecture within AKS
- Experience performing regular AKS upgrades, patching, and version compatibility checks
- Experience implementing and managing container security controls within AKS and enforcing policies via tools such as OPA/Gatekeeper or Azure Policy
- Experience implementing Istio service mesh for traffic routing, security policies (mTLS, ingress/egress), and observability across AKS workloads
- Experience integrating Terraform-based security-as-code modules to provision secure infrastructure and services
- Experience configuring and managing Azure security services, including Azure Key Vault, Defender for Cloud, Azure Sentinel, App Gateway, APIM, and Azure AD PIM
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.