Kantar logo
KantarPosted 1 month ago
EXPIRED

Senior DevSecOps Engineer

On-siteHyderabad, Telangana, India

Full TimeSenior LevelEnterpriseTECH

Job Summary

Own and evolve the security posture of the cloud-native data platform, focusing on protecting containerized Python services on AWS. Design and implement security controls across the build, deploy, and runtime lifecycle, including image hardening, least privilege, and secrets management. Embed security into CI/CD pipelines by building automated checks for SAST, dependency scanning, and IaC compliance. Secure the AWS footprint using Infrastructure as Code for IAM, networking, and encryption, while managing database security for Postgres and Redshift. Build security observability with centralized logging and alerting to reduce mean time to detect and remediate incidents. Partner with Data Engineering and Data Science teams to enable secure MLOps and DataOps practices, ensuring controls balance risk with delivery speed.

Required Qualifications

  • Significant experience in DevSecOps/SRE/Platform Engineering roles, taking ownership of security outcomes for cloud-native systems in production
  • Strong hands-on AWS experience (and an interest/ability to extend controls to Azure over time), including identity, networking, encryption and logging primitives
  • Deep knowledge of containers and orchestration (Docker; Kubernetes/EKS or ECS), including secure configuration, runtime hardening and network isolation
  • Proficiency with Infrastructure as Code (e.g., Terraform/CloudFormation) and CI/CD, with practical experience implementing policy-as-code and security automation
  • Strong Python skills and familiarity with secure software engineering practices for backend services (dependency hygiene, secure configurations, secrets handling)
  • Strong SQL fundamentals and proven experience securing relational databases (e.g., Postgres) and analytical warehouses (e.g., Redshift), including auditing and access control design
  • Experience with secrets management and key management (e.g., AWS Secrets Manager/SSM, KMS; plus an understanding of Azure Key Vault), and designing rotation and break-glass processes
  • Hands-on with security tooling and practices such as SAST, SCA, container vulnerability scanning, IaC scanning, and runtime detection—integrated into developer workflows
  • Experience operating production platforms: monitoring/alerting, incident response, post-incident reviews, and designing for resilience while reducing security risk
  • Working knowledge of data governance and security concepts (e.g., data classification, retention, privacy-by-design) and how to implement them in cloud-native architectures
  • Strong problem-solving and systems-thinking skills, with the ability to assess risk, prioritise remediation, and deliver improvements iteratively
  • Comfortable partnering with Data Engineering and Data Science teams, translating security requirements into pragmatic controls that don't block delivery
  • Strong documentation and communication skills; able to influence stakeholders and raise the security maturity of engineering teams
  • Experience defining standards and mentoring others (security champion models, enablement sessions, and improving engineering self-service)

Desired Qualifications

  • Bonus: experience securing data/ML platforms (SageMaker, Databricks, feature stores, model registries) and understanding of MLOps/AIOps operational patterns

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles