Security Lead (DevSecOps, AWS & Kubernetes Security)
AI Skill Match
Skills You Have
Skills to Develop
You match all skills for this role!
About the Role
**Job Title : Security Lead (DevSecOps, AWS \& Kubernetes Security)** **Experience:** 8\+ years **Role Summary** We are looking for a Security Lead to own and drive the security strategy across our software delivery pipelines, cloud infrastructure, and containerised platforms. You will lead DevSecOps practices, guide the security team, and make sure applications and infrastructure are secure, compliant, and audit\-ready. **Key Responsibilities** * Lead the design and implementation of GitLab CI security stages covering SAST, DAST, SCA, and vulnerability scanning * Define and oversee the integration of SonarQube, OWASP ZAP, Trivy, Syft, and Grype into build and deployment pipelines * Drive software supply chain security, including SBOM generation and Cosign image signing * Set Kubernetes security standards using Kyverno, OPA/Gatekeeper, and Kubernetes RBAC * Own cloud security on AWS across IAM, KMS, Secrets Manager, Inspector, Security Hub, GuardDuty, CloudTrail, CloudWatch Logs, and ACM * Oversee secrets and certificate management, including HashiCorp Vault * Lead Linux and Docker hardening initiatives * Lead SIEM monitoring, VAPT coordination, and security remediation tracking through to closure * Ensure alignment with OWASP Top 10, ISO 27001 controls, and DPDP requirements * Partner with development, DevOps, infrastructure, and compliance teams to build secure\-by\-default practices * Mentor and guide security and DevOps engineers, and report security posture to stakeholders **Required Skills** * **Application security:** SAST, DAST, SCA, vulnerability scanning, OWASP Top 10 * **CI/CD security:** GitLab CI security stages * **Security tools:** Trivy, SonarQube, OWASP ZAP, Syft, Grype, Cosign * **Kubernetes and containers:** Kyverno, OPA/Gatekeeper, Docker security, Kubernetes RBAC * **AWS security:** IAM, KMS, Secrets Manager, Inspector, Security Hub, GuardDuty, CloudTrail, CloudWatch Logs, ACM * **Secrets and certificates:** Vault, certificate management * **Systems:** Linux hardening * **Governance and operations:** IAM, ISO 27001 controls, DPDP awareness, SIEM monitoring, VAPT coordination, security remediation tracking **Preferred Certifications** * AWS Certified Security – Specialty, AWS Solutions Architect Associate, or an equivalent cloud certification * CKS or KCSA * CEH **Qualification** Bachelor's degree in Computer Science, IT, or a related field, or equivalent practical experience. Education: * Bachelor's (Required) Experience: * SAST, DAST, SCA, and vulnerability scanning: 8 years (Required) * SonarQube, OWASP ZAP, Trivy, Syft, and Grype into build : 8 years (Required) License/Certification: * AWS Certified Security, AWS Solutions Architect Associate (Required) Work Location: In person
About Codeguardian Tech International Pvt Ltd.
Codeguardian Tech International Pvt Ltd. is a global leader in its sector, dedicated to innovation, high quality, and delivering outstanding client solutions.
Similar Jobs
No similar jobs found.