Live opening · Posted 1 day ago

Senior DevSecOps Engineer

Bupa · Gurgaon
Instahyre 6-10 yrs
You are 1 day behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 1 day ago
CompanyBupa
LocationGurgaon
Experience6-10 yrs
SourceInstahyre
Listed1 day ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
14 min from Instahyre publishing this role to us finding it
11 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
16,610 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

The Lead DevSecOps Engineer is responsible for driving the integration of security principles into the development and operations processes. This role will champion a security-first culture, design and implement robust security controls, and automate security testing and compliance measures. By collaborating closely with development, operations, and security teams, the Lead DevSecOps Engineer will ensure the confidentiality, integrity, and availability of our systems and applications.
Responsibilities:
Secure CI/CD Pipeline Management (Azure DevOps): Design, implement, manage, and optimize secure CI/CD pipelines and related processes within Azure DevOps.
Infrastructure as Code (IaC) with Security: Implement, maintain, and secure infrastructure using Terraform within Azure DevOps pipelines, incorporating security best practices.
Automated Security Testing and Vulnerability Management: Integrate security scanning tools (SAST, DAST, SCA) and implement automated vulnerability management processes.
Security Collaboration and Requirements: Collaborate with security teams to define security requirements and implement security controls across the SDLC.
Secrets Management and Security Monitoring: Implement and manage secrets management solutions (e. g., Azure Key Vault) and security monitoring/logging.
Security Assessments and Hardening: Conduct regular security assessments, penetration testing, and infrastructure hardening to minimize attack surface.
Container Security (Docker/Kubernetes): Implement and manage container security scanning and vulnerability management for Docker and Kubernetes environments.
Network Security within IaC: Implement and manage network security controls within the infrastructure-as-code.
Policy as Code (OPA) Implementation: Implement and manage Policy as Code (OPA) for enforcing security and compliance policies.
DevSecOps Mentorship and Training: Coach and guide engineering teams on secure coding practices and DevSecOps principles.
GitOps and Kubernetes Deployment Management: Design and manage GitOps workflows using tools such as FluxCD, Helm, and Kustomize to enable declarative, version-controlled Kubernetes deployments and configuration management.
Cross-Functional Collaboration: Work closely with development, operations, and security teams to ensure seamless integration of security.
DevSecOps Ownership and Advocacy: Drive DevSecOps adoption and ownership across the business, working closely with key stakeholders.
Continuous Improvement and Best Practices: Stay up-to-date with the latest DevSecOps trends and best practices, driving continuous improvement within the organization.
You may also carry out any other duties reasonably requested by Bupa from time to time. (Not to be removed)
Requirements:
Extensive DevSecOps Experience: 5+ years of practical experience in DevOps/DevSecOps roles, demonstrating a deep understanding of principles and implementation.
Cloud and IaC Expertise: Strong expertise in a major cloud platform (especially Azure) and Infrastructure as Code (IaC) using Terraform.
CI/CD and Security Integration: Proven ability to design, implement, and secure CI/CD pipelines, integrating security scanning and vulnerability management tools.
Containerization and Orchestration: Solid understanding and hands-on experience with containerization technologies (Docker, Kubernetes) and container security.
Communication and Collaboration: Excellent communication, collaboration, and mentoring skills, with the ability to work effectively across teams and influence technical direction.
Experience in deploying PaaS solutions, APIs, and Infrastructure as Code (Terraform) to Azure
Automation for build and release management; automate and streamline operations and processes
Release Management utilizing Azure DevOps/VSTS mandatory
Excellent Scripting Skills (PowerShell, Shell, and Python)
GitOps Tooling: Hands-on experience with GitOps practices and tooling, including FluxCD, Helm, and Kustomize, for managing Kubernetes workloads and application deployments.
Key relationships: Security Product Owner, Security Business Analyst, Project Manager(s) / Delivery Manager(s) / Scrum Master(s), Security Architect(s), Security Engineers, Bupa Technology Operations teams, Operations Support Group - Identity and Access Management, and Product vendors.
Risk management and compliance obligations (Not to be removed):
Responsible for understanding the risks, accountabilities, rules, and processes associated with my role.
Report issues, incidents, and complaints promptly.
Understand the laws, regulations, policies, and procedures that apply and ensure controls enabling compliance are built into documented processes and procedures.
Work in accordance with the Bupa Health and Safety Policy, always applying safe working practices and procedures and complying with all instructions given about ensuring health and safety at work.
Apply information security skills and/or experience to effectively and securely perform the required obligations of the organization.
Role modelling Bupa's values (not to be removed):
A primary responsibility of this role is to consistently behave according to Bupa's values and to be an exemplary role model of Bupa's values every day.
Delivering fair outcomes for consumers and understanding your regulatory obligations (not to be removed):
Put fair treatment of customers at the heart of what you say and do. Be courageous and speak up if you believe our products or services do not deliver what we have led our customers to expect.
Be accountable and take ownership for ensuring you are familiar with all regulatory requirements that fall within the remit of your role and comply with them at all times. Seek guidance if you need support understanding your regulatory requirements. Notify, without delay, any potential or actual breach of regulation.

Experience
6-10 yrs

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App