Live opening · Posted 1 day ago

Senior / Lead DevSecOps Engineer

Bupa · Gurgaon
Instahyre 6-10 yrs
You are 1 day behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 1 day ago
CompanyBupa
LocationGurgaon
Experience6-10 yrs
SourceInstahyre
Listed1 day ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
14 min from Instahyre publishing this role to us finding it
10 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
17,485 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

The Lead DevSecOps Engineer is responsible for driving the integration of security principles into the development and operations processes. This role will champion a security-first culture, design and implement robust security controls, and automate security testing and compliance measures. By collaborating closely with development, operations, and security teams, the Lead DevSecOps Engineer will ensure the confidentiality, integrity, and availability of our systems and applications.
Responsibilities:
Secure CI/CD Pipeline Management (Azure DevOps): Design, implement, manage, and optimise secure CI/CD pipelines and related processes within Azure DevOps.
Infrastructure as Code (IaC) with Security: Implement, maintain, and secure infrastructure using Terraform within Azure DevOps pipelines, incorporating security best practices.
Automated Security Testing and Vulnerability Management: Integrate security scanning tools (SAST, DAST, SCA) and implement automated vulnerability management processes.
Security Collaboration and Requirements: Collaborate with security teams to define security requirements and implement security controls across the SDLC.
Secrets Management and Security Monitoring: Implement and manage secrets management solutions (e. g., Azure Key Vault) and security monitoring/logging.
Security Assessments and Hardening: Conduct regular security assessments, penetration testing, and infrastructure hardening to minimise attack surface.
Container Security (Docker/Kubernetes): Implement and manage container security scanning and vulnerability management for Docker and Kubernetes environments.
Network Security within IaC: Implement and manage network security controls within the infrastructure-as-code.
Policy as Code (OPA) Implementation: Implement and manage Policy as Code (OPA) for enforcing security and compliance policies.
DevSecOps Mentorship and Training: Coach and guide engineering teams on secure coding practices and DevSecOps principles.
Requirements:
Leadership and Strategy: Proven experience leading/mentoring DevSecOps or Security Engineering teams, defining technical roadmap, and driving security architecture standards.
Security Metrics and Executive Reporting: Ability to define key risk indicators (KRIs/KPIs), build operational dashboards, and translate technical security metrics into clear executive reports for senior stakeholders.
Languages: Advanced Python (for designing complex automation frameworks, custom tooling, and security integrations).
Cloud Architecture and IaC: Deep expertise in Azure and Terraform.
CI/CD and GitOps: Advanced Azure DevOps pipeline architecture alongside GitOps implementations (FluxCD, Helm, or Kustomize).
Container Security and Orchestration: Production-grade Kubernetes and Docker security architecture, image signing, and runtime defence.
Stakeholder Management: Ability to bridge business risk and technical execution, collaborating with Dev, Sec, and Ops leads.
Nice-to-Have Skills (Secondary / Bonus):
AppSec and Pipeline Security: Designing automated SAST/DAST/SCA governance and vulnerability management reporting workflows.
Offensive Security and Hardening: Hands-on threat modelling, penetration testing background, and infrastructure attack-surface reduction.
Secrets and Identity Architecture: Enterprise-wide secrets lifecycle management (e. g., Azure Key Vault, Vault, IAM governance).
Network and Zero Trust Security: Designing cloud network segmentation and micro-segmentation natively within IaC.

Experience
6-10 yrs

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App