Photon Logo

Photon

AWS DevSecOps Sr. Engineer / Testers (Policy Development & Mapping) - Bangalore, India - JPMC

Reposted 21 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in India
Senior level
Remote
Hiring Remotely in India
Senior level
Design and automate AWS security policies, map them to IaC (Terraform/CloudFormation/CDK), embed security testing in CI/CD, perform vulnerability assessments and penetration testing, and collaborate with development/DevOps teams to enforce remediation, compliance, and continuous security improvements.
The summary above was generated by AI

About the Role:

We are seeking an experienced and highly motivated Senior AWS DevSecOps Engineer / Tester with expertise in policy development, security automation, and infrastructure-as-code (IaC). The ideal candidate will have a strong background in AWS cloud environments, DevSecOps principles, and security policy mapping and enforcement. This role will focus on creating and automating security policies, mapping them to cloud infrastructure, and ensuring that our security posture remains strong and compliant across all stages of the software development lifecycle.

You will work closely with cross-functional teams to define security requirements, integrate security tools and processes into the CI/CD pipeline, and continuously improve the security automation framework.

Key Responsibilities:

Policy Development & Mapping:

  • Design, develop, and maintain security policies for AWS environments, ensuring compliance with industry standards (e.g., NIST, CIS, ISO 27001).
  • Map and integrate security policies into infrastructure and applications deployed on AWS using Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, and AWS CDK.
  • Create automated processes for security policy enforcement, auditing, and monitoring.
  • Develop security rules and guardrails using AWS native services (AWS Config, AWS Security Hub, AWS GuardDuty, etc.) and third-party security tools.

DevSecOps Engineering:

  • Build and maintain the CI/CD pipeline with embedded security testing (SAST, DAST, IAST) and automated compliance checks.
  • Automate security vulnerability assessments and remediation in the AWS environment using tools like AWS Inspector, Qualys, and other static and dynamic analysis tools.
  • Collaborate with development teams to implement security in the software development lifecycle (SDLC), shifting security left and automating security testing.
  • Create and maintain AWS security best practices, security controls, and infrastructure standards.

Testing & Vulnerability Management:

  • Conduct manual and automated penetration testing, vulnerability assessments, and code reviews focused on AWS-based applications and infrastructure.
  • Implement automated testing frameworks that validate security policies and configurations (e.g., infrastructure misconfigurations, exposed secrets).
  • Identify security gaps or vulnerabilities in AWS deployments and work with DevOps and development teams to remediate.
  • Continuously assess new threats, vulnerabilities, and attack vectors in AWS environments.

Collaboration & Reporting:

  • Work closely with DevOps, Development, and IT teams to ensure proper integration of security into cloud infrastructure and applications.
  • Provide regular security assessments, risk analysis reports, and security findings to senior leadership and relevant stakeholders.
  • Participate in incident response planning and execution, providing expertise in security issues related to AWS environments.
  • Train development teams on secure coding practices, security testing tools, and best practices for AWS security.

Continuous Improvement & Innovation:

  • Stay current with emerging trends in DevSecOps, cloud security, and AWS services.
  • Continuously improve security policies, tools, and processes to adapt to evolving threats.
  • Contribute to the creation and implementation of security automation frameworks for improved DevSecOps practices.

Required Qualifications:

Experience:

  • 5+ years of experience in AWS cloud environments with a focus on security, DevSecOps, and automation.
  • At least 3+ years of hands-on experience in security policy development and mapping for cloud infrastructure, specifically AWS.
  • Deep knowledge of AWS security tools and services, including AWS IAM, AWS KMS, AWS Config, AWS GuardDuty, AWS Shield, AWS WAF, and others.
  • Strong experience with infrastructure-as-code tools such as Terraform, AWS CloudFormation, and AWS CDK.
  • Experience with security testing tools (e.g., static and dynamic analysis, penetration testing, vulnerability scanning) and frameworks.
  • Hands-on experience with CI/CD pipeline security integration, GitOps, and container security (e.g., Docker, Kubernetes, EKS).

Technical Skills:

  • Proficiency in programming/scripting languages such as Python, Bash, or Go.
  • Experience with AWS Security Hub, AWS Inspector, AWS Trusted Advisor, and other AWS security services.
  • Familiarity with security testing frameworks (e.g., OWASP, SANS, NIST) and cloud security best practices.
  • Experience with integrating security tools into CI/CD pipelines (e.g., Jenkins, GitLab, CircleCI, etc.).
  • Strong knowledge of common security vulnerabilities (e.g., OWASP Top 10, CVE management) and how to mitigate them in cloud environments.

Certifications (Preferred):

  • AWS Certified Security – Specialty.
  • Certified DevSecOps Professional (CDP) or other related certifications.
  • CISSP, CISM, or equivalent security certifications are a plus.

Soft Skills:

  • Excellent problem-solving and analytical skills, with a keen attention to detail.
  • Strong communication skills, able to present complex security issues to both technical and non-technical audiences.
  • Ability to work independently and collaboratively in a fast-paced, dynamic environment.
  • Proactive mindset with a passion for automation, security, and continuous improvement.
  • Strong documentation skills, with the ability to create clear, concise, and actionable security reports.

Preferred Qualifications:

  • Experience with container security tools like Aqua Security, Twistlock, or Falco.
  • Hands-on experience with serverless architectures and security concerns in AWS Lambda, API Gateway, and other serverless services.
  • Familiarity with cloud-native security architectures and concepts (e.g., Zero Trust, defense in depth).
  • Experience with compliance frameworks and regulations (e.g., GDPR, HIPAA, SOC 2, PCI DSS).

Similar Jobs

32 Minutes Ago
In-Office or Remote
Expert/Leader
Expert/Leader
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Lead design, build, and deploy of AI/ML solutions for customers; contribute code across Atlassian products; architect integrations and microservices; ensure compliance and monitoring; mentor engineers; communicate technical strategy to stakeholders and align solutions to business outcomes.
Top Skills: Agent-Based FrameworksAPIsAtlassian IntelligenceEnterprise IntegrationGenerative AiJavaScriptLlmsMicroservicesPythonRovo Ai
33 Minutes Ago
In-Office or Remote
Expert/Leader
Expert/Leader
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Lead design, implementation, and production deployment of AI/ML solutions across Atlassian products. Work directly with customers, architect integrations, ensure compliance (GDPR), mentor engineers, and align technical solutions to business outcomes.
Top Skills: Agent-Based FrameworksAPIsAtlassian IntelligenceGenerative AiJavaScriptLlmsMicroservicesPythonRovoRovo Ai
2 Hours Ago
Easy Apply
Remote or Hybrid
Easy Apply
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Lead GTM AI initiatives for sales analytics by designing, prototyping, and deploying generative AI/LLM solutions and AI agents. Partner with stakeholders to build data models and statistical analyses, apply ML techniques, and convert insights into actionable recommendations to improve sales performance and forecasting.
Top Skills: Ai AgentsAnthropicDbtGenerative AiLarge Language ModelsOpenaiPrompt EngineeringPythonPyTorchRetrieval-Augmented GenerationSalesforceScikit-LearnSnowflakeSQLTensorFlow

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account