Hiring For DevSecOps role!

5 - 7 years

15 - 20 Lacs

mumbai suburban mumbai (all areas)

Posted:6 hours ago| Platform: Naukri logo

Apply

Work Mode

Hybrid

Job Type

Full Time

Job Description

Role & responsibilities

AWS + DevSecOps Roles and Responsibilities (Including Bitbucket)

AWS Roles and Responsibilities:

  • Design and enforce least privilege access policies.
  • Conduct regular audits of IAM roles, groups, and policies.
  • Configure and manage federated identity with external IdPs (e.g., Okta, Azure AD).

Vulnerability Assessment and Penetration Testing (VAPT) and Hardening:

  • Perform regular vulnerability assessments on AWS resources using tools like AWS Inspector, Nessus, or Qualys.
  • Apply AWS best practices to harden services such as EC2, RDS, and S3.
  • Implement encryption in transit and at rest using AWS KMS and SSL/TLS.
  • AWS Cognito and Database Management:
  • Manage authentication and authorization workflows with AWS Cognito.
  • Secure databases (RDS, DynamoDB) with:
  • Fine-grained IAM controls for access.

Bitbucket Roles and Responsibilities:

  • Manage secure repositories in Bitbucket by enforcing:
  • Access controls based on roles (Admin, Developer, Read-Only).
  • Branch protection rules to restrict direct commits and enforce pull request (PR) reviews.
  • Encrypt sensitive data like credentials using Bitbucket Pipelines environment variables.

CI/CD Pipeline Integration:

  • Set up secure CI/CD pipelines in Bitbucket Pipelines:
  • Integrate with tools like SonarQube or Check Marx for code quality and security scanning.
  • Use pre-commit hooks and PR checks for code quality and security validation.

CI/CD and Code Security Responsibilities:

  • Integrate Bitbucket Pipelines with AWS services for secure application deployment
  • Static Application Security Testing (SAST) with SonarQube.
  • Dependency scanning with tools like OWASP Dependency-Check.
  • Container security scanning for Docker images.

Code Scanning and Security:

  • Use Bitbucket Code Insights to run security scans and display results directly in PRs.
  • Monitor Bitbucket repositories for exposed credentials or sensitive data.
  • Automate the review process with Bitbucket integrations like Checkov for IaC scanning.

Application Security Responsibilities:

  • Conduct SAST during development to identify vulnerabilities early.
  • Perform DAST in staging or production environments to simulate real-world attacks.
  • Use tools like Burp Suite, AppScan, or OWASP ZAP to enhance app security.

Infrastructure Security Responsibilities:

AWS and GCP Infrastructure Security:

  • Harden cloud environments using security services:
  • AWS: Security Hub, GuardDuty, CloudTrail, AWS Config.
  • GCP: Security Command Center, IAM, and Cloud Audit Logs
  • Use IaC scanning tools like Checkov, Terrascan, or AWS Config Rules.

Compliance and Governance:

  • Ensure adherence to compliance standards like GDPR, HIPAA, and PCI DSS.
  • Generate and maintain audit trails using AWS CloudTrail and Bitbucket Activity Logs.

Interested candidates can share their resumes on careers@timespro.com

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now

RecommendedJobs for You

pune, chennai, mumbai (all areas)