Senior Information Security Engineer (DevSecOps) at E-Commerce Industry · Bengaluru (Bangalore) · 6 - 10 years · ₹30L - ₹50L / yr · Posted 1 Jan 2026

Senior Information Security Engineer (DevSecOps)
at E-Commerce Industry
SENIOR INFORMATION SECURITY ENGINEER (DEVSECOPS)
Key Skills: Software Development Life Cycle (SDLC), CI/CD
About Company: Consumer Internet / E-Commerce
Company Size: Mid-Sized
Experience Required: 6 - 10 years
Working Days: 5 days/week
Office Location: Bengaluru [Karnataka]
Review Criteria:
Mandatory:
- Strong DevSecOps profile
- Must have 5+ years of hands-on experience in Information Security, with a primary focus on cloud security across AWS, Azure, and GCP environments.
- Must have strong practical experience working with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud, Wiz, or Orca along with SIEM / IDS / IPS platforms
- Must have proven experience in securing Kubernetes and containerized environments including image security,runtime protection, RBAC, and network policies.
- Must have hands-on experience integrating security within CI/CD pipelines using tools such as Snyk, GitHub Advanced Security,or equivalent security scanning solutions.
- Must have solid understanding of core security domains including network security, encryption, identity and access management key management, and security governance including cloud-native security services like GuardDuty, Azure Security Center etc
- Must have practical experience with Application Security Testing tools including SAST, DAST, and SCA in real production environments
- Must have hands-on experience with security monitoring, incident response, alert investigation, root-cause analysis (RCA), and managing VAPT / penetration testing activities
- Must have experience securing infrastructure-as-code and cloud deployments using Terraform, CloudFormation, ARM, Docker, and Kubernetes
- B2B SaaS Product companies
- Must have working knowledge of globally recognized security frameworks and standards such as ISO 27001, NIST, and CIS with exposure to SOC2, GDPR, or HIPAA compliance environments
Preferred:
- Experience with DevSecOps automation, security-as-code, and policy-as-code implementations
- Exposure to threat intelligence platforms, cloud security monitoring, and proactive threat detection methodologies, including EDR / DLP or vulnerability management tools
- Must demonstrate strong ownership mindset, proactive security-first thinking, and ability to communicate risks in clear business language
Roles & Responsibilities:
We are looking for a Senior Information Security Engineer who can help protect our cloud infrastructure, applications, and data while enabling teams to move fast and build securely.
This role sits deep within our engineering ecosystem. You’ll embed security into how we design, build, deploy, and operate systems—working closely with Cloud, Platform, and Application Engineering teams. You’ll balance proactive security design with hands-on incident response, and help shape a strong, security-first culture across the organization.
If you enjoy solving real-world security problems, working close to systems and code, and influencing how teams build securely at scale, this role is for you.
What You’ll Do-
Cloud & Infrastructure Security:
- Design, implement, and operate cloud-native security controls across AWS, Azure, GCP, and Oracle.
- Strengthen IAM, network security, and cloud posture using services like GuardDuty, Azure Security Center and others.
- Partner with platform teams to secure VPCs, security groups, and cloud access patterns.
Application & DevSecOps Security:
- Embed security into the SDLC through threat modeling, secure code reviews, and security-by-design practices.
- Integrate SAST, DAST, and SCA tools into CI/CD pipelines.
- Secure infrastructure-as-code and containerized workloads using Terraform, CloudFormation, ARM, Docker, and Kubernetes.
Security Monitoring & Incident Response:
- Monitor security alerts and investigate potential threats across cloud and application layers.
- Lead or support incident response efforts, root-cause analysis, and corrective actions.
- Plan and execute VAPT and penetration testing engagements (internal and external), track remediation, and validate fixes.
- Conduct red teaming activities and tabletop exercises to test detection, response readiness, and cross-team coordination.
- Continuously improve detection, response, and testing maturity.
Security Tools & Platforms:
- Manage and optimize security tooling including firewalls, SIEM, EDR, DLP, IDS/IPS, CSPM, and vulnerability management platforms.
- Ensure tools are well-integrated, actionable, and aligned with operational needs.
Compliance, Governance & Awareness:
- Support compliance with industry standards and frameworks such as SOC2, HIPAA, ISO 27001, NIST, CIS, and GDPR.
- Promote secure engineering practices through training, documentation, and ongoing awareness programs.
- Act as a trusted security advisor to engineering and product teams.
Continuous Improvement:
- Stay ahead of emerging threats, cloud vulnerabilities, and evolving security best practices.
- Continuously raise the bar on a company's security posture through automation and process improvement.
Endpoint Security (Secondary Scope):
- Provide guidance on endpoint security tooling such as SentinelOne and Microsoft Defender when required.
Ideal Candidate:
- Strong hands-on experience in cloud security across AWS and Azure.
- Practical exposure to CSPM tools (e.g., Prisma Cloud, Wiz, Orca) and SIEM / IDS / IPS platforms.
- Experience securing containerized and Kubernetes-based environments.
- Familiarity with CI/CD security integrations (e.g., Snyk, GitHub Advanced Security, or similar).
- Solid understanding of network security, encryption, identity, and access management.
- Experience with application security testing tools (SAST, DAST, SCA).
- Working knowledge of security frameworks and standards such as ISO 27001, NIST, and CIS.
- Strong analytical, troubleshooting, and problem-solving skills.
Nice to Have:
- Experience with DevSecOps automation and security-as-code practices.
- Exposure to threat intelligence and cloud security monitoring solutions.
- Familiarity with incident response frameworks and forensic analysis.
- Security certifications such as CISSP, CISM, CCSP, or CompTIA Security+.
Perks, Benefits and Work Culture:
A wholesome opportunity in a fast-paced environment that will enable you to juggle between concepts, yet maintain the quality of content, interact and share your ideas and have loads of learning while at work. Work with a team of highly talented young professionals and enjoy the comprehensive benefits that company offers.

Similar jobs (10)
About Us
CLOUDSUFI is a Silicon Valley-based specialist Data Engineering & Cloud Technologies player with top-tier clients, favorable revenue mix, strong financial performance, and robust management. We pride ourselves in helping in the Data Discovery, Insights and Monetization for organizations. We offer quality of work, opportunities to learn new platforms/technologies that will help young engineers put themselves ahead in their careers compared to their peers in the IT Services industry. CLOUDSUFI is a Data Science and Product Engineering company building Products/Solutions for Technology and Enterprise industries leveraging the advent of Cloud Hyper Scalers and AI/ML, NLP technologies.
The organization is built to scale with strong external/ internal tech capabilities and governance standards. Started in 2019, CLOUDUSUFI is a family of 250 members working towards a common goal of making the enterprise data dance.
To know more, please visit https://cloudsufi.com
Our Values
We are a passionate and empathetic team that prioritizes human values. Our purpose is to elevate the quality of lives for our family, customers, partners and the community.
Equal Opportunity Statement
CLOUDSUFI is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified candidates receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation and national origin status. We provide equal opportunities in employment, advancement, and all other areas of our workplace. Please explore more at https://www.cloudsufi.com/
Role : Full-Time Individual Contributor (IC)
Reporting to : Solution Architect / Program Manager
Location : India Remote (Quarterly visits to Noida office)
Shift : 2PM-11PM IST
12x5 (On call duty)
Experience : 8-14 Years
ABOUT YOU
- 5+ years’ experience with AWS orchestration via Terraform script
- 5+ years’ experience with CloudWatch/CloudTrail/Guard Duty
- 5+ years’ experience with AWS WAF
- 4+ years’ experience with CloudFlare
- 3+ years’ experience with DataDog
- Experience with PagerDuty
- Ability to make nuanced threat assessments
- Experience in SOPHOS.
- Significant experience with PCI, SOC2, SOX, HIPAA, or other compliance regimes
- Experience in Infrastructure As Code – Ansible / Terraform/ CloudFormation
- Hands-on experience implementing various security tools in CI/CD pipeline
- Strong experience with any cloud service provider (AWS Preferred)
- Implement and oversee technological upgrades, improvements and major changes to the cloud security environment.
- Develop solutions, install/configure/integrate IT tools and security processes within an application or organization to help improve the overall IT security posture.
- Set up Static and Dynamic Code Analysis tools, review the results and explain any gaps and potential impact to the teams (development and operations).
- Penetration testing and container security.
- Evaluate and analyze threat, vulnerability, impact and risk to security issues discovered from security assessments.
- Assess current technology architecture for vulnerabilities, weaknesses and for possible upgrades or improvement
- Creating and managing security strategies
- Oversee information security audits, whether performed by organization or third-party personnel
- Develop, maintain and publish up-to-date information security policies, standards and guidelines.
- Preferred Certification - AWS Security/CISSP/CISM (Certified Information Security Manager)
ABOUT THE ROLE
- Work independently with vendors and collaborate with colleagues
- Experience negotiating remediation timelines and/or remediate found issues independently
- Ability to implement vendor platforms within CI/CD pipelines
- Experience managing/responding to incidents, collecting evidence, and making decisions.
- Working with vendors and HM Teams to deploy criteria within WAF and fine tuning it according to applications’ needs
- Multitasking and continuous ability to provide a high level of concentration for assigned projects.
- Good working knowledge of AWS security in general and familiarity of the AWS native security tools
- The candidate should be experienced and articulate, who is not going to get discouraged, despite meeting roadblocks, and will continue promoting security within the company.
- Ability to create DevSecOps security requirements while working on a project
- Ability to articulate security requirements during the Architecture meetings and working hand in hand with HM Applications and DevOps Principal Engineers
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
Senior Cloud Site Reliability Engineer (CSRE) – Azure
About Searce:
Searce is an AI-native, engineering-led modern technology consultancy that empowers
clients to futurify their businesses by delivering real, intelligent business outcomes. As a
trusted partner for over 3,000 clients globally, Searce specializes in cloud modernization,
data engineering, applied AI, and robust cloud platform security. Driven by a "HAPPIER"
cultural mindset and our proprietary evlos problem-solving framework, we eliminate
bureaucratic fluff to build working prototypes fast and scale enterprise production
environments intelligently. We don't just fix systems; we leverage multi-cloud technologies
to transform client operations into distinct competitive advantages.
Position Overview:
We are looking for a high-caliber Senior or Lead Cloud Site Reliability Engineer (CSRE) to
architect, secure, and stabilize next-generation hybrid and multi-cloud environments.
Operating at the intersection of infrastructure design, security compliance, and production
operations, you will serve as the technical Subject Matter Expert (SME) across GCP, Azure,
and AWS.
Whether optimizing a microservice mesh on GKE, tuning autoscaling on AKS, or driving a
massive disaster recovery drill across AWS regions, your focus will be absolute reliability. For
the Lead path, you will couple this deep engineering toolkit with stakeholder management
and mentorship to drive an elite operational culture.
Experience & Level Expectation:
Years of Experience: 3 to 10 years of intensive, hands-on production operations
experience in a dedicated DevOps, Cloud Platform Engineering, or SRE role.
Associate level (3-5 Years): Expected to show flawless execution of IaC, advanced
triaging of infrastructure failures, and ownership of the CI/CD and deployment
lifecycles.
Intermediate level (5-10 Years): Expected to take architectural ownership, serve as
primary Incident Commander for complex outages, design cross-cloud governance
frameworks, and act as a reliable bridge between technical teams and client
leadership.
Key Responsibilities & Role Expectations:
Multi-Cloud Platforms & Orchestration: Design, configure, and maintain
production-grade Kubernetes clusters across major platforms (AKS).
Manage advanced network routing, service meshes (e.g., Istio), and multi-tenant
isolation.
Infrastructure as Code (IaC) & GitOps: Build declarative, enterprise-grade, reusable
infrastructure components using Terraform or Crossplane. Standardize automated
environment provisioning to eliminate configuration drift across multi-branch
environments.
Incident Management & Reliability (SRE): Own and optimize the production on-call
rotation. Lead rapid mitigation strategies for Sev-1/Sev-2 system outages, reducing
Mean Time to Recovery (MTTR) through centralized log and metric correlation.
Root Cause Analysis (RCA): Facilitate rigorous, blameless post-incident reviews to
identify core architectural vulnerabilities and establish long-term fixes preventing
recurrence.
Lifecycle, Patching & Upgrades: Plan and execute zero-downtime cluster upgrades,
operating system patching strategies (Linux/Windows), database lifecycle updates,
and multi-region Disaster Recovery (DR) failover drills.
Core Core Operations & Legacy Integration: Manage enterprise-level hybrid
networking architecture (VPCs, Firewalls, Load Balancers, DNS routing, and DHCP
configurations) while effectively connecting cloud native services to legacy
infrastructures like Active Directory.
Security & Governance: Embed Zero Trust policies, secure secrets management
(Secrets Manager/Key Vault), and continuous vulnerability patching into the
automated SDLC pipeline.
Required Technical Skills:
- Microsoft Azure: Azure Virtual Machines, Virtual Networks, Azure Active Directory, Azure Update Management.
- Containers & Orchestration
- Production-level management of GKE, AKS, and EKS.
- Advanced mastery of Docker, Helm, Kubernetes StatefulSets, Pod Disruption
WowPe is a leading fintech company revolutionizing the way businesses handle financial transactions. Our suite of innovative products includes a secure Payment Gateway for seamless online transactions, robust Payouts solutions to streamline bulk payments, and a versatile Point of Sale (POS) system for efficient in-store transactions. At WowPe, we’re dedicated to providing user-friendly, scalable, and reliable solutions that empower businesses to grow and succeed in today’s fast-paced digital economy.
We are looking for a highly skilled Cloud Infrastructure & Cloud Network Engineer to design, build, and manage secure, scalable hybrid cloud environments at WowPe. This role will focus on cloud networking, hybrid connectivity, infrastructure automation, security, reliability, and performance across on-prem and cloud platforms (AWS/Azure). You will play a critical role in ensuring high availability, security, and performance of our fintech platforms.
A Day in the Life
- Design and review cloud network architectures (VPC/VNet, routing, segmentation)
- Troubleshoot latency, connectivity, VPN, and performance issues
- Work with DevOps and application teams to support deployments and scalability
- Automate infrastructure provisioning and security guardrails
- Monitor network health, traffic flow, and system performance
- Ensure security, compliance, and disaster recovery readiness
- Support hybrid connectivity between on-prem data centers and cloud environments.
Key Responsibilities
Cloud Networking & Hybrid Architecture
- Design and implement VPC/VNet architectures, subnetting, routing tables, NAT, gateways, and secure segmentation
- Build and manage hybrid connectivity between on-prem data centers and cloud using Site-to-Site VPN, ExpressRoute, Direct Connect
- Configure and manage Layer 4 & Layer 7 load balancers for high availability and traffic distribution
- Architect DNS, CDN, and edge networking strategies for low-latency global access
Security & Zero-Trust
- Implement Zero-Trust networking using security groups, NACLs, identity-aware proxies, mTLS
- Design secure access controls and network isolation
- Work closely with security teams to ensure PCI, ISO, SOC compliance readiness
Automation, Platform & Reliability
- Automate infrastructure provisioning using Infrastructure as Code (Terraform/ARM/CloudFormation)
- Build self-healing, auto-scaling architectures with health checks and fault tolerance
- Support and manage Kubernetes clusters (EKS/AKS) including networking and service communication
- Integrate infra with CI/CD pipelines for safe and frequent deployments
Operations & Observability
- Perform advanced troubleshooting for latency, packet loss, MTU, routing loops
- Implement and manage monitoring, logging, and observability (Prometheus, Grafana, ELK, Azure Monitor, CloudWatch)
- Design and maintain disaster recovery architectures, multi-region networking, and replication strategies
- Ensure high availability, performance optimization, and cost efficiency
Basic Qualifications & Skills
- 4+ years of experience in Cloud Infrastructure & Cloud Networking
- Strong hands-on experience with AWS and/or Azure
- Deep understanding of VPC/VNet, routing, NAT, gateways, load balancers, DNS
- Experience with Hybrid connectivity (VPN, ExpressRoute, Direct Connect)
- Solid knowledge of network security, firewalls, access control, segmentation
- Hands-on experience with Infrastructure as Code (Terraform preferred)
- Experience in monitoring, troubleshooting, and incident handling
- Strong understanding of high availability, DR, and performance optimization
Preferred Qualifications
- Experience in fintech, BFSI, or high-compliance environments
- Exposure to Zero-Trust architecture and security best practices
- Experience with Kubernetes (EKS/AKS), service mesh, microservices networking
- Familiarity with CI/CD pipelines and DevOps practices
- Knowledge of CDN, edge networking, and global traffic management
- Experience with compliance frameworks (PCI-DSS, ISO 27001, SOC2)
- Ability to design large-scale, resilient, production-grade architectures
Cloud Infrastructure Engineer – BANG | 10+ Years
Location: Bangalore
Experience: 10+ Years
Job Description:
- Design, implement, and manage cloud infrastructure across AWS/Azure/GCP environments.
- Strong experience in cloud architecture, compute, storage, networking, and security.
- Manage VMs, VPC/VNet, load balancers, DNS, DHCP, firewalls, and IAM.
- Hands-on experience with Windows/Linux servers, VMware, virtualization, and infrastructure operations.
- Automate infrastructure provisioning and configuration using Terraform, Ansible, or similar tools.
- Monitor infrastructure performance, availability, and capacity using tools such as Grafana, Prometheus, or CloudWatch/Azure Monitor.
- Handle incident management, troubleshooting, disaster recovery, backup, and high-availability requirements.
- Work with cross-functional teams to support cloud migration, infrastructure upgrades, and production environments.
- Ensure infrastructure follows security, compliance, and operational best practices.
Must-Have Skills:
Cloud Infrastructure | AWS/Azure/GCP | Networking | Linux/Windows | VMware | Terraform | Ansible | DNS/DHCP | IAM | Monitoring | Backup & DR
The recruiter has not been active on this job recently. You may apply but please expect a delayed response.
Cloud Expertise(Azure):
• Strong understanding of cloud services and resources like AI services, webapp, database, including monitoring tools like Azure Monitor and Log Analytics.
• Experience with Infrastructure as Code (IaC) tools such as Arm template / Bicep/Terraform.
• Deep understanding of Networking concepts(DNS, DHCP , Hub and Spoke).
• Understanding on policies and security aspects of cloud.
Kubernetes & Helm:
• In-depth knowledge of Kubernetes concepts such as pods, services, ingress, config maps, and secrets.
• Understand of Kubernetes templates and its deployment.
• Proficiency with Helm/ Kustomize or equivalent for Kubernetes package management and deployment automation.
• Implement Kubernetes best practices, including security, networking, and scaling.
• Concepts of Docker and Containers
CI/CD & Programming:
• Hands-on experience with YAML-based CI/CD pipelines (e.g., Azure DevOps, GitHub Actions).
• Familiarity with scripting and automation tools such as PowerShell, Azure CLI, or Bash.
• Proven skill in python programming and concepts.
Monitoring and Observability:
Expertise in creating and managing Grafana dashboards for visualizing metrics and logs.
• Knowledge of Log Analytics & Azure Application Insights for performance monitoring and tracing.
Job Title: AppSec / AI Security Engineer
Employment Type: Full-time/ Permanent
Location: Indore (Work from Office)
About the Role
We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.
If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.
Key Responsibilities
- Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
- Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
- Develop structured code review workflows incorporating specifications, scan results, and code provenance.
- Optimize security scanning tools to reduce false positives and drive developer adoption.
- Investigate and manage security findings using established remediation and documentation processes.
- Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
- Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.
Required Skills & Experience
- Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
- Experience implementing automated security scanning and enforcement — not just operating existing tools.
- Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
- Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
- Ability to design, build, and own security automation and governance solutions from the ground up.
- Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
- Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
- Strong analytical mindset and ability to independently assess security risk across internal and external codebases.
Preferred Qualifications
- ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
- Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
- Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
- AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
- Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
- Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).
About Company:
Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.
For more info, please visit our website: https://5exceptions.com
We are looking for a hands-on Senior AWS Cloud Engineer to lead the infrastructure build, optimization, automation, and production deployment of a Multi-Agent AI Chatbot Platform hosted on AWS. The development environment is already in place, and the successful candidate will drive the solution through testing, integrations, and production go-live.
Key Responsibilities
- Review, validate, and optimize existing Terraform code and AWS infrastructure.
- Establish and manage integrations with enterprise platforms such as ServiceNow, Workday, and other third-party systems.
- Design, build, and support secure, scalable, and highly available AWS environments.
- Implement and automate CI/CD pipelines and Infrastructure-as-Code practices.
- Lead infrastructure testing, performance tuning, and production readiness activities.
- Drive deployment and operationalization of the platform in the Production environment.
- Implement cloud governance, security, monitoring, and FinOps best practices.
- Troubleshoot and resolve complex cloud infrastructure issues.
Required Skills & Experience
- 10+ years of IT experience with strong expertise in AWS Cloud Engineering.
- Proven experience designing, deploying, and managing AWS production environments.
- Strong hands-on experience with Terraform and Infrastructure-as-Code.
- Experience with CI/CD pipeline automation and DevOps practices.
- Expertise in AWS services including VPC, IAM, EC2, S3, Lambda, CloudWatch, and networking.
- Experience in performance optimization, reliability, and cloud cost management (FinOps).
- Strong scripting and automation skills.
- Experience integrating enterprise applications through APIs and secure connectivity patterns.
At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.
Learn more at www.shipthis.co
Role Overview
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
What You’ll be Doing
Security Operations
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
- Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
- Track security issues and corrective actions through closure.
Vulnerability Management
- Run and review application and infrastructure vulnerability scans.
- Maintain a vulnerability register and coordinate remediation with engineering teams.
- Support VAPT and penetration-testing exercises and validate closure of findings.
- Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
- Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
- Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain device inventory and monitor endpoint compliance.
- Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
- Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
- Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
- Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
- Automate repetitive deployment, infrastructure, security, and compliance tasks.
- Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
- Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Required Fundamentals
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Desired Qualifications
- 1–2 years of experience with strong fundamentals are welcome.
- Basic scripting knowledge in Python, Bash, or similar.
- Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates:
- Who can join immediately
- Female candidates returning to work after a career break are strongly encouraged.
We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.
Job Synopsys
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product
About Shopalyst:
Shopalyst offers a Discovery Commerce platform for digital marketers. Combining data, AI and deep integrations with digital media and e-commerce platforms, Shopalyst connects people with products they love. More than 500 marquee brands leverage our SaaS platform for data driven marketing and sales in 30 countries across Asia, Europe and Americas. We have offices in Fremont CA, Bangalore, and Trivandrum. Our company is backed by Kalaari Capital.
About the Role:
- This position is responsible for end to end management of Shopalyst's cloud infrastructure platform (AWS and Google Cloud).
- Candidate should have a bachelor's degree in Computer Science and Engineering (or equivalent) plus minimum 3+ years of experience in managing AWS cloud infrastructure.
Core responsibilities:
Infra management
- Review infrastructure change requests, suggest & implement optimal solution in terms of performance, maintainability & cost
- Keep the infrastructure updated/upgraded. This includes servers, operating system, packages and application software
- Maintain all infrastructure configuration as IaC (Infrastructure as Code)
Infra monitoring and site reliability
- Continuous monitoring of infrastructure and ensuring 24x7 availability
- Implement/maintain automated alerting mechanisms for handling infra outages
- Document and maintain infra recovery procedures, ensure successful backup of critical data
- Continuously monitor infra utilization and alert on when to scale up/scale down instances
Infra Security, Compliance & Certifications
- Infrastructure access management - ensure least privilege as the default policy. Review infra access periodically. Manage access to critical systems like AWS/Open VPN
- Adherence to CIS/AWS security benchmarks on AWS Security Hub
- Implement controls required for different attestations/certifications like SOC 2 Type 2,ISO 27xxx, PCI DSS etc
DevOps
- Enable CI/CD process for application deployment
Infra cost monitoring and optimisation
- Services-wise infrastructure cost monitoring analysis and optimisation
Infra trends and new services
- Evaluate new cloud services, analyse feasibility of adoption
Required Skills and Experience:
- AWS: 3+ years experience with using a broad range of AWS technologies (e.g. EC2,S3, ELB, VPC,Route 53, IAM, CloudWatch, CloudFront, RDS, Lambda, Glacier) to develop and maintain an Amazon AWS based cloud solution
- DevOps: Solid experience as a DevOps Engineer in a 24x7 uptime Amazon AWS environment, including automation experience with configuration management tools.
- Infra automation: Experience in Terraform/Ansible
- Scripting Skills: Strong scripting (e.g. Python) and automation skills.
- Operating Systems: Linux system administration and strong shell scripting skills
- Monitoring Tools: Experience with web servers (e.g. Nginx).
- Problem Solving: Ability to analyze and resolve complex infrastructure resource and application deployment issues.
Desired Skills (Not essential but beneficial to have):
- DB Skills: Basic DB administration experience - Cassandra, RDS, MySQL
- Search engines: Experience with search engines such as Apache Solr/Elastic Search
- Version Control: Experience administrating version control systems such as Git











