Cloud Security & DevSecOps Engineer
Harden cloud infrastructure, automate CI/CD security pipelines, manage Linux VPS clusters, and maintain enterprise compliance.
Role Overview & Operational Scope
You will protect our cloud perimeter, build secure automated deployment pipelines, and ensure zero-trust security across all server fleets.
Key Responsibilities & Production Deliverables
- Design and maintain secure CI/CD pipelines with automated SAST, DAST, and dependency scanning.
- Harden Linux servers (Ubuntu/Debian), SSH policies, iptables/UFW firewalls, and fail2ban rules.
- Manage and optimize Nginx reverse proxies with strict CSP, HSTS, and rate-limiting configurations.
- Perform regular automated vulnerability scanning and remediation across cloud instances.
- Respond to security events and coordinate disaster recovery drills.
Mandatory Foundational Knowledge
- Thorough understanding of Linux system administration, process isolation, and file permissions.
- Deep knowledge of cloud networking: VPCs, subnets, security groups, NAT gateways, and DNS.
- Principles of infrastructure-as-code, secrets management, and least-privilege IAM.
Mandatory Practical Skills & Architecture
- Hands-on experience configuring Docker container isolation and image slimming.
- Expertise in shell scripting (Bash) and CI/CD automation (GitHub Actions).
- Proficiency in configuring and debugging Nginx, SSL/TLS certificates (Let's Encrypt), and PM2.
Problem Solving, Execution Rigor & Curiosity
- Proactive mindset that fixes security misconfigurations before they can be probed.
- Pride in resilient infrastructure that stays online during traffic spikes.
5-Day Live Technical Evaluation Milestone
5-Day DevSecOps Milestone: Audit a multi-container deployment, harden the Linux host and Nginx configuration, and implement automated vulnerability scanning in a CI pipeline (strictly 5 working days). Verification unlocks immediate official offer letter.
Institutional Hiring Protocol: Candidates who pass initial resume screening are invited to a live, practical evaluation milestone spanning strictly not more than 5 working days. Verifiable completion and code audit by your assigned senior engineering mentor is the sole prerequisite for official corporate offer letter issuance.
Compensation, Total Rewards & Advancement
- Annual package ₹7,50,000–₹13,50,000 with annual performance appraisals.
- Full remote work setup with cloud lab credits.
- Sponsorship for cloud security certifications (AWS Certified Security, CKA).
Dedicated Inquiries Inbox for This Role
Have questions regarding architecture scope or wish to share private research repos directly? Messages sent to this address route straight to the engineering leads reviewing this opening.
cloud-security-devsecops-enginee-careers@cehpoint.co.in
Open Mail Client →