Locations: Pune
💼 Experience: 8 -14 Years
🏢 Mode of Work: Hybrid
ROLE OVERVIEW
The Senior / Lead AWS Cloud DevSecOps Engineer owns secure, scalable, and highly available AWS infrastructure, defining standards, reference patterns, and delivery direction for the DevOps team.
The role combines platform engineering, automation, CI/CD, observability, security, and leadership in enterprise, regulated environments to improve reliability, deployment speed, and cloud security.
KEY RESPONSIBILITIES
Cloud Architecture & Platform Ownership
- Own the AWS DevSecOps roadmap, engineering standards, and reusable reference patterns.
- Design Terraform and AWS CDK modules for production-grade, multi-region infrastructure.
- Govern core AWS services including EKS, API Gateway, ALB/NLB, CloudFront, VPC, PrivateLink, Secrets Manager, KMS, SQS, SNS, and Kinesis.
- Standardise infrastructure, configuration, and environment parity across production, staging, and development.
- Apply FinOps practices using AWS Cost Explorer, Compute Optimizer, Savings Plans, and related tooling.
CI/CD & Delivery Engineering
- Build and operate reusable CI/CD pipelines with AWS CodePipeline, CodeBuild, CodeDeploy, GitHub Actions, GitLab CI/CD, or Jenkins.
- Embed security checks such as SAST, secret scanning, and container image scanning into delivery workflows.
- Use ArgoCD or Flux for declarative, auditable Kubernetes delivery on EKS.
Kubernetes & Container Platform
- Manage Amazon EKS clusters, ingress, autoscaling, Karpenter, and service mesh adoption where applicable.
- Maintain Helm libraries and containers build pipelines for multi-environment delivery via Amazon ECR.
- Troubleshoot Kubernetes issues, perform root-cause analysis, and implement scalable fixes.
Observability & Reliability
- Drive observability with CloudWatch, X-Ray, OpenSearch, Datadog, or Dynatrace for tracing, dashboards, SLOs, and alerts.
- Define reliability standards, error budgets, incident response practices, and blameless postmortems.
- Improve reliability and deployment efficiency through proactive monitoring and automated remediation.
Security & Compliance (DevSecOps)
- Embed security across IAM, secrets, encryption, network controls, and CI/CD workflows.
- Manage cloud security posture using IAM Identity Center, IRSA, AWS Config, Security Hub, GuardDuty, Macie, Inspector, WAF, Shield, and VPC Endpoints.
- Support vulnerability remediation, cloud governance, and compliance requirements such as SOC 2, PCI-DSS, HIPAA, or FedRAMP where applicable.
- Resolve compute, storage, IAM, and public access findings as part of ongoing cloud security operations.
Leadership & Collaboration
- Lead and mentor the DevSecOps team while reinforcing ownership, standards, and continuous improvement.
- Partner with engineering, product, security, and business stakeholders to improve developer experience and delivery outcomes.
- Communicate technical trade-offs clearly and maintain practical architecture and platform documentation.
REQUIRED QUALIFICATIONS
- 5+ years in DevOps, Cloud, or SRE, including 2+ years in a lead or architect role.
- Hands-on production AWS experience with EKS, API Gateway, ALB/NLB, CloudFront, VPC, PrivateLink, Secrets Manager, KMS, SQS, SNS, and Kinesis.
- Strong Terraform skills, including modular design, remote state, and environment separation; AWS CDK is a plus.
- Production Kubernetes experience with Amazon EKS, Helm, and containerized applications.
- CI/CD experience with CodePipeline, CodeBuild, CodeDeploy, GitHub Actions, GitLab CI/CD, or Jenkins.
- Strong AWS networking, security, identity, scripting, troubleshooting, and production support skills.
- Experience in enterprise, multi-region AWS environments and ability to explain technical trade-offs to stakeholders.
- AWS Certified DevOps Engineer – Associate or Professional is mandatory.
PREFERRED QUALIFICATIONS
- Exposure to Azure or GCP alongside AWS.
- Experience with GitOps, Datadog/Dynatrace, FinOps, vulnerability management, or service mesh technologies.
- Exposure to regulated, financial services, or global operational environments.
- Graduate or postgraduate degree, or equivalent qualification.
Required Certification: AWS Certified DevOps Engineer – Associate or Professional