Job title: Azure DevSecOps Engineer
Required Technical Skill Set : Azure DevOps, Azure Security Center, Azure Policy, ARM/Bicep/Terraform, GitHub Actions, CI/CD, Azure Kubernetes Service (AKS), Docker, Security Scanning (SAST/DAST), Key Vault, Defender for Cloud; Good-to-Have: Python/PowerShell, SIEM/SOAR, Zero Trust, Compliance Frameworks (NIST, CIS), MATLAB
Desired Relevant Experience : 5 to 10 Years
CI/CD & DevOps ToolsMust-Have
- Hands-on experience with Azure DevOps and GitHub Actions (multi-stage CI/CD pipelines).
- Strong understanding of DevSecOps practices including shift-left security and automated security testing.
- Experience integrating SAST, DAST, SCA tools (e.g., SonarQube, Checkmarx, OWASP ZAP).
- Expertise with Azure Kubernetes Service (AKS) including cluster hardening and policy enforcement.
- Experience implementing security controls using Azure Policy, Defender for Cloud, and blueprints.
- Infrastructure as Code (IaC) expertise using ARM, Bicep, or Terraform.
- Knowledge of Zero Trust, RBAC, identity governance, and Entra ID (AAD) integration.
- Knowledge of monitoring and observability tools such as Azure Monitor, Log Analytics, App Insights.
- Containerization experience using Docker with security best practices.
- Strong understanding of networking security (NSGs, firewalls, WAF, Private Link).
Good-to-Have
- Experience with SIEM/SOAR (Microsoft Sentinel, Defender XDR).
- Knowledge of compliance frameworks (CIS Benchmarks, NIST 800-53, ISO 27001).
- Automation scripting using Python or PowerShell.
- Experience with secret scanning and credential hygiene tools.
- Familiarity with security in microservices and distributed systems.
- Cloud cost governance and FinOps awareness.
- Professional certifications
Responsibilities / Expectations from the Role
- Design, build, and maintain secure CI/CD pipelines using Azure DevOps and GitHub Actions.
- Integrate security scanning, compliance checks, and vulnerability management into pipelines.
- Implement secure IaC deployments using Bicep, ARM, or Terraform.
- Harden AKS clusters and enforce policies using OPA/Gatekeeper or Azure Policy.
- Collaborate with development teams to embed security best practices early in SDLC.
- Continuously monitor workloads using Microsoft Defender for Cloud and Sentinel.
- Troubleshoot production issues and drive resolution with RCA documentation.
- Perform threat modeling and risk assessments for new workloads.
- Implement identity and access governance including RBAC, Privileged Identity Management (PIM).
- Maintain documentation, runbooks, and operate secure, automated pipelines.