DevSecOps- AWS/AZURE- Terraform/Ansible- CI/CD
Extreme NetworksBangalore, Karnataka
it-jobs
Job Description
We are seeking a skilled Security & Compliance Engineer to implement and maintain security controls aligned with ISO 27001, SOC 2, and NIST 800-53. The role involves ensuring compliance readiness, integrating security into development lifecycles, and supporting audit activities while securing cloud-native and containerized environments. Key Responsibilities: - Follow established processes for the implementation and maintenance of security controls aligned with ISO 27001, SOC 2, and NIST 800-53. - Collaborate with security leadership to ensure adherence to controls and procedures. - Support internal and external audits by providing evidence, documentation, and remediation tracking. - Develop and maintain automated security and compliance monitoring tools and dashboards. - Translate regulatory requirements into technical requirements and integrate them into the Secure Development Lifecycle (SDLC). - Conduct gap assessments and risk analysis, define remediation plans, and track completion. - Apply hands-on expertise in Kubernetes security, including RBAC, pod security policies, network policies, and secrets management. - Implement secure configurations and governance controls in cloud-native environments (AWS, Azure, or GCP). - Integrate security controls into CI/CD pipelines using tools like GitLab CI, Jenkins, or GitHub Actions. - Ensure proper access management, encryption, logging/monitoring, and network security. Required Qualifications: - 8+ years of experience in information security or compliance engineering roles. - Strong understanding and practical experience with ISO 27001, SOC 2 (Type I and II), and NIST SP 800-53. - Hands-on experience with DevOps security practices and secure CI/CD pipelines. - Familiarity with cloud-native security, container orchestration, and infrastructure-as-code tools (Terraform, Helm, Ansible). - Solid knowledge of access management, encryption, logging/monitoring, and network security principles. - Demonstrated ability to lead technical initiatives and influence cross-functional teams. Skills: CI/CD Security Integration, Cloud Security (AWS/Azure/GCP), Compliance Frameworks (ISO 27001/SOC 2/NIST 800-53), Infrastructure-as-Code Security (Terraform/Helm/Ansible), Kubernetes Security, Risk Assessment & Remediation Experience: 8.00-14.00 Years
Get AI-Matched to This Job
Upload your resume and our AI will score how well you match this and thousands of similar roles.