Security Lead (DevSecOps, AWS & Kubernetes Security)
Codians.ai · Delhi, India
Apply & track with Apply EdgeCompany Description Codians.ai is a technology platform focused on IT outsourcing, talent hiring, and transparent reviews of IT companies and professionals. The company connects businesses with vetted IT experts across disciplines such as development, design, consulting, and other services, emphasizing reliability and quality delivery. Through detailed profiles, genuine reviews, and ratings, Codians.ai helps organizations make informed decisions when selecting technology partners. Its user-friendly interface streamlines the process of finding and hiring top IT talent, supporting both businesses in scaling projects and professionals in showcasing expertise and building reputations.
Key Responsibilities
-Lead the design and implementation of GitLab CI security stages covering SAST, DAST, SCA, and vulnerability scanningDefine and oversee the integration of SonarQube, OWASP ZAP, Trivy, Syft, and Grype into build and deployment pipelinesDrive software supply chain security, including SBOM generation and Cosign image signingSet Kubernetes security standards using Kyverno, OPA/Gatekeeper, and Kubernetes RBACOwn cloud security on AWS across IAM, KMS, Secrets Manager, Inspector, Security Hub, GuardDuty, CloudTrail, CloudWatch Logs, and ACMOversee secrets and certificate management, including HashiCorp VaultLead Linux and Docker hardening initiativesLead SIEM monitoring, VAPT coordination, and security remediation tracking through to closureEnsure alignment with OWASP Top 10, ISO 27001 controls, and DPDP requirementsPartner with development, DevOps, infrastructure, and compliance teams to build secure-by-default practicesMentor and guide security and DevOps engineers, and report security posture to stakeholdersRequired Skills -Application security: SAST, DAST, SCA, vulnerability scanning, OWASP Top 10CI/CD security: GitLab CI security stagesSecurity tools: Trivy, SonarQube, OWASP ZAP, Syft, Grype, CosignKubernetes and containers: Kyverno, OPA/Gatekeeper, Docker security, Kubernetes RBACAWS security: IAM, KMS, Secrets Manager, Inspector, Security Hub, GuardDuty, CloudTrail, CloudWatch Logs, ACMSecrets and certificates: Vault, certificate managementSystems: Linux hardeningGovernance and operations: IAM, ISO 27001 controls, DPDP awareness, SIEM monitoring, VAPT coordination, security remediation trackingCertifications -AWS Certified Security – Specialty, AWS Solutions Architect Associate, or an equivalent cloud certificationCKS or KCSACEH