Senior DevSecOps Engineer – AWS CloudHSM | Terraform | JFrog
Asian Hires · Bengaluru, Karnataka, India
Apply & track with Apply EdgeExperience: 7–10 Years
Location: Bangalore — Bangalore candidates preferredCTC: ₹13–15 LPAInterview: SaturdayL1: Face-to-Face in BangaloreShift: Up to 10 PM US shift; otherwise normal shiftRole Type: Senior Individual ContributorRole OverviewWe are looking for a Senior DevSecOps Engineer to design, build, and operate the cryptographic and infrastructure foundation for an Agentic Authentication Platform.The role has three core technology areas:AWS CloudHSM + Terraform/Terragrunt + JFrog ArtifactoryThe engineer will also work across AWS, EKS/Kubernetes, Helm, GitOps, CI/CD, cloud networking, Zero Trust, and security-focused platform engineering.Key ResponsibilitiesAWS CloudHSMDesign and deploy CloudHSM clusters.Perform key ceremonies and key rotation.Manage high-availability operations.Integrate CloudHSM with downstream authentication and signing services.Terraform / TerragruntDesign multi-environment infrastructure across Dev, QA, Stage, and Production.Build reusable/DRY Terraform modules.Manage remote-state governance.Implement Policy-as-Code using OPA/Sentinel in CI.JFrog ArtifactoryManage enterprise artifact governance.Manage signed container images and Helm charts.Implement SBOM generation and scanning gates.Integrate artifact promotion with GitOps workflows.EKS / KubernetesManage production AWS EKS environments.Work with Helm charts and CRDs.Support service mesh implementations.Implement ingress/egress controls and Zero Trust principles.Security & ObservabilityBuild observability for delegation chains and audit trails.Ensure auditability of who acted on whose behalf, with what scope, and when.Work with IAM, KMS, networking, DNS, firewalls, routing, and AWS security services.Support GitOps and CI/CD pipelines.Mandatory Skills🔴 AWS CloudHSM – hands-on production experience🔴 Terraform + Terragrunt🔴 JFrog Artifactory🔴 7+ years in DevSecOps / Platform Engineering / SRE with security focus🔴 Strong AWS – VPC, IAM, KMS, EKS, Route 53, security services🔴 Production Kubernetes / EKS🔴 Helm & CRDs🔴 Cloud networking – DNS, firewalls, routing🔴 GitOps & CI/CD🔴 Zero Trust principlesPreferred SkillsCryptographic delegation flows - OAuth 2.0 token exchange, workload identity federation.Familiarity with agentic security patterns (scoped-capability tokens).Policy-as-Code (OPA / Sentinel).AWS Professional / Specialty certs; Kubernetes certs (CKA, CKAD, CKS).