All fields marked * are required
Job Summary
We are seeking a highly skilled AWS DevSecOps Engineer with 6-7 years of experience in designing, securing, and automating cloud-native data and machine learning platforms. The ideal candidate will be responsible for implementing secure CI/CD pipelines, managing multi-account AWS environments, enforcing governance and compliance controls, and ensuring the security, reliability, and operational excellence of data and ML workloads.
This role requires strong expertise in AWS cloud services, Infrastructure as Code (IaC), security automation, DevSecOps practices, monitoring, compliance, and platform engineering.
Key Responsibilities
CI/CD & Infrastructure Automation
路 Design, implement, and maintain secure CI/CD pipelines for data engineering and machine learning workloads.
路 Develop Infrastructure as Code (IaC) solutions using Terraform, AWS CloudFormation, or similar tools.
路 Automate application, infrastructure, and data platform deployments across environments.
路 Integrate security scanning, vulnerability assessment, and compliance validation into CI/CD workflows.
路 Implement automated deployment, rollback, and recovery mechanisms.
AWS Platform & Multi-Account Management
路 Build, configure, and manage AWS multi-account environments using AWS Organizations and Control Tower.
路 Establish cloud environments aligned with AWS security best practices and well-architected principles.
路 Implement account-level guardrails, governance frameworks, and environment segregation.
路 Support scaling and management of enterprise-grade cloud infrastructure.
Identity & Access Management
路 Design and implement secure IAM strategies across AWS services.
路 Configure IAM roles, policies, permission boundaries, and least-privilege access controls.
路 Manage AWS Lake Formation permissions and fine-grained access control for data assets.
路 Enforce Role-Based Access Control (RBAC) and secure authentication mechanisms.
路 Conduct periodic reviews of access privileges and security configurations.
Security, Governance & Compliance
路 Automate governance controls and compliance checks as part of deployment pipelines.
路 Develop and maintain cloud security policies, standards, and operational guardrails.
路 Implement compliance automation for production and non-production environments.
路 Ensure adherence to organizational security, audit, and regulatory requirements.
路 Support security audits, risk assessments, and remediation activities.
Monitoring, Logging & Observability
路 Implement enterprise-wide monitoring and observability solutions.
路 Configure and manage:
o Amazon CloudWatch
o AWS CloudTrail
o AWS Config
o Security Hub
o GuardDuty
路 Develop alerting mechanisms for infrastructure, data pipelines, and SageMaker workloads.
路 Create operational dashboards and monitoring reports for stakeholders.
Data & ML Platform Security
路 Secure AWS SageMaker environments and ML deployment pipelines.
路 Implement encryption strategies for data at rest and in transit.
路 Configure secure data access controls for S3, Glue, Athena, and Lake Formation.
路 Support model governance and secure ML lifecycle management.
Secrets Management & Encryption
路 Implement secure credential management using:
o AWS Secrets Manager
o AWS Systems Manager Parameter Store
路 Configure KMS encryption for:
o Amazon S3
o Databases
o Data pipelines
o ML workloads
路 Establish key rotation and encryption best practices.
路 Eliminate hardcoded secrets and improve credential security across platforms.
Security Operations & Incident Response
路 Conduct regular security reviews and infrastructure assessments.
路 Identify and remediate vulnerabilities across cloud environments.
路 Develop automated rollback and recovery mechanisms for security incidents.
路 Support incident response activities and post-incident reviews.
路 Collaborate with Security, DevOps, Data Engineering, and ML Engineering teams.
Documentation & Operational Excellence
路 Create and maintain:
o Security standards
o Deployment procedures
o Operational runbooks
o Disaster recovery documentation
o Compliance reports
路 Develop secure maintenance and operational playbooks.
路 Support knowledge transfer and security awareness initiatives.
Required
Preferred
All fields marked * are required
Job Summary
We are seeking a highly skilled AWS DevSecOps Engineer with 6-7 years of experience in designing, securing, and automating cloud-native data and machine learning platforms. The ideal candidate will be responsible for implementing secure CI/CD pipelines, managing multi-account AWS environments, enforcing governance and compliance controls, and ensuring the security, reliability, and operational excellence of data and ML workloads.
This role requires strong expertise in AWS cloud services, Infrastructure as Code (IaC), security automation, DevSecOps practices, monitoring, compliance, and platform engineering.
Key Responsibilities
CI/CD & Infrastructure Automation
路 Design, implement, and maintain secure CI/CD pipelines for data engineering and machine learning workloads.
路 Develop Infrastructure as Code (IaC) solutions using Terraform, AWS CloudFormation, or similar tools.
路 Automate application, infrastructure, and data platform deployments across environments.
路 Integrate security scanning, vulnerability assessment, and compliance validation into CI/CD workflows.
路 Implement automated deployment, rollback, and recovery mechanisms.
AWS Platform & Multi-Account Management
路 Build, configure, and manage AWS multi-account environments using AWS Organizations and Control Tower.
路 Establish cloud environments aligned with AWS security best practices and well-architected principles.
路 Implement account-level guardrails, governance frameworks, and environment segregation.
路 Support scaling and management of enterprise-grade cloud infrastructure.
Identity & Access Management
路 Design and implement secure IAM strategies across AWS services.
路 Configure IAM roles, policies, permission boundaries, and least-privilege access controls.
路 Manage AWS Lake Formation permissions and fine-grained access control for data assets.
路 Enforce Role-Based Access Control (RBAC) and secure authentication mechanisms.
路 Conduct periodic reviews of access privileges and security configurations.
Security, Governance & Compliance
路 Automate governance controls and compliance checks as part of deployment pipelines.
路 Develop and maintain cloud security policies, standards, and operational guardrails.
路 Implement compliance automation for production and non-production environments.
路 Ensure adherence to organizational security, audit, and regulatory requirements.
路 Support security audits, risk assessments, and remediation activities.
Monitoring, Logging & Observability
路 Implement enterprise-wide monitoring and observability solutions.
路 Configure and manage:
o Amazon CloudWatch
o AWS CloudTrail
o AWS Config
o Security Hub
o GuardDuty
路 Develop alerting mechanisms for infrastructure, data pipelines, and SageMaker workloads.
路 Create operational dashboards and monitoring reports for stakeholders.
Data & ML Platform Security
路 Secure AWS SageMaker environments and ML deployment pipelines.
路 Implement encryption strategies for data at rest and in transit.
路 Configure secure data access controls for S3, Glue, Athena, and Lake Formation.
路 Support model governance and secure ML lifecycle management.
Secrets Management & Encryption
路 Implement secure credential management using:
o AWS Secrets Manager
o AWS Systems Manager Parameter Store
路 Configure KMS encryption for:
o Amazon S3
o Databases
o Data pipelines
o ML workloads
路 Establish key rotation and encryption best practices.
路 Eliminate hardcoded secrets and improve credential security across platforms.
Security Operations & Incident Response
路 Conduct regular security reviews and infrastructure assessments.
路 Identify and remediate vulnerabilities across cloud environments.
路 Develop automated rollback and recovery mechanisms for security incidents.
路 Support incident response activities and post-incident reviews.
路 Collaborate with Security, DevOps, Data Engineering, and ML Engineering teams.
Documentation & Operational Excellence
路 Create and maintain:
o Security standards
o Deployment procedures
o Operational runbooks
o Disaster recovery documentation
o Compliance reports
路 Develop secure maintenance and operational playbooks.
路 Support knowledge transfer and security awareness initiatives.
Required
Preferred