All fields marked * are required
Key Responsibilities
CI/CD & Infrastructure Automation
• Design, implement, and maintain secure CI/CD pipelines for data engineering and machine learning workloads.
• Develop Infrastructure as Code (IaC) solutions using Terraform, AWS CloudFormation, or similar tools.
• Automate application, infrastructure, and data platform deployments across environments.
• Integrate security scanning, vulnerability assessment, and compliance validation into CI/CD workflows.
• Implement automated deployment, rollback, and recovery mechanisms.
AWS Platform & Multi-Account Management
• Build, configure, and manage AWS multi-account environments using AWS Organizations and Control Tower.
• Establish cloud environments aligned with AWS security best practices and well-architected principles.
• Implement account-level guardrails, governance frameworks, and environment segregation.
• Support scaling and management of enterprise-grade cloud infrastructure.
Identity & Access Management
• Design and implement secure IAM strategies across AWS services.
• Configure IAM roles, policies, permission boundaries, and least-privilege access controls.
• Manage AWS Lake Formation permissions and fine-grained access control for data assets.
• Enforce Role-Based Access Control (RBAC) and secure authentication mechanisms.
• Conduct periodic reviews of access privileges and security configurations.
Security, Governance & Compliance
• Automate governance controls and compliance checks as part of deployment pipelines.
• Develop and maintain cloud security policies, standards, and operational guardrails.
• Implement compliance automation for production and non-production environments.
• Ensure adherence to organizational security, audit, and regulatory requirements.
• Support security audits, risk assessments, and remediation activities.
Monitoring, Logging & Observability
• Implement enterprise-wide monitoring and observability solutions.
• Configure and manage:
o Amazon CloudWatch
o AWS CloudTrail
o AWS Config
o Security Hub
o GuardDuty
• Develop alerting mechanisms for infrastructure, data pipelines, and SageMaker workloads.
• Create operational dashboards and monitoring reports for stakeholders.
Data & ML Platform Security
• Secure AWS SageMaker environments and ML deployment pipelines.
• Implement encryption strategies for data at rest and in transit.
• Configure secure data access controls for S3, Glue, Athena, and Lake Formation.
• Support model governance and secure ML lifecycle management.
Secrets Management & Encryption
• Implement secure credential management using:
o AWS Secrets Manager
o AWS Systems Manager Parameter Store
• Configure KMS encryption for:
o Amazon S3
o Databases
o Data pipelines
o ML workloads
• Establish key rotation and encryption best practices.
• Eliminate hardcoded secrets and improve credential security across platforms.
Security Operations & Incident Response
• Conduct regular security reviews and infrastructure assessments.
• Identify and remediate vulnerabilities across cloud environments.
• Develop automated rollback and recovery mechanisms for security incidents.
• Support incident response activities and post-incident reviews.
• Collaborate with Security, DevOps, Data Engineering, and ML Engineering teams.
Documentation & Operational Excellence
• Create and maintain:
o Security standards
o Deployment procedures
o Operational runbooks
o Disaster recovery documentation
o Compliance reports
• Develop secure maintenance and operational playbooks.
• Support knowledge transfer and security awareness initiatives.
Required Skills & Qualifications
Technical Experience
• 6-7 years of experience in DevOps, Cloud Engineering, DevSecOps, or Platform Engineering.
• Strong hands-on experience with AWS cloud services and security best practices.
• Experience building CI/CD pipelines using:
o Azure DevOps
o GitHub Actions
o Jenkins
o GitLab CI/CD
• Expertise in Infrastructure as Code:
o Terraform
o AWS CloudFormation
AWS Services
• AWS Organizations
• AWS Control Tower
• IAM
• AWS Lake Formation
• AWS KMS
• AWS Secrets Manager
• Amazon S3
• AWS Glue
• AWS Lambda
• AWS Step Functions
• Amazon SageMaker
• AWS Config
• CloudWatch
• CloudTrail
• Security Hub
• GuardDuty
Security & Compliance
• Identity and Access Management (IAM)
• Least Privilege Access Design
• Security Automation
• Compliance Monitoring
• Vulnerability Management
• Data Encryption
• Governance Frameworks
• Audit Readiness
Scripting & Automation
• Python
• Shell Scripting (Bash)
• PowerShell (Preferred)
• YAML/JSON-based deployment templates
Preferred Qualifications
• AWS Certified Security – Specialty (Preferred)
• AWS Certified DevOps Engineer – Professional
• AWS Certified Solutions Architect – Associate/Professional
• Experience supporting enterprise Data Lake or Lakehouse platforms.
• Exposure to MLOps and Machine Learning infrastructure security.
• Experience with container platforms such as Docker and Kubernetes.
• Familiarity with SOC2, ISO 27001, GDPR, or similar compliance frameworks.
Soft Skills
• Strong analytical and troubleshooting skills.
• Excellent communication and stakeholder management abilities.
• Ability to work in cross-functional teams.
• Strong documentation and process improvement mindset.
• Proactive approach to security and risk management.
• Ability to operate effectively in Agile environments.
Required
Preferred
All fields marked * are required
Key Responsibilities
CI/CD & Infrastructure Automation
• Design, implement, and maintain secure CI/CD pipelines for data engineering and machine learning workloads.
• Develop Infrastructure as Code (IaC) solutions using Terraform, AWS CloudFormation, or similar tools.
• Automate application, infrastructure, and data platform deployments across environments.
• Integrate security scanning, vulnerability assessment, and compliance validation into CI/CD workflows.
• Implement automated deployment, rollback, and recovery mechanisms.
AWS Platform & Multi-Account Management
• Build, configure, and manage AWS multi-account environments using AWS Organizations and Control Tower.
• Establish cloud environments aligned with AWS security best practices and well-architected principles.
• Implement account-level guardrails, governance frameworks, and environment segregation.
• Support scaling and management of enterprise-grade cloud infrastructure.
Identity & Access Management
• Design and implement secure IAM strategies across AWS services.
• Configure IAM roles, policies, permission boundaries, and least-privilege access controls.
• Manage AWS Lake Formation permissions and fine-grained access control for data assets.
• Enforce Role-Based Access Control (RBAC) and secure authentication mechanisms.
• Conduct periodic reviews of access privileges and security configurations.
Security, Governance & Compliance
• Automate governance controls and compliance checks as part of deployment pipelines.
• Develop and maintain cloud security policies, standards, and operational guardrails.
• Implement compliance automation for production and non-production environments.
• Ensure adherence to organizational security, audit, and regulatory requirements.
• Support security audits, risk assessments, and remediation activities.
Monitoring, Logging & Observability
• Implement enterprise-wide monitoring and observability solutions.
• Configure and manage:
o Amazon CloudWatch
o AWS CloudTrail
o AWS Config
o Security Hub
o GuardDuty
• Develop alerting mechanisms for infrastructure, data pipelines, and SageMaker workloads.
• Create operational dashboards and monitoring reports for stakeholders.
Data & ML Platform Security
• Secure AWS SageMaker environments and ML deployment pipelines.
• Implement encryption strategies for data at rest and in transit.
• Configure secure data access controls for S3, Glue, Athena, and Lake Formation.
• Support model governance and secure ML lifecycle management.
Secrets Management & Encryption
• Implement secure credential management using:
o AWS Secrets Manager
o AWS Systems Manager Parameter Store
• Configure KMS encryption for:
o Amazon S3
o Databases
o Data pipelines
o ML workloads
• Establish key rotation and encryption best practices.
• Eliminate hardcoded secrets and improve credential security across platforms.
Security Operations & Incident Response
• Conduct regular security reviews and infrastructure assessments.
• Identify and remediate vulnerabilities across cloud environments.
• Develop automated rollback and recovery mechanisms for security incidents.
• Support incident response activities and post-incident reviews.
• Collaborate with Security, DevOps, Data Engineering, and ML Engineering teams.
Documentation & Operational Excellence
• Create and maintain:
o Security standards
o Deployment procedures
o Operational runbooks
o Disaster recovery documentation
o Compliance reports
• Develop secure maintenance and operational playbooks.
• Support knowledge transfer and security awareness initiatives.
Required Skills & Qualifications
Technical Experience
• 6-7 years of experience in DevOps, Cloud Engineering, DevSecOps, or Platform Engineering.
• Strong hands-on experience with AWS cloud services and security best practices.
• Experience building CI/CD pipelines using:
o Azure DevOps
o GitHub Actions
o Jenkins
o GitLab CI/CD
• Expertise in Infrastructure as Code:
o Terraform
o AWS CloudFormation
AWS Services
• AWS Organizations
• AWS Control Tower
• IAM
• AWS Lake Formation
• AWS KMS
• AWS Secrets Manager
• Amazon S3
• AWS Glue
• AWS Lambda
• AWS Step Functions
• Amazon SageMaker
• AWS Config
• CloudWatch
• CloudTrail
• Security Hub
• GuardDuty
Security & Compliance
• Identity and Access Management (IAM)
• Least Privilege Access Design
• Security Automation
• Compliance Monitoring
• Vulnerability Management
• Data Encryption
• Governance Frameworks
• Audit Readiness
Scripting & Automation
• Python
• Shell Scripting (Bash)
• PowerShell (Preferred)
• YAML/JSON-based deployment templates
Preferred Qualifications
• AWS Certified Security – Specialty (Preferred)
• AWS Certified DevOps Engineer – Professional
• AWS Certified Solutions Architect – Associate/Professional
• Experience supporting enterprise Data Lake or Lakehouse platforms.
• Exposure to MLOps and Machine Learning infrastructure security.
• Experience with container platforms such as Docker and Kubernetes.
• Familiarity with SOC2, ISO 27001, GDPR, or similar compliance frameworks.
Soft Skills
• Strong analytical and troubleshooting skills.
• Excellent communication and stakeholder management abilities.
• Ability to work in cross-functional teams.
• Strong documentation and process improvement mindset.
• Proactive approach to security and risk management.
• Ability to operate effectively in Agile environments.
Required
Preferred