About the role
structured by ORIExperience: 1-2 years of experience. Job Summary We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering.
What you will do
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Run and review application and infrastructure vulnerability scans and maintain a vulnerability register.
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
What they are looking for
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Nice to have
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
Full posting text
Experience: 1-2 years of experience.
Job Summary
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
Responsibilities
Security Operations
Monitor infrastructure, application, and security alerts and assist with incident investigation.
Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
Track security issues and corrective actions through closure.
Vulnerability Management
Run and review application and infrastructure vulnerability scans.
Maintain a vulnerability register and coordinate remediation with engineering teams.
Support VAPT and penetration-testing exercises and validate closure of findings.
Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
Maintain device inventory and monitor endpoint compliance.
Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
Automate repetitive deployment, infrastructure, security, and compliance tasks.
Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Requirements
Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Qualifications
1-2 years of experience with strong fundamentals are welcome.
Basic scripting knowledge in Python, Bash, or similar.
Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates
Who can join immediately
Female candidates returning to work after a career break are strongly encouraged.
Job Details
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
Key skills: devops engineering, ci/cd pipelines, ciso, cloudflare, caching, cybersecurity, cloud, automation, cloud cost optimization, apis, compliance, devops, cloud infrastructure, bash, aws, cloud computing, audits, application deployment, azure, deployment.
Role: Site Reliability Engineer
Industry Type: IT Services & Consulting
Department: Engineering - Software & QA
Employment Type: Full Time, Permanent
Role Category: DevOps
Education: UG: Any Graduate
Education: PG: Any Postgraduate
