Overview
Join Smartsheet's global Security Operations team as a Senior DevSecOps Engineer. Engineer and operate reliable, scalable, and defensible production environments at the intersection of Site Reliability Engineering, infrastructure automation, and security.
What you'll do
- Design, build, maintain, and improve secure, scalable, and highly available infrastructure in a multi-cloud environment, primarily AWS, using Infrastructure as Code principles with tools like Terraform, Kubernetes, and Helm.
- Engineer and automate threat detection, incident response, and vulnerability management processes.
- Build the tools and workflows that allow the team to respond to threats at machine speed.
- Architect and secure CI/CD pipelines by integrating automated security tooling, including SAST, DAST, and SCA.
- Manage, operate, and secure the Kubernetes container orchestration platform.
- Implement container security best practices from registry to runtime, including hardening requirements such as CIS Benchmarks or DISA STIG.
- Act as a technical lead during security and reliability incidents.
- Drive incident resolution and conduct blameless post-mortems to engineer preventative solutions.
- Implement and automate technical controls for continuous compliance with frameworks such as FedRAMP, SOC 2, and ISO 27001.
- Serve as a subject matter expert for security and reliability.
- Mentor other engineers and champion operational excellence and security ownership across the organization.
What you'll need
- 8+ years of progressive experience in technology, including at least 5 years in a hands-on senior role such as Site Reliability Engineering, DevOps, or Security Engineering.
- A BS or MS in Computer Science, Engineering, or a related field, or equivalent industry experience.
- Expert-level proficiency in at least one major cloud provider, with deep knowledge of core infrastructure and security services.
- Expert-level proficiency with Infrastructure as Code, particularly Terraform.
- Expert-level proficiency with a scripting or programming language such as Python, Go, or Ruby.
- A proven history of building automation and custom tooling.
- Deep experience with containerization and orchestration technologies, including Kubernetes.
- Experience securing containerized environments.
- Proficiency with the modern security operations toolchain, including SIEM, EDR, and vulnerability scanning technologies.
- Experience integrating security tools, including SAST, DAST, and SCA, into CI/CD pipelines.
- A critical-thinking approach and a proven ability to troubleshoot complex problems in high-pressure production environments.
- Excellent verbal and written communication skills and a collaborative spirit.
- Fluency in English.
Nice to have
- Advanced industry certifications such as CISSP, CISM, OSCP, or cloud-specific security certifications.
- Experience with compliance frameworks like FedRAMP, ISO27001, and SOC2.
Details
- Location: Bangalore, India.
- Work mode: Hybrid in Bangalore.
Read the full description and apply on the company’s own careers page.