Sr. Security Engineer - Devsecops (hybrid in Bangalore)

Smartsheet Smartsheet · Seattle · India · IT

Senior DevSecOps Engineer responsible for engineering and operating secure, scalable, and highly available infrastructure, automating threat detection, incident response, and vulnerability management, and securing CI/CD pipelines. The role involves managing container security, leading incident response, driving automated compliance with frameworks like FedRAMP and SOC 2, and mentoring other engineers.

What you'd actually do

  1. Engineer Secure and Resilient Infrastructure: Design, build, maintain, and improve secure, scalable, and highly available infrastructure in our multi-cloud environment (primarily AWS) using Infrastructure as Code (IaC) principles with tools like Terraform, Kubernetes, and Helm.
  2. Automate Proactive Security: Engineer and automate threat detection, incident response, and vulnerability management processes. You will build the tools and workflows that allow us to respond to threats at machine speed.
  3. Secure the Software Development Lifecycle: Architect and secure our CI/CD pipelines, integrating automated security tooling (SAST, DAST, SCA) to provide developers with fast, actionable feedback.
  4. Master Container Security: Manage, operate, and secure our container orchestration platform (Kubernetes), implementing best practices for container security from the registry to runtime, including knowledge of hardening requirements such as CIS Benchmarks or DISA STIG.
  5. Lead Incident Response: Act as a technical lead during security and reliability incidents, driving resolution and conducting blameless post-mortems to engineer preventative solutions.

Skills

Required

  • AWS
  • Terraform
  • Python
  • Go
  • Ruby
  • Kubernetes
  • SIEM
  • EDR
  • SAST
  • DAST
  • SCA
  • CI/CD
  • DevOps
  • Security Engineering
  • Site Reliability Engineering

Nice to have

  • CISSP
  • CISM
  • OSCP
  • FedRAMP
  • ISO27001
  • SOC2

What the JD emphasized

  • 8+ years of progressive experience in technology, with at least 5 years in a hands-on senior role such as Site Reliability Engineering, DevOps, or Security Engineering.
  • Expert-level proficiency in at least one major cloud provider, preferably AWS, with deep knowledge of core infrastructure and security services.
  • Expert-level proficiency with Infrastructure as Code, particularly Terraform.
  • Expert-level proficiency in a scripting or programming language such as Python, Go, or Ruby, with a proven history of building automation and custom tooling.
  • Deep experience with containerization and orchestration technologies (Kubernetes), including securing containerized environments.
  • Proficiency with the modern security operations toolchain, including SIEM, EDR, and vulnerability scanning technologies.
  • Experience integrating security tools (SAST, DAST, SCA) into CI/CD pipelines.
  • A critical thinker with a proven ability to troubleshoot complex problems in high-pressure production environments.