
- Growing fastShowed strong hiring growth in the past month
DevSecOps Engineer
- ₹12L – ₹25L • No equity
- |Remote (Everywhere)
- |3 years of exp
- |Full Time
Remote only
Not Available
About the job
DevSecOps Engineer
Intempt is an agentic GTM platform processing 350M+ events/month across 9 AI agents and 4 products (Design, Marketing, Sales, Analytics). We run 36+ microservices on AWS EKS, backed by Aurora PostgreSQL, MSK Kafka, ClickHouse, Apache Flink, HashiCorp Vault, and Redis — all managed through Terraform with SOPS-encrypted secrets and deployed via GitHub Actions OIDC.
The infrastructure works. We need someone who can run it and prove, continuously, that it's secure.
This is a security-first role, not DevOps with a security checklist bolted on. You'll own IAM least-privilege across 20+ per-service GitHub Actions deployer roles, container image scanning on every ECR push, Vault secret rotation and Transit engine key management, network segmentation across VPCs and security groups, and vulnerability management for every service in the cluster. Every service has its own ECR repo with immutable tags and scan-on-push - you decide what blocks a deploy.
What you'll own
- Security posture for 36+ microservices — threat modeling, container vulnerability scanning (ECR scan-on-push), remediation SLAs
- IAM and secrets — least-privilege GitHub Actions OIDC deployer roles, HashiCorp Vault HA (KMS auto-unseal, Transit engine, AppRole auth), SOPS+KMS-encrypted Terraform state
- Network security — VPC segmentation, security groups, ALB/WAF rules, TLS everywhere (ACM/cert-manager), service-to-service auth
- EKS cluster operations — node group scaling, spot instances, Fargate profiles, RBAC hardening, Pod Security Standards, and day-2 kubectl work: pods stuck in Pending, CrashLoopBackOff, resource limit tuning
- Terraform IaC across all environments (staging/qa/production) with S3 state backend and policy-as-code guardrails
- Database and streaming security — Aurora PostgreSQL 13.8 encryption at rest/in transit, MSK Kafka 3.3.1 TLS and ACLs, ClickHouse access control
- Incident response — detection tooling (DataDog, CloudWatch), security runbooks, postmortems that fix root cause
- Compliance and DR — audit logging, AWS Backup (daily, 7-day retention), RDS point-in-time recovery, evidence collection for security reviews
You are
- 3+ years in a security-focused infrastructure role — DevSecOps, cloud security, or AppSec, not general DevOps with security as an afterthought
- Deep AWS IAM expertise — least-privilege policies, OIDC federation, cross-account roles; you can read a policy doc and spot the over-permission
- Hands-on with container and supply-chain security — image scanning, SBOM, signed images, dependency vulnerability triage
- Experienced with HashiCorp Vault operations — secret rotation, Transit engine, dynamic secrets, AppRole patterns
- Comfortable running production Kubernetes on AWS — RBAC, network policies, Pod Security Standards, admission control
- Deep hands-on kubectl fluency — you debug a pod stuck in Pending or a CrashLoopBackOff from the events and logs, not a search engine
- Strong Terraform experience — multi-environment IaC, remote state, encrypted secrets, policy-as-code
- Someone who thinks like an attacker first and an operator second — you find the gap before it's exploited
- Bonus: AWS Certified Security – Specialty or AWS Certified Solutions Architect — not required, but it signals the depth we're looking for
Stack you'll live in
AWS (EKS, Aurora, MSK, ElastiCache, S3, CloudFront, Route53, ACM, EFS, IAM, GuardDuty) · Kubernetes 1.25 · Terraform · GitHub Actions (OIDC) · HashiCorp Vault · Container/image scanning (ECR scan-on-push, Trivy) · Apache Flink · ClickHouse (Altinity Cloud) · DataDog · Helm · SOPS + KMS · Docker / ECR · Prometheus
Not a fit if
- You've only used managed Kubernetes through a UI — we need someone who reads the Terraform and knows what every resource does
- You can't debug a pod that won't schedule without googling every error message
- You think security is a quarterly audit, not a daily practice
- You can't explain the blast radius of an over-permissioned IAM role or a leaked Vault token
About the company

Intempt Technologies
- Growing fastShowed strong hiring growth in the past month
Perks
Similar Jobs








