All jobs
MindPlus (Pvt)DevOps
DevSecOps
Sri LankaPosted today
The role is for a Team Lead / Associate Team Lead in DevSecOps, focusing on leading security integration across development and operations in a data-driven organization serving the Financial Services Industry.
Location: Sri Lanka
Responsibilities
- Lead and mentor a team of DevSecOps engineers across cloud, application, and infrastructure security domains.
- Define and drive DevSecOps strategy, standards, and best practices across the organisation.
- Architect and oversee secure CI/CD pipelines, including SAST, DAST, SCA, container, and IaC scanning.
- Design and implement security solutions across Azure, AWS, and hybrid environments.
- Ensure secure Infrastructure as Code (IaC) practices using Terraform, ARM, or similar tools.
- Guide the implementation of container and Kubernetes security, including RBAC, network policies, and image scanning.
- Oversee secrets and identity management, including Azure Key Vault, AWS Secrets Manager, and IAM.
- Drive the automation of security processes, controls, and incident response integrations.
- Collaborate with DevOps, SOC, and engineering teams to embed security across the SDLC.
- Establish and monitor security KPIs, metrics, and reporting.
- Support and lead compliance initiatives such as SOC 2, ISO 27001, and CIS benchmarks.
- Align DevSecOps practices with threat detection and response strategies in coordination with SOC teams.
- Manage stakeholder and client engagements, providing technical leadership and guidance.
Requirements
- 6–8+ years of experience in DevOps, Security, or DevSecOps, including leadership experience.
- 5+ years of experience with strong technical expertise and emerging leadership capabilities.
- Strong hands-on experience with CI/CD tools such as Azure DevOps, GitHub Actions, and Jenkins.
- Deep familiarity with cloud platforms (Azure and/or AWS) and security architecture.
- Strong experience with containerisation technologies such as Docker and Kubernetes.
- Proficiency in scripting (PowerShell, Python, Bash) and Infrastructure as Code (Terraform preferred).
- Strong understanding of application security (OWASP Top 10) and secure SDLC practices.
- Expertise in IAM, RBAC, Zero Trust, and network security principles.
- Proven experience in mentoring teams and managing technical projects.