Senior Specialist - Architecture
Indexed description
Experience: 7–11 Years
About The Role
We are looking for a Senior DevSecOps Engineer to design, build, and operate secure cryptographic and infrastructure foundations for an agentic authentication platform. The role is a hands-on individual contributor position focused on AWS CloudHSM, Terraform/Terragrunt, JFrog Artifactory, AWS, Kubernetes, and DevSecOps.
Job Description
The role focuses on building and operating secure cloud infrastructure, including AWS CloudHSM cluster design, deployment, key ceremonies, rotation, high availability, and integration with authentication and signing services.
The engineer will develop governed multi-environment infrastructure using Terraform and Terragrunt, manage enterprise artifact governance through JFrog Artifactory, and support EKS platform operations, Helm, CRDs, and service mesh capabilities. The position also involves implementing Zero Trust principles, GitOps/CICD practices, observability, and audit trails.
Key Responsibilities
- Design, deploy, and operate AWS CloudHSM clusters, including key management, rotation, and HA operations.
- Build multi-environment Terraform/Terragrunt modules with appropriate governance and Policy-as-Code practices.
- Manage JFrog Artifactory, including signed builds, container images, Helm charts, SBOM generation, scanning, and promotion policies.
- Operate AWS EKS platforms using Kubernetes, Helm, CRDs, and service mesh technologies.
- Implement Zero Trust controls and secure ingress/egress patterns.
- Design and manage cloud networking, including VPC, DNS, routing, firewalls, IAM, and Route 53.
- Develop GitOps and CI/CD pipelines supporting secure and governed deployments.
- Maintain delegation-chain observability and audit trails to track authorization scope and actions.
- DevSecOps / Platform Engineering / SRE
- AWS CloudHSM
- Terraform and Terragrunt
- JFrog Artifactory
- AWS: VPC, IAM, KMS, EKS, Route 53, security services
- Kubernetes, EKS, Helm, and CRDs
- Cloud networking, DNS, firewalls, and routing
- Zero Trust and service mesh — Istio, Envoy, Linkerd, or App Mesh
- GitOps and CI/CD
- Application Security and DevSecOps
- Secure SDLC, threat modelling, and Application Security Architecture Review
- Cryptographic delegation flows, OAuth 2.0, token exchange, and workload identity federation
- Agentic security patterns and scoped-capability tokens
- Policy-as-Code using OPA or Sentinel
- AWS Professional/Specialty certifications
- Kubernetes certifications such as CKA, CKAD, or CKS
- Application Security, including application security frameworks, threat modelling, Secure SDLC, DevSecOps, and Application Security Architecture Review
The ideal candidate should have 7+ years of experience in DevSecOps, Platform Engineering, or SRE with a security focus, along with strong hands-on cloud infrastructure expertise. The candidate should be comfortable operating production AWS and Kubernetes environments and working across security, infrastructure, and engineering teams.
Benefits Package
- Competitive salary and benefits package
- Opportunities for professional growth and development
- A collaborative and inclusive work environment
- The opportunity to work on exciting and challenging projects with leading clients
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search