Key Responsibilities
•Design and develop custom security controls based on threat modelling outputs
•Build:
oDetective controls using Python-based frameworks
oPreventative controls using OPA/Rego policies
•Extend and enhance existing security control frameworks
•Develop and maintain:
oAutomated unit tests
oBehavioral (BDD) test cases
•Integrate controls into CI/CD pipelines for continuous validation
•Collaborate with:
oThreat modeling teams
oCloud architects
oSecurity SMEs
Required Qualifications
This is a development-heavy role. Candidates must demonstrate strong coding capability.
Security experience is required, but coding proficiency is mandatory.
•Minimum of 3-5 years of experience in DevSecOps engineering with a focus on cloud environments (AWS, GCP, Azure), ideally working within a security program.
•Strong software engineering background - proficiency in software testing methodologies and tools.
•Advanced proficiency in Python - proficiency with Python and Terraform for testing, automation and custom tool development.
•Proficiency with:
oAPI integrations and backend development
oWriting scalable, maintainable code
•Hands-on experience with:
oAutomated testing frameworks (Python)
oCI/CD pipelines
•Experience with cloud-native development and architecture, leveraging services and tools specific to AWS, GCP, and Azure.
•Experience with detection engineering: detection-as-code practices, developing and maintaining detection rules
•Hands-on experience with Open Policy Agency (OPA) for policy enforcement
•Proficiency in DevOps tools and practices
•Experience with SIEM query languages such as Splunk SPL, YARA rules, etc.
•MUST pass Karat Assessment (Python focused).
Salary Range: $100,000 to $150,000 per year
More Information
Application Details
- Organization DetailsTCS / Tata Consultancy Services


Recommended Comments
There are no comments to display.
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.