Our client, PureLogics, is seeking a skilled DevSecOps Engineer based in Lahore. The ideal candidate will have strong expertise in cloud platforms such as AWS, Azure, and GCP, along with hands-on experience in containerization technologies like Docker, Kubernetes, and OpenShift. This role focuses on integrating security best practices into DevOps processes, automating security testing within CI/CD pipelines, and leading ethical hacking and penetration testing efforts to safeguard infrastructure and applications. The candidate will work closely with cross-functional teams to design, deploy, and maintain secure cloud environments using Infrastructure as Code (IaC) tools, while ensuring compliance with industry security standards.
Key Responsibilities
- Lead and manage a team of six DevSecOps professionals, fostering a culture of security awareness and best practices.
- Design, implement, and maintain secure cloud infrastructure using IaC tools such as Terraform, CloudFormation, or Ansible to ensure scalability and compliance.
- Integrate security tools and policies into CI/CD pipelines to automate vulnerability assessments, security testing, and incident detection.
- Develop and enforce container security strategies to protect Docker, Kubernetes, and OpenShift environments.
- Automate security scanning, configuration management, and patch management processes across cloud and application environments.
- Conduct ethical hacking, penetration testing, and security audits using tools like Burp Suite, Metasploit, Nmap, and Kali Linux to identify vulnerabilities and recommend mitigation strategies.
- Monitor security alerts and perform risk assessments using SIEM tools such as Splunk, ELK, or AWS Security Hub.
- Collaborate with development, operations, and security teams to identify security gaps and implement effective remediation measures.
- Ensure adherence to security compliance frameworks including NIST, CIS, ISO 27001, and SOC 2, and assist in regular security audits.
- Conduct threat modeling and risk assessments to continuously improve the organization's security posture.
- Provide ongoing training and mentorship to team members on emerging security technologies, threats, and best practices.
- Document security processes, incident reports, and compliance status for communication with stakeholders and management.
- Stay updated with the latest security threats, vulnerabilities, and industry trends to proactively enhance security defenses.
Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field.
- Proven experience with cloud platforms (AWS, Azure, GCP) and containerization technologies (Docker, Kubernetes, OpenShift).
- Strong knowledge of Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or Ansible.
- Hands-on experience with penetration testing, ethical hacking, and security auditing tools.
- Familiarity with security compliance frameworks and incident response procedures.
Preferred Qualifications and Benefits
PureLogics is a well-established technology company with over 18 years of experience and a presence in the USA, UAE, and Lahore. The company is CMMI Level 2 and ISO certified, and recognized as a leading AWS consulting partner. PureLogics values building a team of high-performing professionals who strive for excellence and innovation.
The company offers a supportive environment for individuals eager to tackle challenging projects under expert mentorship. Benefits include annual paid leaves, leave encashment, paid certifications, health and life insurance, provident fund, child education program, referral bonus program, car and bike financing options, monthly achievement rewards, and compensation for public holidays and weekends.
This role provides an excellent opportunity to grow professionally while contributing to securing cutting-edge cloud and application environments within a dynamic and collaborative team.