- Location
- India Corporate Headquarters - Hyderabad
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Closing date
- Today
- Source
- Workday
Description
Why AIS?
When you join AIS, you’re joining a mission-driven team that’s passionate about making a difference. You’ll work on projects that matter, alongside industry-leading experts, in an environment that fosters innovation, driving client success, and empowering our team to make a lasting impact. As an employee-owned company, we value collaboration, inclusivity, continuous growth, and shared success.
Employee Ownership: Your contributions directly impact the company’s success, and you share in its achievements.
Continuous Learning: Access to resources, training, and mentorship to support your professional growth.
Inclusive Culture: A workplace where diversity is celebrated, and everyone’s voice is valued.
Mission-Driven Work: Engage in projects that make a meaningful difference for our clients and communities.
What are we looking for?
At AIS, we're looking for more than just skills - we're looking for driven individuals who are passionate about making a difference, eager to grow, and aligned with our core principles.
Working@AIS
At AIS, we are dedicated to providing our employees with diverse opportunities to grow their careers while supporting a variety of impactful projects. For this position, we are seeking a talented individual to join AIS as a DevOps Engineer.
Core Knowledge & Skills: Proficient with branching strategies, CI/CD automation, Infrastructure as Code (e.g., Terraform/Ansible), and intermediate scripting; improves monitoring and security practices.
Work & Complexity: Manages and optimizes pipelines for multiple projects, automates deployments, and resolves moderately complex infrastructure issues.
Quality & Independence: Conducts thorough testing, enhances reliability and performance, documents changes, and works independently on routine projects.
Teamwork & Communication: Coordinates with developers and operations teams, shares knowledge, provides clear updates, and helps align team efforts.
Consulting & Engagement: Advises on DevOps process improvements, offers technical recommendations, and participates in cross-functional initiatives.
.Project Summary
We are seeking a hands-on Security Engineer to lead vulnerability remediation across a multi-subscription Azure environment. The role spans infrastructure, application, platform, and identity related findings, including access reviews and exposed credentials. The person will track remediation against defined timelines, support audits and compliance reviews, and report on risk trends from internal, external, and vendor sources. Automation and repeatable processes are central to the work, and the role requires enough technical depth to build and maintain that automation. The person will also support broader security initiatives as priorities shift.
Key Responsibilities
Cloud & Infrastructure Security Remediation:
- Remediate vulnerabilities across multiple Azure subscriptions
- Address findings from Wiz (CSPM/CNAPP) and External scanning platforms (RiskRecon, Security Scorecard, etc.)
- Investigate and resolve infrastructure-level security risks across Cloud resources (IaaS / PaaS), Networking components, Storage and supporting services
Vulnerability Management & Patching:
- Assist in remediation of OS and infrastructure vulnerabilities, including OS patching and hardening (Windows / Linux), VM OS updates and lifecycle management
- Identify and address end-of-life (EOL) systems and dependencies
- Establish repeatable processes for Patch management, Vulnerability tracking and reporting, Risk prioritization
Application Security Remediation:
- Partner with development teams to remediate SAST findings (e.g., Snyk), DAST findings (e.g., Invicti), Open-source library vulnerabilities, Penetration Testing Findings
- Support secure configuration of application environments
DevSecOps & Automation:
- Integrate security into Azure DevOps CI/CD pipelines where applicable
- Improve overall DevSecOps maturity
Security Program Support:
- Support assigned security program initiatives as directed by leadership
- Assist with security review documentation for client and audit requests
- Contribute to remediation tracking and reporting across security workstreams
Observability & Reporting:
- Analyze and prioritize vulnerabilities based on Severity (CVSS), Exploitability, Business impact
- Provide regular updates on Remediation progress, Risk reduction trends, Outstanding issues
Required Skills & Experience
Core Technical Skills:
- Strong experience in Microsoft Azure PaaS and IaaS resources, networking, identity, storage
- Hands-on expertise with Systems administration and patching (Windows, Linux, etc.), Infrastructure vulnerability remediation
- Familiarity with Wiz or similar CSPM/CNAPP tools, Vulnerability scanners (Nessus, Qualys, etc.), Azure Policy
Security & DevOps:
- Experience with SAST/DAST tools (Snyk, Invicti, etc.), Dependency and open-source vulnerability remediation
- Understanding of Cloud security best practices, Secure configuration standards (CIS, NIST, etc.)
Nice to Have Skills
- Experience with Azure Automation / Update Management, Infrastructure as Code (Terraform, ARM, Bicep, etc.), CI/CD pipelines (Azure DevOps, GitHub Actions, etc.), Penetration Testing
- Familiarity with Risk scoring platforms (SecurityScorecard, RiskRecon), Monitoring Tools (DataDog, Grafana, etc.)