Talent Apply
Log in
All jobs
DM

Senior DevSecOps Engineer

dr martens
Bengaluru
On-site

About this role

About the Role The DevSecOps Engineer will be a core member of the Brand Experience team, enabling reliable, secure and compliant delivery of Dr. Martens’ Next.js storefront with a Backend-for-Frontend pattern hosted on AWS. This role operates in a You Build It, You Run It model, embedding security across the software delivery lifecycle to help product teams ship faster while meeting performance, privacy and regulatory expectations in a digital commerce environment. What You'll Do

  • AWS Cloud & Platform Security: Design and operate secure-by-default AWS foundations for Next.js and BFF workloads, including VPC design, segmentation, edge/CDN protections, and least-privilege controls; own Infrastructure as Code (IaC) security standards using Terraform and/or CloudFormation; embed policy-as-code (Checkov, tfsec, OPA/Conftest) and reusable hardened modules; define baselines for IAM, KMS, networking, logging, and guardrails (AWS Config, Security Hub, GuardDuty, SCPs).
  • Secure CI/CD & Software Supply Chain: Build and harden CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, AWS-native tooling) with integrated SAST, DAST, SCA, IaC scanning, container image scanning, and secrets detection; implement software supply chain controls (signed commits, artifact signing, SBOM generation, dependency provenance, protected release paths); enable progressive delivery and safe rollback patterns.
  • Threat & Vulnerability Management: Operate continuous vulnerability discovery across cloud, container, application and dependency layers; drive risk-based prioritisation and remediation SLAs; lead threat modelling and secure design reviews for new features; define and operate web application protections (WAF, bot mitigation, rate limiting) for storefront and BFF endpoints.
  • Identity, Secrets & Data Protection: Own secrets management and rotation (e.g., AWS Secrets Manager, Parameter Store, HashiCorp Vault), eliminating hard-coded credentials across services and pipelines; implement encryption in transit and at rest, certificate lifecycle management, and key governance using KMS. What We're Looking For
  • Experience designing and operating secure-by-default AWS foundations for modern web storefronts and BFF architectures.
  • Proficiency with Infrastructure as Code (Terraform and/or CloudFormation) and policy-as-code tooling (e.g., Checkov, tfsec, OPA/Conftest), plus reusable hardened modules.
  • Strong background in securing CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, AWS tooling) with SAST/DAST/SCA, IaC scanning, container scanning, and secrets detection.
  • Knowledge of software supply chain controls (signed commits, SBOM, artifact provenance) and safe release practices such as progressive delivery.
  • Demonstrated ability in threat modelling, secure design reviews, and implementing web application protections (WAF, bot mitigation, rate limiting).
  • Expertise in Identity, Secrets & Data Protection: secrets management (Secrets Manager, Parameter Store, Vault), encryption in transit/rest, and key management using KMS. Compensation & Benefits
  • Salary: Competitive

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →