Job Description
<p>Core Solutions (CORE), headquartered in King of Prussia, Pennsylvania, is a leading provider of Electronic Health Record (EHR) solutions specifically designed for the behavioral healthcare industry.<br/><br/>We serve large healthcare providers with comprehensive software solutions that improve patient outcomes and operational efficiency.<br/><br/>With the introduction of our new version and AI solutions, we are positioning ourselves for rapid growth and market expansion.</p><p><br/><b>Position Summary :</b><br/><br/>We are seeking an experienced Senior DevSecOps Engineer to be part of our technical transformation as we transition to a SaaS-first organization.<br/><br/>This technical role shall be focused on integrating security practices throughout the software development lifecycle, primarily through automation and infrastructure as code.<br/><br/>Senior DevSecOps Engineer shall be responsible for design, implement, and manage secure cloud infrastructure and CI/CD pipelines, ensuring robust security controls and compliance.<br/><br/>This role often involves mentoring junior engineers, leading initiatives, and fostering a culture of continuous :</b><br/><br/>- Own the security design and implementation of CI/CD pipelines (GitHub Actions, GitHub, Octopus, etc.)<br/><br/>- Design and enforce secure infrastructure-as-code (IaC) patterns (Terraform, Cloudformation).<br/><br/>- Implement policy-as-code frameworks (OPA, Sentinel) across Kubernetes and cloud environments (AWS, GCP, Azure preferably AWS).<br/><br/>- Perform threat modeling and risk assessments across microservices and deployment architecture.<br/><br/>- Drive end-to-end integration of SAST, DAST, SCA, secrets scanning, and container scanning tools into pipelines (e.g, SonarQube, Burpsuite etc).<br/><br/>- Lead initiatives around zero-trust architecture, least privilege IAM automation, and secure baseline enforcement.<br/><br/>- Collaborate with developers, SREs, and product managers to drive a security-first culture.<br/><br/>- Mentor and guide junior DevSecOps and DevOps engineers.</p><p><br/><b>Qualifications :</b><br/><br/>- 10+ years of overall experience with over four years in DevOps, Cloud, and Security.<br/><br/>- Deep expertise in AWS/GCP security services (IAM, KMS, VPC, WAF, Shield, S3, RDS, ECS etc.)<br/><br/>- Hands-on with IaC and CI/CD (Terraform, Cloudformation etc.)<br/><br/>- Strong proficiency with scripting (Python, Bash, Powershell, Nodejs etc).<br/><br/>- Expertise in Container security (Sysdig, SecurityPolicies etc.)<br/><br/>- Familiar with compliance frameworks (SOC2, HIPAA, NIST etc.) and automating controls.<br/><br/>- Experience in threat modeling and security risk assessments.</p><p><br/><b>Nice to Have :</b><br/><br/>- OSCP, CISSP, AWS Security or GIAC certifications.<br/><br/>- Experience in building secure SDLC in SaaS-based or multi-tenant platforms.</p><p><br/><b>Job Location</b> : Guindy , Chennai.<br/><br/>Work from office 5 days.<br/><br/>Preferred candidates from chennai location.</p> (ref:hirist.tech)