Job Summary
The company is seeking a SecOps Engineer to design, implement, and operate its core security infrastructure and network security, with particular emphasis on securing and hardening the Kubernetes/container platform. This role is both hands-on and strategic: building secure-by-design infrastructure from the ground up before expanding into SOC/DFIR capability as the security baseline matures. The engineer will combine deep systems/platform expertise with security engineering judgment to close foundational gaps
Key Responsibilities
1. Security Architecture & Infrastructure
- Design and implement Identity & Access Management (IAM/SSO) architecture and Single Sign-On integration across internal applications.
- Design and implement Privileged Access Management (PAM) and Zero Trust Network Access (ZTNA) / identity-aware proxy solutions.
- Design and implement network security architecture, including segmentation, firewalls, VPN, and secure remote access.
- Build infrastructure using Infrastructure-as-Code (Terraform, Ansible) and version-controlled configuration where applicable.
2. Platform & Container Security
- Support the hardening of the company's Kubernetes platform: RBAC design, network policy, workload security baseline, secrets management.
- Contribute to the rollout of Policy-as-Code (e.g., Kyverno, OPA) for cluster governance.
- Collaborate with the current Cluster Admin to reduce single-point-of-failure risk and support knowledge transfer / documentation.
3. SOC Development & Operations
- Support the design, implementation, and day-to-day operation of the company's SOC capabilities (SIEM, EDR, log management, monitoring pipelines).
- Contribute to detection rule and alert logic development as SOC capability is built out.
4. Threat Detection, Response & DFIR
- Participate in security event investigation, containment, and remediation activities.
- Contribute to DFIR playbooks, escalation paths, and evidence-handling procedures.
5. Continuous Improvement & Collaboration
- Assist in tabletop exercises and simulations to validate incident response readiness.
- Collaborate with IT, InfraOps, AppSec, and Red Team functions to close security gaps.
- Document architecture decisions, runbooks, and lessons learned.
- Contribute to security policies, standards, and compliance initiatives (ISO 27001, etc.) incollaboration with the GRC team.





