Full-Time

Senior AWS DevSecOps Engineer / Testers

Policy Development & Mapping

Photon

Photon

Global AI and digital solutions provider

No salary listed

India

In Person

Category
DevOps & Infrastructure (1)
Requirements
  • 5+ years of experience in AWS cloud environments with a focus on security, DevSecOps, and automation
  • At least 3+ years of hands-on experience in security policy development and mapping for cloud infrastructure, specifically AWS
  • Deep knowledge of AWS security tools and services, including AWS Identity and Access Management, AWS Key Management Service, AWS Config, AWS GuardDuty, AWS Shield, AWS Web Application Firewall, and others
  • Strong experience with infrastructure-as-code tools such as Terraform, AWS CloudFormation, and AWS Cloud Development Kit
  • Experience with security testing tools (e.g., static and dynamic analysis, penetration testing, vulnerability scanning) and frameworks
  • Hands-on experience with CI/CD pipeline security integration, GitOps, and container security (e.g., Docker, Kubernetes, EKS)
  • Proficiency in programming/scripting languages such as Python, Bash, or Go
  • Experience with AWS Security Hub, AWS Inspector, AWS Trusted Advisor, and other AWS security services
  • Familiarity with security testing frameworks (e.g., OWASP, SANS, NIST) and cloud security best practices
  • Experience with integrating security tools into CI/CD pipelines (e.g., Jenkins, GitLab, CircleCI, etc.)
  • Strong knowledge of common security vulnerabilities (e.g., OWASP Top 10, CVE management) and how to mitigate them in cloud environments
Responsibilities
  • Design, develop, and maintain security policies for AWS environments, ensuring compliance with industry standards (e.g., NIST, CIS, ISO 27001)
  • Map and integrate security policies into infrastructure and applications deployed on AWS using Infrastructure as Code tools such as Terraform, CloudFormation, and AWS Cloud Development Kit
  • Create automated processes for security policy enforcement, auditing, and monitoring
  • Develop security rules and guardrails using AWS native services (AWS Config, AWS Security Hub, AWS GuardDuty, etc.) and third-party security tools
  • Build and maintain the CI/CD pipeline with embedded security testing (SAST, DAST, IAST) and automated compliance checks
  • Automate security vulnerability assessments and remediation in the AWS environment using tools like AWS Inspector, Qualys, and other static and dynamic analysis tools
  • Collaborate with development teams to implement security in the software development lifecycle (SDLC), shifting security left and automating security testing
  • Create and maintain AWS security best practices, security controls, and infrastructure standards
  • Conduct manual and automated penetration testing, vulnerability assessments, and code reviews focused on AWS-based applications and infrastructure
  • Implement automated testing frameworks that validate security policies and configurations (e.g., infrastructure misconfigurations, exposed secrets)
  • Identify security gaps or vulnerabilities in AWS deployments and work with DevOps and development teams to remediate
  • Continuously assess new threats, vulnerabilities, and attack vectors in AWS environments
  • Work closely with DevOps, Development, and IT teams to ensure proper integration of security into cloud infrastructure and applications
  • Provide regular security assessments, risk analysis reports, and security findings to senior leadership and relevant stakeholders
  • Participate in incident response planning and execution, providing expertise in security issues related to AWS environments
  • Train development teams on secure coding practices, security testing tools, and best practices for AWS security
  • Stay current with emerging trends in DevSecOps, cloud security, and AWS services
  • Continuously improve security policies, tools, and processes to adapt to evolving threats
  • Contribute to the creation and implementation of security automation frameworks for improved DevSecOps practices
Desired Qualifications
  • AWS Certified Security – Specialty
  • Certified DevSecOps Professional (CDP) or other related certifications
  • CISSP, CISM, or equivalent security certifications are a plus
  • Experience with container security tools like Aqua Security, Twistlock, or Falco
  • Hands-on experience with serverless architectures and security concerns in AWS Lambda, API Gateway, and other serverless services
  • Familiarity with cloud-native security architectures and concepts (e.g., Zero Trust, defense in depth)
  • Experience with compliance frameworks and regulations (e.g., GDPR, HIPAA, SOC 2, PCI DSS)

Photon helps large enterprises accelerate AI adoption and digital growth. It delivers AI management, digital innovation, product design thinking, and engineering to implement and run AI solutions, scale products and experiences, and improve operations. By serving thousands of employees across many countries and working with a sizable portion of the Fortune 100, Photon combines global delivery with a broad skill set to handle billions of daily touchpoints. Its goal is to keep clients agile and future-ready by expanding AI capabilities and digital initiatives across industries.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

London, United Kingdom

Founded

N/A

Simplify Jobs

Simplify's Take

What believers are saying

  • Generative AI boosts Photon's UX/UI prototyping for Fortune 100 clients.
  • Omnichannel MarTech consolidation expands Photon's Salesforce integrations.
  • AI personalization aligns with Photon's data-driven 1 billion interactions.

What critics are saying

  • Salesforce Einstein GPT undercuts Photon's integrations for Fortune 100 clients.
  • Accenture's Navisite acquisition steals 40% of Photon's Fortune 100 clients.
  • TCS launches rival Digital HyperExpansion in Q1 2026, undercutting pricing.

What makes Photon unique

  • Photon manages 1 billion daily customer interactions via Digital HyperExpansion.
  • Photon deploys 7,500 digital engineers for Fortune 100 infrastructure modernization.
  • Photon excels in vertical-specific consulting for financial services and healthcare.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Paid Vacation

Paid Holidays

Performance Bonus

Company News

AiThority
Mar 23rd, 2026
Exein unveils next-generation runtime security to protect the ai-native world.

Exein unveils next-generation runtime security to protect the ai-native world. * Photon blocks cyberattacks before execution across physical AI and IoT, autonomous AI agents and cloud and edge infrastructure * Kernel-level prevention sets a new standard beyond traditional user-space detection * Builds on Exein's position as the world's largest runtime security provider, protecting over two billion devices Mar 23, 2026 Prev Next 1 of 42,872 Exein, the global leader in runtime cybersecurity, unveiled Photon, a preemptive breakthrough solution that blocks cyberattacks at the point of execution. Designed for the AI-native world - where digital and physical systems are now inseparable - Photon marks a fundamental shift in how critical infrastructure protects itself. Unlike traditional cybersecurity solutions that detect threats after compromise - typically operating in user space and relying on a cloud network - Exein's Photon operates directly inside the kernel, preventing malicious execution paths before they can run. By blocking attacks before the point of execution, the technology dramatically reduces latency and eliminates entire classes of threats before damage occurs. If malicious instructions cannot execute, the attack itself cannot take place. This advancement establishes a new category of runtime security designed for systems that cannot be disconnected: physical AI and IoT environments, autonomous AI agents, and local hybrid cloud and edge infrastructure. In these environments, from industrial robotics and critical infrastructure to AI-driven platforms, downtime is not an option, and protection must be more precise and granular, blocking malicious threats without shutting down the entire process. The announcement at the RSA Conference (RSAC) comes as cyber threats increasingly target physical systems. Last month, the Munich Security Report 2026 warned that cyber operations are now engineered to cause real-world disruption, accelerating regulatory intervention after voluntary measures failed to address systemic vulnerabilities. At the same time, the speed of attacks is accelerating dramatically: recent threat intelligence shows average attacker 'breakout times' fell to just 29 minutes in 2025, 65% faster than the previous year, driven in part by AI-assisted automation. Protecting the digital and physical in the AI era Artificial intelligence is already capable of identifying vulnerabilities in software and infrastructure. In the near future, these models will not only detect weaknesses but exploit them autonomously to launch attacks at machine speed. As the scale and sophistication of these attacks grow, traditional runtime security systems that rely on detection alone will no longer be sufficient. Photon introduces a new model of preemptive runtime security designed for this AI-driven environment. Rather than detecting attacks after they begin, it prevents malicious execution paths from running in the first place, blocking threats in real time before they can impact the system. Unlike conventional security tools that operate in user space alongside the applications they protect, Photon operates directly within the kernel, the core of the operating system. By enforcing protection at this foundational layer, rather than merely detecting and stopping attacks, it prevents them from executing in the first place - all in real time. This marks a major milestone as physical and digital systems converge, positioning Photon as a new reference architecture for securing physical AI, agent AI and cloud and hybrid infrastructure. Gianni Cuozzo, Founder and CEO of Exein, said: "In a future where the world is infinitely connected with humanoid robots walking among Aithority, local LLMs powering intelligent edges, autonomous drones reshaping mobility, and billions of new autonomous systems bridging the digital and physical realms, preemptive runtime security represents the new generation of protection, built into the very DNA of every device from the ground up. "Exein was born to make this vision a reality: transforming every connected device into a fortress of security, forging the largest decentralised immune system for digital life - cross-vendor, cross-platform, and cross-system. We stand as the first line of defence between the boundless digital world and the physical one we live in, empowering manufacturers to build inherently safe innovations and already safeguarding over 2 billion devices worldwide."