Design Engineer Professional
Outer Ring Road, Bellandur, Bengaluru, India
Recruiter: Sowmya Tipgond
Hiring Manager: Sreeraj Sivadasan Pathiyan
Location - Bangalore
Mode - Hybrid
Why BT
We’ve always been an organisation with a purpose; to use the power of communication to make a better world. You can trace this back to our beginning as pioneers of the world’s firs telecommunications company. At our heart we’re a technology company with research and innovation in our bones and a desire to be personal, simple, and brilliant for our customers - those are the values we live by whilst also creating an inclusive working environment where people from all backgrounds can succeed. Our pursuit of progress over the past 180 years has established BT as a strong, successful brand, with huge scale capable of achieving great things. From supporting emergency services, hospitals, banks and keeping economies around the world online, safe and secure, to delivering large scale technology infrastructure like the creation of BT Sport.
Today in this fast-changing, always on, digital world our purpose remains true. Yet the market conditions, regulations and competition we face are tougher than ever before. So, if you have the drive, optimism and resilience to help propel us forward we’ll offer unrivalled personal development, a wealth of opportunities to learn, experience new things and pursue new careers. If that’s you and what you’re looking for, we’d love you to be part of our future.
Role Responsibilites
Conduct security assessments at the application, container, and infrastructure levels.
• Implement and manage Kubernetes security practices, including RBAC, network policies, and audit logging.
• Secure Kafka topics by configuring ACLs, monitoring access patterns, and ensuring data encryption.
• Implement database security measures for Postgres and Neo4J DB, including encryption, access controls, and auditing.
• Secure the private cloud environment, ensuring compliance with security best practices and implementing appropriate controls.
• Integrate security tools into our CI/CD pipeline using Jenkins, Spinnaker, and GitLab CI/CD.
• Perform image scanning and signing to ensure the security of container images using tools like Trivy, Clair, and Aqua Security.
• Monitor and log security events using tools such as Prometheus, Grafana, Fluentd, Elasticsearch, and Kibana.
• Implement runtime security measures and respond to incidents using tools like Falco and Sysdig.
• Ensure compliance with industry standards and regulations (e.g., GDPR, HIPAA, SOC 2).
• Manage secrets and encryption for sensitive data using HashiCorp Vault and Kubernetes Secrets.
• Collaborate with the cloud infrastructure team to enforce security best practices on AWS, Azure, GCP, and the private cloud.
• Use Infrastructure as Code (IaC) tools like Terraform and CloudFormation to maintain secure infrastructure configurations.
• Implement and enforce security policies using Open Policy Agent (OPA) and Gatekeeper.
•
Key Tools and Technologies
Kubernetes Security: RBAC, Network Policies, Pod Security Policies (PSP), Kubernetes Audit Logging
• Kafka Security: ACLs, TLS Encryption, SASL Authentication
• Database Security: Postgres, Neo4J DB, Encryption, Access Controls, Auditing
• Private Cloud Security: Secure configuration, Access Controls, Compliance
• Container Security: containerd, Trivy, Clair, Aqua Security
• CI/CD Tools: Jenkins, Spinnaker, GitLab CI/CD
• Monitoring and Logging: Prometheus, Grafana, Fluentd, Elasticsearch, Kibana
• Runtime Security: Falco, Sysdig
• Cloud Security: AWS, Azure, GCP, Private Cloud
• Infrastructure as Code: Terraform, CloudFormation
• Secrets Management: HashiCorp Vault, Kubernetes Secrets
• Policy as Code: Open Policy Agent (OPA), Gatekeeper
• Image Security:
o Static Application Security Testing (SAST) Tools: SonarQube, Snyk, Fortify
o Dependency Scanning: Snyk, OWASP Dependency-Check, Whitesource
o Image Scanning Tools: Trivy, Clair, Aqua Security, Twistlock
o Image Signing: Docker Content Trust, Notary
• Vulnerability and Patch Management: Qualys or similar tools
Qualification
- Proven experience in security roles, particularly with Kubernetes, Kafka, database security (Postgres, Neo4J DB), and private cloud environments.
- Strong understanding of DevSecOps practices and tools.
- Familiarity with cloud security and infrastructure as code.
- Excellent problem-solving skills and attention to detail.
- Ability to work collaboratively in a fast-paced, dynamic environment.
Our leadership standards
Looking in:
Leading inclusively and Safely
I inspire and build trust through self-awareness, honesty and integrity.
Owning outcomes
I take the right decisions that benefit the broader organisation.
Looking out:
Delivering for the customer
I execute brilliantly on clear priorities that add value to our customers and the wider business.
Commercially savvy
I demonstrate strong commercial focus, bringing an external perspective to decision-making.
Looking to the future:
Growth mindset
I experiment and identify opportunities for growth for both myself and the organisation.
Building for the future
I build diverse future-ready teams where all individuals can be at their best.
Who is the BT Group
We're the leading communications provider with customers in 180 countries. Across the world we enable customer's digital transformations so they can thrive. Our focus is simple: be the global provider-of-choice for managed network and IT infrastructure services.