Senior DevSecOps Engineer
Kantar · Hyderabad, International Tech Park
Kantar · Hyderabad, International Tech Park
We go beyond the obvious, using intelligence, passion and creativity to inspire new thinking and shape the world we live in. To start a career that is out of the ordinary, please apply... Job Details Job Description- Data Engineer Kantar is the world’s leading AI-native marketing data and analytics business and an indispensable brand partner to the world’s top companies. We combine the most meaningful attitudinal and behavioural data with deep expertise and advanced analytics to uncover how people think and act. We help clients understand what has happened and why and how to shape the marketing strategies that shape their future. In recent years, the market research industry has faced increasing threats from online fraud, particularly in incentivised markets. Fraudsters attempt to exploit survey systems for financial gain, and their tactics are constantly evolving. At Kantar, we are committed to staying ahead of these threats by investing in advanced data science solutions and fraud detection technologies. This is a high-impact role with the opportunity to collaborate directly with Operational, Commercial, and Data Science teams. You’ll be part of a talented team of analysts, scientists, engineers, and developers, working on mission-critical systems that support our global research operations. What You’ll Do You will own and evolve the security posture of our cloud-native data platform, with a particular focus on protecting data in containerised Python services running on AWS. Partnering closely with Data Engineering and Data Science, you’ll enable secure-by-default delivery of DevOps, DataOps, MLOps and AIOps workloads—building guardrails, automation and observability that scale. You’ll also help shape a medium-term path to support Azure, ensuring security controls, IaC patterns and CI/CD pipelines are portable across clouds. • Design and implement security controls for containerised Python applications across build, deploy and runtime (image hardening, least privilege, network policies, secrets management, vulnerability management). • Embed security into CI/CD by building automated checks (SAST, dependency scanning, IaC scanning, container scanning) and enforcing policy-as-code with pragmatic developer workflows. • Secure our AWS footprint using Infrastructure as Code: IAM design, account/environment separation, encryption standards, private networking, and service control guardrails. • Own database security across our data stores (e.g., Postgres/Redshift): access models, row/column-level controls where applicable, encryption, key management, auditing, patching and backup/restore security. • Implement end-to-end data protection controls: encryption in transit/at rest, data classification, tokenisation/masking where needed, and secure data sharing patterns for analytics and ML. • Build security observability: centralised logging, security monitoring and alerting, and incident runbooks for cloud, containers and data platforms—reducing mean time to detect and remediate. • Enable secure MLOps/DataOps practices: protect model artefacts and feature/data pipelines, support secure compute for training/inference, and guide teams on secure coding and threat modelling. • Create practical security standards and documentation, mentor engineers, and partner with stakeholders to balance risk, delivery speed and operational reliability. • Build cloud-agnostic security patterns to support a potential move to Azure (e.g., mapping IAM to Entra ID, KMS to Key Vault, container services to AKS, and ensuring IaC/pipelines are portable). What You’ll Bring • Significant experience in DevSecOps/SRE/Platform Engineering roles, taking ownership of security outcomes for cloud-native systems in production. • Strong hands-on AWS experience (and an interest/ability to extend controls to Azure over time), including identity, networking, encryption and logging primitives. • Deep knowledge of containers and orchestration (Docker; Kubernetes/EKS or ECS), including secure configuration, runtime hardening and network isolation. • Proficiency with Infrastructure as Code (e.g., Terraform/CloudFormation) and CI/CD, with practical experience implementing policy-as-code and security automation. • Strong Python skills and familiarity with secure software engineering practices for backend services (dependency hygiene, secure configurations, secrets handling). • Strong SQL fundamentals and proven experience securing relational databases (e.g., Postgres)