Back to search results
Senior DevSecOps Engineer
Location: Hyderabad, International Tech Park
Posted: More than 30 days ago
Job Type: Regular
Ref: R101529
Three Indian colleagues are working together. From left to right. A man with a short brown beard is smiling across at two female colleagues. He is wearing a white shirt. In the middle, a female colleague is working at a silver laptop and has dark hair to just past her shoulders. She is wearing a blue shirt. Finally there is a second woman making notes in her notebook. She is wearing a white patterned scarf and blue and red patterned elbow length top. Her hair is in a braid.

Job Description- Data Engineer

Kantar is the world’s leading AI-native marketing data and analytics business and an indispensable brand partner to the world’s top companies. We combine the most meaningful attitudinal and behavioural data with deep expertise and advanced analytics to uncover how people think and act. We help clients understand what has happened and why and how to shape the marketing strategies that shape their future. 

In recent years, the market research industry has faced increasing threats from online fraud, particularly in incentivised markets. Fraudsters attempt to exploit survey systems for financial gain, and their tactics are constantly evolving. At Kantar, we are committed to staying ahead of these threats by investing in advanced data science solutions and fraud detection technologies. 

This is a high-impact role with the opportunity to collaborate directly with Operational, Commercial, and Data Science teams. You’ll be part of a talented team of analysts, scientists, engineers, and developers, working on mission-critical systems that support our global research operations.

What You’ll Do 

You will own and evolve the security posture of our cloud-native data platform, with a particular focus on protecting data in containerised Python services running on AWS. Partnering closely with Data Engineering and Data Science, you’ll enable secure-by-default delivery of DevOps, DataOps, MLOps and AIOps workloads—building guardrails, automation and observability that scale. You’ll also help shape a medium-term path to support Azure, ensuring security controls, IaC patterns and CI/CD pipelines are portable across clouds.

  • Design and implement security controls for containerised Python applications across build, deploy and runtime (image hardening, least privilege, network policies, secrets management, vulnerability management).
  • Embed security into CI/CD by building automated checks (SAST, dependency scanning, IaC scanning, container scanning) and enforcing policy-as-code with pragmatic developer workflows.
  • Secure our AWS footprint using Infrastructure as Code: IAM design, account/environment separation, encryption standards, private networking, and service control guardrails.
  • Own database security across our data stores (e.g., Postgres/Redshift): access models, row/column-level controls where applicable, encryption, key management, auditing, patching and backup/restore security.
  • Implement end-to-end data protection controls: encryption in transit/at rest, data classification, tokenisation/masking where needed, and secure data sharing patterns for analytics and ML.
  • Build security observability: centralised logging, security monitoring and alerting, and incident runbooks for cloud, containers and data platforms—reducing mean time to detect and remediate.
  • Enable secure MLOps/DataOps practices: protect model artefacts and feature/data pipelines, support secure compute for training/inference, and guide teams on secure coding and threat modelling.
  • Create practical security standards and documentation, mentor engineers, and partner with stakeholders to balance risk, delivery speed and operational reliability.
  • Build cloud-agnostic security patterns to support a potential move to Azure (e.g., mapping IAM to Entra ID, KMS to Key Vault, container services to AKS, and ensuring IaC/pipelines are portable).

What You’ll Bring 

  • Significant experience in DevSecOps/SRE/Platform Engineering roles, taking ownership of security outcomes for cloud-native systems in production.
  • Strong hands-on AWS experience (and an interest/ability to extend controls to Azure over time), including identity, networking, encryption and logging primitives.
  • Deep knowledge of containers and orchestration (Docker; Kubernetes/EKS or ECS), including secure configuration, runtime hardening and network isolation.
  • Proficiency with Infrastructure as Code (e.g., Terraform/CloudFormation) and CI/CD, with practical experience implementing policy-as-code and security automation.
  • Strong Python skills and familiarity with secure software engineering practices for backend services (dependency hygiene, secure configurations, secrets handling).
  • Strong SQL fundamentals and proven experience securing relational databases (e.g., Postgres) and analytical warehouses (e.g., Redshift), including auditing and access control design.
  • Experience with secrets management and key management (e.g., AWS Secrets Manager/SSM, KMS; plus an understanding of Azure Key Vault), and designing rotation and break-glass processes.
  • Hands-on with security tooling and practices such as SAST, SCA, container vulnerability scanning, IaC scanning, and runtime detection—integrated into developer workflows.
  • Experience operating production platforms: monitoring/alerting, incident response, post-incident reviews, and designing for resilience while reducing security risk.
  • Working knowledge of data governance and security concepts (e.g., data classification, retention, privacy-by-design) and how to implement them in cloud-native architectures.
  • Strong problem-solving and systems-thinking skills, with the ability to assess risk, prioritise remediation, and deliver improvements iteratively.
  • Comfortable partnering with Data Engineering and Data Science teams, translating security requirements into pragmatic controls that don’t block delivery.
  • Strong documentation and communication skills; able to influence stakeholders and raise the security maturity of engineering teams.
  • Experience defining standards and mentoring others (security champion models, enablement sessions, and improving engineering self-service).
  • Bonus: experience securing data/ML platforms (SageMaker, Databricks, feature stores, model registries) and understanding of MLOps/AIOps operational patterns.

Our Tech Stack 

  • AWS (ECS/EKS, IAM, VPC, KMS, S3, CloudWatch/CloudTrail, Lambda, Redshift, SageMaker)
  • Azure (AKS in the medium term, Key Vault, Entra ID; Databricks where relevant)
  • Containers & orchestration (Docker, Kubernetes)
  • Databases (Postgres and cloud data stores/warehouses such as Redshift)
  • Infrastructure & delivery (Terraform/CloudFormation, CI/CD pipelines, Git-based workflows)
  • Security & observability (secrets management, vulnerability scanning, policy-as-code, central logging/monitoring)

Why Join Us? 

At Kantar, you’ll be part of a global leader in data, insights, and consulting. You’ll work on meaningful challenges, contribute to cutting-edge solutions, and help shape the future of market research. We offer a collaborative environment, opportunities for growth, and the chance to make a real impact.

Apply Now
Back to search results