DevOps Engineer
guidewire · India - Bangalore · On-site
Posted Sep 23, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Summary
Guidewire is seeking a hands-on DevOps Engineer and Security Champion to join our Professional Services AI Engineering team in Bangalore. You will be the single owner of security implementation across our internal AI Engineering platform and the AI productization projects it supports. This is an execution-focused security role with real input into security strategy. You partner with Product to shape security guidance and own its correct implementation across our infrastructure, applications, and developer workflows — knowing when a decision belongs at the policy level and escalating it accordingly. You will pair closely with the Platform Architect and Strike Team developers to bake security into every layer of the system.
Job Description
Key Responsibilities
• Authentication: Stand up and operate authentication flows across all Strike Team projects — JWT, AWS Cognito, SSO integrations, and machine-to-machine auth patterns.
• Authorization & Access Controls: Implement role-based and attribute-based access control patterns. Maintain a reusable authorization library that Strike Teams consume rather than rebuild.
• Compliance Implementation: Translate compliance requirements (SOC 2, regional data privacy, customer-driven controls) into concrete technical controls — encryption, key management, audit logging, data residency.
• IP & Network Controls: Implement IP restrictions, VPC-level network segmentation, and traffic policies that protect customer data without blocking legitimate Strike Team workflows.
• Security Patterns Library: Build and maintain a library of vetted security components (auth middleware, secret management helpers, audit log clients) that every Strike Team uses by default.
• Security Reviews & Audit Support: Review Strike Team designs for security gaps, support customer audits, and partner with the QA Architect on security-focused testing standards.
KPIs & Success Metrics
• Security controls implemented across all Strike Team projects (auth, authz, encryption, audit logging) with no critical gaps.
• Reusable security library adoption — share of teams consuming vetted components rather than rebuilding.
• Compliance readiness: SOC 2 and data-privacy controls in place; successful customer audit support.
• Time-to-remediate security findings within SLA.
• Zero preventable authentication or access-control incidents.
Key Skills & Experience
• Education: Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or a related technical field.
• Experience: 8+ years of software engineering experience with a strong focus on security implementation — auth systems, compliance controls, or platform security.
• Technical Proficiency:
– Expert-level knowledge of authentication and authorization patterns (OAuth 2.0, OIDC, JWT, SAML).
– Hands-on experience with AWS Cognito, IAM, KMS, and Secrets Manager.
– Strong backend development skills (Python, Java, or TypeScript) — this is a…