Architect - DevOps 4D
Ready to turn bold ideas into real-world impact?
At Genpact, we don’t just adapt to change, we lead it. AI and digital innovation are transforming the way businesses work, and we’re at the forefront of it. Genpact’s AI Gigafactory, our industry-first accelerator, exemplifies how we scale advanced technology solutions to help global enterprises work smarter, grow faster, and transform at scale. Whether tackling complex challenges through large-scale models or agentic AI, our breakthrough solutions tackle companies’ most complex challenges.
If you thrive in a fast-moving, innovation-driven environment, love building and deploying cutting-edge AI solutions, and want to push the boundaries of what’s possible, this is your moment.
Genpact (NYSE: G) is an agentic and advanced technology solutions company. We leverage process intelligence and artificial intelligence to deliver measurable outcomes. With a strong partner ecosystem and decades of client trust, we provide innovative solutions that transform how businesses run. Powered by a team with an active learning mindset and client centricity at its core, we deliver lasting value for the world’s leading enterprises.
Get to know us at genpact.com and on LinkedIn, YouTube, X, and Facebook.
Job Description
Key Responsibilities
Application Code Security (Primary Accountability)
- Design, implement, and enforce the mandatory SAST (Static Application Security Testing) scanning pipeline for all NH2030 code before Databricks deployment
- Configure GitHub Advanced Security (or equivalent) for the NH2030 GitHub repositories: code scanning, secret scanning, and dependency review
- Define and enforce the code review process including OWASP Top 10 compliance checks for all application code
- Own the security gate in the CI/CD pipeline: no deployment proceeds without a passing security scan
- Triage and remediate security findings from SAST scans; track findings to closure in the security register
- Conduct periodic security reviews of notebooks, Python/PySpark scripts, and DLT pipeline code for common vulnerabilities
Library & Dependency Management
- Establish and maintain the approved library list for NH2030 workloads on both classic and serverless Databricks compute
- Implement dependency pinning across all NH2030 project requirements files (requirements.txt, pyproject.toml, etc.) to prevent supply chain attacks
- Run regular vulnerability scans on all library dependencies using tools such as Dependabot, Snyk, or Safety
- Coordinate with ADP Platform Team to request library and init script whitelisting for classic compute
- Ideally establish and maintain an internal Nexus/Artifactory proxy repository stocked with pre-vetted, trusted libraries for NH2030 teams
- For serverless compute: since no centralised restriction is possible, own full end-to-end responsibility for dependency vetting, pinning, and vulnerability management
- Review and approve all init script and JAR file whitelisting requests before submission to ADP team
GitHub Repository Security & Connectivity
- Identify all GitHub repositories required by the NH2030 programme for Databricks Git integration
- Submit and manage workspace-level GitHub repository whitelisting configuration (ADP default: no repos whitelisted)
- Configure branch protection rules, required review policies, and CODEOWNERS on NH2030 repositories
- Monitor repository access and audit logs for unauthorised access or anomalous activity
FQDN Whitelisting & Egress Security
- Identify and document all external FQDNs required by NH2030 serverless and classic compute workloads
- Prepare and submit FQDN whitelisting requests via ServiceNow: classic compute to FCP Azure Firewall, serverless compute to ADP network policies
- Validate that whitelisted FQDNs are the minimum required (least-privilege egress principle)
- Review FQDN requests from development teams to ensure they are justified and do not introduce risk
- Monitor for unauthorised egress attempts in ACDC SIEM logs and Dynatrace dashboards
Workspace Security Configuration
- Verify and document that DBFS and Hive Metastore are disabled in the NH2030 Dev workspace (mandatory ADP control)
- Review and tighten data exfiltration prevention controls: restrict file export, notebook download, clipboard access, and MLflow artifact export per NH2030 data classification requirements
- Validate that ADP-provisioned default restrictions are active and configure additional controls as required by NH2030 data sensitivity
- Review cluster policy configurations to ensure they enforce secure compute settings
BYOS Storage Security (in coordination with Azure Cloud Engineer)
- Define BYOS security requirements based on NH2030 data classification: Defender enablement, CMK scope, WORM requirements, SAS token policy
- Review and sign off on BYOS security control configurations implemented by the Azure Cloud Engineer
- Ensure Malware Scanning is active on all BYOS storage accounts and define the alert response procedure
- Validate container-level ACLs and access policies against the principle of least privilege
SIEM & Security Monitoring
- Define and document the Genpact incident response process for ACDC SIEM security alerts received for the NH2030 Dev workspace
- Monitor ACDC/Google SecOps dashboards for NH2030 workspace security events; triage and respond to alerts within agreed SLA
- Contribute to security alert definition and log forwarding configuration with ADP Platform Team
- Set up SQL Alerts in Databricks for access anomaly detection and unusual query patterns
Security Readiness & Compliance
- Lead the Security & Compliance Readiness Review (P10-04) prior to Dev environment sign-off
- Maintain a security configuration checklist covering all OE security obligations under the Platform Security Shared Responsibility Model
- Conduct periodic security posture reviews throughout the development phase
- Provide security guidance to NH2030 developers on secure coding practices for Databricks
- Escalate unresolved security findings to NH2030 Programme Governance and ADP Platform Team as required
ADP-Specific Activities (from Platform Security Shared Responsibility Model)
Primary Security Activities
Governance & Review Activities
- SAST code scanning pipeline (mandatory pre-deployment) – P5-04
- Library & package security – dependency pinning, vulnerability scanning – P5-03
- GitHub repo whitelisting in workspace – P5-01
- FQDN whitelisting request preparation – P5-02
- BYOS security controls sign-off (Defender, CMK, WORM, SAS) – P5-07
- Exfiltration prevention controls – export/download/clipboard restrictions – P5-06
- DBFS / Hive Metastore lockdown verification – P5-05
- ACDC SIEM alert response process definition – P7-04
- Security & Compliance Readiness Review (pre-Dev sign-off) – P10-04
- Application code security ownership (OWASP Top 10) – per SRM
- App dependency management for Databricks Apps – per SRM
- CI/CD security gate (SAST in pipeline) – P9-03
Required Skills & Experience
Core Security Skills
Supporting Skills
- 3+ years DevSecOps or application security engineering in cloud environments
- SAST tooling: GitHub Advanced Security, SonarQube, Semgrep, or equivalent
- OWASP Top 10: understanding and practical remediation in Python/PySpark contexts
- Dependency management: pip, poetry, Dependabot, Snyk, Safety, or equivalent
- GitHub repository security: branch protection, CODEOWNERS, secret scanning
- Azure Defender for Storage, Microsoft Defender for Cloud
- SIEM platforms: Google SecOps (ACDC), Splunk, or equivalent
- Supply chain security: package pinning, Nexus/Artifactory proxy repository management
- Databricks security model: workspace admin controls, DBFS/Hive lockdown, exfiltration prevention
- Azure networking security: FQDN whitelisting, Azure Firewall, NSG
- CMK and Key Vault security for storage encryption
- CI/CD pipeline integration (GitHub Actions / Azure DevOps) for security gates
- Data classification and tagging principles for regulated data environments
- Incident response process design and runbook development
- Experience in financial services or insurance sector security requirements (advantageous)
- Familiarity with Allianz ARS framework / Wiz CSPM (advantageous)
Certifications
- GitHub Advanced Security Certification (required)
- SC-100 Microsoft Cybersecurity Architect or SC-200 Security Operations Analyst (desirable)
- CEH (Certified Ethical Hacker) or equivalent offensive security certification (desirable)
- CISSP or CISM (desirable for senior candidate)
- Databricks workspace security knowledge (no dedicated cert – demonstrated experience)
Key Interfaces
- Lead Databricks Platform Engineer: Cluster policy security settings, DBFS/Hive lockdown verification, workspace exfiltration controls, Git integration security
- Azure Cloud Engineer: BYOS security controls alignment, CMK and Defender configuration sign-off, FQDN whitelisting coordination
- ADP Platform Team (AzTech): Library allowlisting requests, FQDN whitelisting submission, ACDC SIEM log forwarding configuration
- ACDC / Allianz Security Team: SIEM alert triage and escalation, security incident response
- All NH2030 Developers: Code review guidance, secure coding standards, SAST scan remediation support
- NH2030 Programme Governance: Security compliance reporting, readiness review sign-off
Qualifications
Bachelors - Computer Engineering, Bachelors - Computer Science, Bachelors - Information Technology, Masters - Computer ScienceCertifications
Certified Kubernetes Administrator (CKA) - CNCF (Cloud Native Computing Foundation)CNCF (Cloud Native Computing Foundation), HashiCorp Certified Terraform Associate - UdemyUdemyRequired Skills
Agile Methodology, Agile Methodology, Artifactory, Atlassian, Atlassian Bamboo, Azure Devops, Change Management, Chef (Software), Client Relations, Cloud Automation, Collaboration Tools, Design Thinking, DevOps, DevOps Coaching, DevOps Process Flow, DevSecOps, Docker (Software), ERP Software Selection, Executive Presence, GitHub, GitLab, Implementation Support, Inclusion, Information Technology Consulting, Infrastructure as a Service (IaaS) {+ 19 more}Language
English (Required), English (Required)Language Proficiency -
Advanced - C1Additional Job Location -
Job Type
RegularMaster Skill List -
DevOpsRemote Type -
HybridWork Shift -
Flex Time (India)Why join Genpact?
• Lead AI-powered transformation – Drive innovation and solve real-world business challenges that matter
• Make an impact – Help global enterprises solve business challenges that matter
• Accelerate your career – Gain hands-on experience, mentorship, and world-class learning opportunities to stay ahead
• Work with the best – Join 140,000+ bold thinkers and problem-solvers who push boundaries every day
• Thrive in a values-driven culture – Our courage, curiosity, and incisiveness - built on a foundation of integrity and inclusion - allow your ideas to fuel progress
Come join the 140,000+ coders, tech shapers, and growth makers at Genpact and take your career in the only direction that matters: Up.
Let’s build tomorrow together.
Genpact is an Equal Opportunity Employer and considers applicants for all positions without regard to race, color, religion or belief, sex, age, national origin, citizenship status, marital status, military/veteran status, genetic information, sexual orientation, gender identity, physical or mental disability or any other characteristic protected by applicable laws. Genpact is committed to creating a dynamic work environment that values respect and integrity, customer focus, and innovation.
Furthermore, please do note that Genpact does not charge fees to process job applications and applicants are not required to pay to participate in our hiring process in any other way. Examples of such scams include purchasing a 'starter kit,' paying to apply, or purchasing equipment or training.