Photon Logo

Photon

Policy as Code Engineer / Testers - Bangalore, India - JPMC

Posted 3 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in India
Entry level
Remote
Hiring Remotely in India
Entry level
Develop, test, and maintain Rego policies for OPA to enforce security and compliance across GCP resources. Integrate policy tests into CI/CD, collaborate with DevOps/security teams, automate validation of cloud infrastructure, document best practices, and continuously improve policy-as-code processes.
The summary above was generated by AI

Key Responsibilities:

Policy as Code Development & Testing:

  • Design, implement, and maintain Rego policies for cloud resources, ensuring that security, compliance, and operational policies are enforced.
  • Write and maintain unit, integration, and acceptance tests for policy as code to ensure that policies are correctly applied in different environments.
  • Collaborate with security teams to define and translate security and compliance requirements into actionable Rego policies.

Cloud Infrastructure Policy Management:

  • Ensure that GCP cloud resources (e.g., Compute Engine, Kubernetes, Cloud Storage, IAM, BigQuery, etc.) are configured according to company policies and regulatory requirements.
  • Automate policy enforcement and validation for cloud resources using OPA and other policy enforcement tools.

Automation & CI/CD Integration:

  • Integrate Rego policy tests and enforcement into CI/CD pipelines to ensure that policies are tested and applied consistently across environments.
  • Work with DevOps teams to automate policy validation as part of the deployment and provisioning workflows.

Collaboration & Documentation:

  • Collaborate with cross-functional teams (DevOps, Security, Compliance) to ensure that the policies meet business, security, and regulatory requirements.
  • Create and maintain documentation for policies, tests, and guidelines for policy-as-code best practices.

Continuous Improvement:

  • Stay up-to-date with the latest trends, tools, and best practices in cloud security, policy-as-code, and GCP services.
  • Identify opportunities to improve policy automation and testing processes for cloud environments.

Skills & Qualifications:

Required:

Strong Experience with Rego / OPA:

  • Hands-on experience writing policies using Rego for Open Policy Agent (OPA) to enforce cloud security and operational best practices.

Deep Knowledge of Google Cloud Platform (GCP):

  • Extensive experience with GCP services such as IAM, Compute Engine, Kubernetes Engine, Cloud Storage, BigQuery, VPC, Cloud Functions, and more.
  • Understanding of GCP-specific security controls, best practices, and compliance frameworks (e.g., CIS benchmarks, SOC 2, HIPAA, etc.).

Cloud Security & Compliance:

  • Experience working with cloud security frameworks and tools, including infrastructure as code (IaC) principles.
  • Knowledge of security and compliance requirements for cloud-based environments (e.g., GDPR, SOC 2, PCI-DSS).

Automated Testing & CI/CD:

  • Proficiency in test-driven development (TDD) and automated testing frameworks.
  • Familiarity with CI/CD tools (e.g., Jenkins, GitLab CI, CircleCI, GitHub Actions) for automating policy testing and enforcement.

Programming / Scripting Skills:

  • Proficiency in at least one programming or scripting language, such as Python, Go, Shell, or JavaScript.

Version Control & Collaboration Tools:

  • Experience with version control systems, particularly Git, and collaborating on code repositories (e.g., GitHub, GitLab).

Preferred:

  • Experience with Other Policy Engines:
    • Familiarity with other policy engines like Kubernetes admission controllers, Sentinel, or KubernetesOPA is a plus.
  • Cloud Security Tools & Practices:
    • Hands-on experience with cloud security posture management (CSPM) tools, vulnerability scanning, and incident response.
  • Certifications:
    • Google Cloud Certified - Professional Cloud Security Engineer or equivalent is a plus.
    • OPA or other security certifications are a plus.

Similar Jobs

An Hour Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Manage US sales and use tax compliance across jurisdictions, including preparing and filing returns, tax data extraction and reconciliations, month-end accruals and GL reconciliations, supporting state and local tax audits, improving tax processes and automation, and partnering with Tax, Accounting, IT, and business teams on tax treatment and reporting.
Top Skills: AlteryxAvalaraClaudeExcelOnesourceOraclePower BISAPVertex
10 Hours Ago
Remote or Hybrid
India
Expert/Leader
Expert/Leader
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
The role involves managing finance change, regulatory reporting, project management, and software testing, requiring extensive experience in financial services and team leadership.
Top Skills: Automation Testing ToolsExcelSQL
10 Hours Ago
Remote or Hybrid
India
Senior level
Senior level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Manage projects in the transaction banking sector with an emphasis on compliance and retail payments, using Agile methodologies and strong stakeholder management.
Top Skills: ConfluenceIso20022JIRA

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account