< Back to search
Boomi • India

Principal Software Engineer – DevSecOps

< Back to search
top 3
scores:
90%

Location flexibility

86%

Hours flexibility

86%

Autonomy

Apply now

Job Description

About Boomi and What Makes Us Special

Are you ready to work at a fast-growing company where you can make a difference? Boomi aims to make the world a better place by connecting everyone to everything, anywhere. Our award-winning, intelligent integration and automation platform helps organizations power the future of business. At Boomi, you’ll work with world-class people and industry-leading technology. We hire trailblazers with an entrepreneurial spirit who can solve challenging problems, make a real impact, and want to be part of building something big. If this sounds like a good fit for you, check out boomi.com or visit our Boomi Careers page to learn more.

Role and Responsibilities

  • AWS Security and IAM:

    • Extensive experience in managing AWS IAM roles, policies, and permissions, ensuring adherence to the principle of least privilege.

    • Proficiency in utilizing AWS security services such as AWS Config, CloudTrail, GuardDuty, and Security Hub for continuous monitoring and compliance.

    • Hands-on experience with AWS Key Management Service (KMS) for encryption key management and data protection.

  • Azure Security and Identity Management:

    • Solid understanding of Azure Active Directory (AAD) for identity and access management across Azure resources.

    • Experience with Azure Role-Based Access Control (RBAC) to manage permissions and access to Azure services.

    • Familiarity with Azure Security Center and Azure Policy for assessing and improving the security posture of Azure environments.LinkedIn+3careers-buspatrol.icims.com+3SmartRecruiters+3

  • Infrastructure as Code (IaC) and Automation:

    • Proficient in developing and maintaining infrastructure using IaC tools such as Terraform, AWS CloudFormation, and Azure Resource Manager (ARM) templates.

    • Experience in automating security configurations and compliance checks across AWS and Azure environments.

    • Skilled in implementing and managing secrets management solutions like AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault.

  • CI/CD Pipeline Security Integration:

    • Expertise in integrating security controls and checks into CI/CD pipelines using tools like Jenkins, GitLab CI/CD, Azure DevOps, or AWS CodePipeline.

    • Experience in automating static and dynamic code analysis (SAST/DAST) to identify and remediate vulnerabilities early in the development lifecycle.

    • Familiarity with containerization and orchestration tools like Docker and Kubernetes, including implementing security best practices.

  • Monitoring and Incident Response:

    • Proficient in setting up and maintaining monitoring and alerting systems using AWS CloudWatch, Azure Monitor, and third-party SIEM tools.

    • Experience in developing incident response plans and conducting regular drills to ensure preparedness for security events.

    • Skilled in conducting root cause analysis and implementing corrective actions to prevent future incidents.

  • Compliance and Governance:

    • Thorough understanding of industry standards and frameworks such as ISO 27001, SOC 2, PCI DSS, and HIPAA.

    • Experience in maintaining documentation for security policies, procedures, and compliance audits.

    • Stay updated on emerging security threats and cloud security features to proactively address potential risks.

  • Vulnerability Management:

    • Hands-on experience with vulnerability assessment tools like Snyk, TruffleHog, and CrowdStrike CSPM to identify and remediate security issues.

    • Ability to prioritize and track remediation efforts to ensure timely resolution of vulnerabilities.

  • Collaboration and Training:

    • Proven ability to work closely with development, operations, and security teams to promote a culture of security and shared responsibility.

    • Experience in providing training and guidance on secure coding practices, cloud security, and DevSecOps methodologies.

Technical Must-Know Concepts

  • Application Security:

    • In-depth knowledge of secure coding practices, including familiarity with OWASP Top 10 and CWE guidelines.

    • Experience integrating security into the Software Development Life Cycle (SDLC).

  • Threat Modeling:

    • Proficiency in threat modeling methodologies such as STRIDE and DREAD.

    • Ability to identify attack surfaces and develop mitigation strategies.

  • Cloud Security:

    • Expertise in AWS and Azure security best practices, including IAM, KMS, GuardDuty, and Security Center.

    • Understanding of encryption mechanisms for data at rest and in transit.

    • Experience in hardening cloud resources to prevent unauthorized access.

  • Infrastructure and CI/CD Security:

    • Knowledge of securing Infrastructure as Code (IaC) using tools like Terraform and CloudFormation.

    • Experience with secrets management and integrating security scans (SAST, SCA, DAST) into CI/CD pipelines.

  • Vulnerability Management:

    • Proficiency in using tools like Snyk, TruffleHog, and CrowdStrike CSPM for vulnerability assessment.

    • Ability to prioritize vulnerabilities based on risk and impact.

  • Authentication and Authorization Security:

    • Understanding of OAuth 2.0, OpenID Connect, and Single Sign-On (SSO) principles.

    • Experience in implementing secure authentication and authorization mechanisms.

  • Container and Kubernetes Security:

    • Knowledge of container security best practices, including image scanning and hardening.

    • Experience with Kubernetes security features like RBAC and network policies.

  • Cryptography Fundamentals:

    • Familiarity with TLS/SSL protocols, encryption standards, and key management practices.

  • Security Standards and Compliance:

    • Awareness of frameworks such as NIST, ISO 27001, SOC 2, and PCI DSS.

    • Experience in aligning security practices with compliance requirements.

  • DevSecOps Tooling:

    • Proficiency in using CI/CD tools like GitHub, GitLab, and Bitbucket, and integrating security automation into workflows.

Be Bold. Be You. Be Boomi. We take pride in our culture and core values and are committed to being a place where everyone can be their true, authentic self. Our team members are our most valuable resources, and we look for and encourage diversity in backgrounds, thoughts, life experiences, knowledge, and capabilities.

All employment decisions are based on business needs, job requirements, and individual qualifications.

Boomi strives to create an inclusive and accessible environment for candidates and employees. If you need accommodation during the application or interview process, please submit a request to talent@boomi.com. This inbox is strictly for accommodations, please do not send resumes or general inquiries.

Company benefits

Shared parental leave
Open to compressed hours
Accrued annual leave
Compassionate leave
Enhanced sick pay
Mental health days
In house training
Enhanced WFH tools
Annual bonus
Private GP service
Health insurance
Life insurance
Travel insurance
Dental coverage
Eye Care Support
Faith rooms
Mental health and wellbeing programs
Fitness programs and discounts
Retirement plans with employer contributions
Paid parental leave
Flexible vacation time

We asked employees of Boomi what it's like to work there, and this is what they told us.

Location flexibility
90%
Employees are very happy with their working location freedom
Hours flexibility
86%
Employees are very happy with the flexibility in the hours they work
Benefits
76%
Employees are largely happy with the benefits their company offers
Work-life balance
76%
Employees feel that they can switch off quite easily from work
Role modelling
82%
Employees feel that flexible working is part of the culture
Autonomy
86%
Employees feel they have complete autonomy over getting their work done

Additional employee ratings
(these do not contribute to the FlexScore®)

Diversity
79%
Employees feel that the diversity is good and there are continued efforts to improve it
Inclusion
79%
Employees feel that the culture supports equity and inclusivity well
Culture
79%
Employees enjoy the working environment
Mission
81%
Employees feel very excited about and aligned with the company mission
Salary
66%
Employees feel that their salary is good and matches the value they bring

Working at Boomi

Company employees

1,500

Currently Hiring Countries

Australia

Canada

Germany

India

Israel

Spain

United Kingdom

United States

Office Locations

Awards & Achievements

3rd – Diversity and Inclusion

3rd – Diversity and Inclusion

Flexa awards 2025
Family Friendly

Family Friendly

Flexa awards 2025
Most flexible companies

Most flexible companies

Flexa100 2024
SaaS & Software

SaaS & Software

Industry awards 2023
;