Cognizant is seeking a DevSecOps Engineer to lead infrastructure-as-code and CI/CD deliverables for the AIM project, focusing on enhancing security across the program. The role involves designing and maintaining Terraform modules, managing cloud resources, and building secure CI/CD pipelines.
Responsibilities:
- Design build and maintain reusable Terraform modules with clear interfaces versioning and documentation so other teams can self-serve infrastructure safely
- Manage and optimize HCP Terraform workspaces using VCS-driven workflows - including workspace design variable sets run triggers and policy enforcement
- Provision and manage cloud resources (primarily AWS) following least-privilege access patterns and security best practices
- Manage secrets and sensitive configuration using HashiCorp Vault and/or AWS Secrets Manager
- Build and maintain CI/CD pipelines (GitHub Actions) with proper gating scanning testing and promotion workflows that integrate with HCP Terraform VCS-driven run model
- Conduct security reviews of infrastructure code and pipeline configurations
Requirements:
- 12+ years of experience
- 5+ years of hands-on Terraform experience including writing modules with proper state management remote backends and provider configuration
- Hands-on Experience with HCP Terraform (Terraform Cloud) specifically VCS-driven workflows - workspace configuration speculative plans on PRs run approvals and managing workspace variables/variable sets
- Experience with HCP Terraform private registry for publishing and consuming internal modules
- Strong understanding of AWS IAM - policies roles trust relationships permission boundaries and service control policies
- Hands-on Experience with at least one secrets management platform: HashiCorp Vault or AWS Secrets Manager
- Solid understanding of OIDC and federated identity - how trust is established token exchange and practical application in CI/CD and cloud access
- Proven experience building and maintaining CI/CD pipelines in GitHub Actions or GitLab CI/CD including environment promotion approval gates and artifact management
- Security-first mindset - you default to deny scope permissions tightly and can articulate why
- Hands-on Experience using AI coding assistants (Amazon Q Kiro GitHub Copilot or similar) with a clear understanding of when to trust verify and override AI-generated output
- Commitment to human-in-the-loop practices code review manual approval gates for production and treating AI output as a draft - never as the final word
- Experience with Sentinel within HCP Terraform
- Knowledge of infrastructure testing tools
- Contributions to internal developer platforms or self-service infrastructure tooling