> Markdown version of [/jobs/ext/1306028-security-controls-engineer](https://www.wearedevelopers.com/jobs/ext/1306028-security-controls-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Controls Engineer - **Company:** Tata Consultancy Services Limited - **Location:** Irving, TX, United States - **Experience:** Experienced - **Salary:** $100,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Amazon Web Services, Unit Testing, Microsoft Azure, Cloud Computing, Computer Programming, DevOps, Intrusion Detection and Prevention, Python (Programming Language), Security Information and Event Management, Software Engineering, Google Cloud, Cloud Platform System, Backend, Terraform, Splunk, Devsecops, Api Management - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b55b2c9b40c3f0a0 ## About the Role This is a development-heavy role. Candidates must demonstrate strong coding capability. Security experience is required, but coding proficiency is mandatory. * Minimum of 3-5 years of experience in DevSecOps engineering with a focus on cloud environments (AWS, GCP, Azure), ideally working within a security program. * Strong software engineering background - proficiency in software testing methodologies and tools. * Advanced proficiency in Python - proficiency with Python and Terraform for testing, automation and custom tool development. * Proficiency with: o API integrations and backend development o Writing scalable, maintainable code * Hands-on experience with: o Automated testing frameworks (Python) o CI/CD pipelines * Experience with cloud-native development and architecture, leveraging services and tools specific to AWS, GCP, and Azure. * Experience with detection engineering: detection-as-code practices, developing and maintaining detection rules * Hands-on experience with Open Policy Agency (OPA) for policy enforcement * Proficiency in DevOps tools and practices * Experience with SIEM query languages such as Splunk SPL, YARA rules, etc., Qualifications : BACHELOR OF COMPUTER SCIENCE ## Description * Design and develop custom security controls based on threat modelling outputs * Build: o Detective controls using Python-based frameworks o Preventative controls using OPA/Rego policies * Extend and enhance existing security control frameworks * Develop and maintain: o Automated unit tests o Behavioral (BDD) test cases * Integrate controls into CI/CD pipelines for continuous validation * Collaborate with: o Threat modeling teams o Cloud architects o Security SMEs ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)