Architect DevSecOps
Styli- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
Role: Architect – DevSecOps
Location: Bangalore
Department: Platform Engineering / Architect
Experience: 8–12 Years
About Styli Marketplace
Launched in 2019 by Landmark Group, Styli Marketplace is the first e-commerce venture of the
group, quickly becoming a leading online destination for fashion and lifestyle across the GCC,
including Saudi Arabia, the UAE, Kuwait, Bahrain, and beyond. Styli connects global sellers and
creators with millions of fashion-forward customers, offering the latest trends, exceptional value,
and convenient services like same-day to 48-hour delivery and flexible payment options. Our
mission is to make style accessible, aspirational, and exciting for all, backed by a passionate
team fostering a culture of creativity and innovation. At Styli, we aim to revolutionize fashion
retail and bring unique experiences to our customers.
Role Overview
We are looking for a senior, hands-on Architect – DevSecOps to lead the design and evolution
of the platform that powers Styli's commerce business on GCP. This role is the technical anchor
across three deeply connected disciplines — reliability engineering, platform/DevOps, and
application security — and is responsible for setting the architectural direction while staying
close to the code, infrastructure, and incidents.
You will own a large-scale, multi-region GCP architecture, define SLOs and reliability practices, embed security into every stage of the SDLC, and partner with product engineering leaders to ensure Styli scales reliably and securely through flash sales, regional expansion, and traffic peaks of 10x–20x baseline.
This is explicitly a hands-on architect role — you will write Terraform, debug production
incidents, review pull requests, integrate security gates into services/pipelines, tune GKE
clusters, and pair with engineers on hard problems. We expect senior judgment and influence,
not slide decks.
What You'll Do
Architecture & Technical Leadership
• Own the end-to-end architecture for Styli's platform on GCP — compute, networking,
data, security, and delivery — across multiple regions and environments.
• Define and evolve the platform engineering, SRE, and DevSecOps roadmaps in
alignment with business growth, peak commerce events, and regional expansion across
the GCC.
• Set technical standards, golden paths, and reference architectures that product
engineering teams build on.
• Lead architecture reviews for new services, third-party integrations, and major platform
changes — balancing reliability, security, cost, and developer velocity.
• Mentor senior engineers across SRE, DevOps, and AppSec; provide technical guidance
without becoming a bottleneck.
Large-Scale GCP Cloud Architecture
• Design and operate multi-region, multi-project GCP landing zones using Shared
VPC, VPC Service Controls, Private Service Connect, Cloud Interconnect, and
Hierarchical Firewall Policies.
• Architect for high-traffic e-commerce — design stateless services, sharded data tiers,
multi-tier caching (Memorystore, CDN), async pipelines (Pub/Sub), and graceful
degradation strategies for flash sales and campaign launches.
• Own GCP-native services at scale: GKE, Cloud Run, Cloud SQL, AlloyDB, Cloud
Spanner, BigQuery, Pub/Sub, Cloud CDN, Cloud Armor, Apigee, and Service Mesh.
• Drive multi-region resilience — active-active and active-passive patterns, regional
failover playbooks, data replication strategies, and DR drills with measurable RTO/RPO
targets.
• Lead FinOps for the platform — design cost-aware architectures, committed use and
Spot/preemptible strategies, chargeback/showback models, and continuous cost
optimisation reviews.
• Govern IAM, organisation policies, and resource hierarchy to enforce least privilege and
prevent configuration drift at scale.
Site Reliability Engineering (SRE)
• Define and operationalise SLOs, SLIs, and error budgets for all customer-facing and
critical internal services; drive reliability conversations with product engineering using
error budget policy.
• Lead capacity planning and load testing for sale events and seasonal peaks — model
traffic patterns, run game days, and validate auto-scaling and circuit-breaking behaviour
end-to-end.
• Design and operate observability across logs, metrics, traces, and events — typically
using Prometheus, Grafana, OpenTelemetry, Cloud Operations Suite, and tools such as
Datadog, New Relic, or Honeycomb.
• Drive systemic reliability improvements: chaos engineering, dependency hardening,
graceful degradation patterns, and elimination of single points of failure.
• Continuously reduce operational toil through automation, self-healing systems, and
platform improvements.
DevSecOps & Application Security
• Own the application security and DevSecOps strategy — shift-left security across
the SDLC with secure coding standards, threat modelling, and security architecture
reviews.
• Design and operate the security toolchain: SAST, DAST, SCA, IaC scanning,
container image scanning, secret scanning, and runtime protection — integrated into
CI/CD with developer-friendly feedback loops.
• Lead Kubernetes and cloud security hardening
• Manage secrets and identity at scale using Secret Manager solutions
• Drive compliance and audit readiness and regional data-residency requirements
relevant to the GCC.
• Own edge and API security
• Lead vulnerability management — triage, SLA-driven remediation, and root-cause-based
class-of-vuln elimination — and partner with engineering on secure-by-default
frameworks.
Kubernetes & Container Platform
• Architect and operate production GKE clusters (Standard and Autopilot) at scale —
multi-cluster, multi-region, with strong tenancy boundaries.
• Design workload scheduling: HPA, VPA, KEDA, node pool strategy, topology spread,
PDBs, and graceful shutdown patterns for stateful and stateless workloads.
• Own the GitOps delivery model using ArgoCD or Flux, with Helm/Kustomize patterns
that scale across dozens of services and environments.
• Run a production service mesh
DevOps, CI/CD & Internal Developer Platform
• Design fast, secure, and reliable CI/CD pipelines with built-in security gates and
progressive delivery.
• Build the internal developer platform and golden paths so engineering teams can ship
safely and quickly without re-solving infrastructure problems.
• Implement deployment patterns: blue-green, canary, and feature-flag-driven releases
with automated rollback based on SLO breach.
• Drive a strong automation culture — Python, Bash, or Go — to eliminate manual
operations and ensure reproducibility across dev, staging, and production.
What We're Looking For
Required
• 8–12 years of hands-on experience across DevOps, SRE, Platform Engineering, and
DevSecOps — with at least 3+ years in an architect, principal, or staff-level role.
• Deep, hands-on expertise on GCP
• Proven experience in architecting and running e-commerce or high-traffic
consumer platforms
• Strong SRE foundations — SLOs, error budgets, capacity planning, incident
command, blameless postmortems, and a track record of measurable reliability
improvements.
• Strong application security and DevSecOps background
• Expert Kubernetes operations — multi-cluster GKE, RBAC, network policies,
admission control (OPA/Kyverno), service mesh, GitOps (ArgoCD/Flux), and
Helm/Kustomize.
• Expert with Terraform for multi-cloud / multi-account IaC.
• Strong scripting/automation skills in Python and/or Go; comfortable reading and
contributing to application code in at least one mainstream language.
• Excellent communication and influence skills — able to drive alignment across
engineering, product, security, and leadership without relying on positional authority.
Good to Have
• Experience in fashion, marketplace, or D2C e-commerce
• FinOps leadership experience — managing multi-million-dollar cloud spend with
chargeback/showback models.
• Data platform familiarity — Kafka, Spark, Airflow, dbt, or BigQuery at production scale.
• Relevant certifications: Google Professional Cloud Architect, Professional Cloud
Security Engineer, Professional Cloud DevOps Engineer, CKA / CKS, CISSP, or OSCP.
• Contributions to open-source projects in the CNCF / security ecosystem.
The Scale You'll Work At
• Millions of active users across multiple countries in the Middle East — Saudi Arabia,
UAE, Kuwait, Qatar, Bahrain, and Oman.
• High-concurrency commerce events — flash sales and campaign launches driving
10x–20x baseline traffic.
• Microservices are deployed across multi-region GKE clusters with strong tenancy and
security boundaries.
• Cloud architecture hosted on GCP (primary), with a focus on regional proximity to end
users across the GCC.
• A security and reliability bar that protects customer trust, payment flows, and brand
reputation across markets with varying regulatory expectations.

