DevSecOps-AI SSDLC Security Engineer

Alignity

Hyderabad

Hybrid

INR 1,800,000 - 3,200,000

Part time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Equal Opportunity Employer

Job summary

Alignity is seeking a DevSecOps-AI SSDLC Security Engineer in Hyderabad. Hybrid work model, contract-to-hire, with 5-8 years of experience. Immediate joiners preferred.

You will integrate SAST/SCA/DAST in CI/CD, assess OWASP risks, audit APIs (OAuth2/JWT), and drive secure coding practices with cross-functional teams.

Qualifications

  • As a Security Engineer, you will integrate, configure, and optimize SAST, SCA, and DAST tools within CI/CD pipelines to automate security testing across build, test, and release stages (including quality gates and exception workflows).
  • Perform static, dynamic, and open-source dependency assessments to identify vulnerabilities including OWASP Top 10 risks, insecure libraries, exposed secrets, misconfigurations, and software supply‑chain weaknesses.
  • Execute API security testing (REST/GraphQL) including authentication/authorization validation (OAuth2/OIDC/JWT), input validation, rate limiting/abuse cases, and broken object/function level authorization (BOLA/BFLA).
  • Analyze scan results, remove false positives, prioritize findings based on exploitability and business impact, and provide remediation guidance.

Responsibilities

  • Integrate, configure, and optimize SAST, SCA, and DAST tools within CI/CD pipelines to automate security testing across build, test, and release stages.
  • Perform static, dynamic, and open-source dependency assessments to identify vulnerabilities and risks including OWASP Top 10.
  • Execute API security testing (REST/GraphQL) including OAuth2/OIDC/JWT validation and BOLA/BFLA checks.
  • Analyze results, remove false positives, and provide actionable remediation guidance to developers.

Skills

SAST
SCA
DAST
CI/CD pipelines
OWASP Top 10
OAuth2/JWT
Python
Bash
Kubernetes security
SBOM
Threat modeling

Tools

CI/CD tooling

Job description

Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you. Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees. Jobseeker Video Testimonials Employee Glassdoor Reviews

If you are a DevSecOps-AI SSDLC Security Engineer looking for excitement, challenge and stability in your work, then you would be glad to come across this page. We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details. Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.

Role:DevSecOps-AI SSDLC Security Engineer

Location: Hyderabad

Experience:5-8 Years

Work Mode: Hybrid

Type: Contract to Hire

Notice Period:Immediate Joiners

Requirements Description: As a Security Engineer, you will:

  • Integrate, configure, and optimize SAST, SCA, and DAST tools within CI/CD pipelines to automate security testing across build, test, and release stages (including quality gates and exception workflows).
  • Perform static, dynamic, and open-source dependency assessments to identify vulnerabilities including OWASP Top 10 risks, insecure libraries, exposed secrets, misconfigurations, and software supply‑chain weaknesses.
  • Execute API security testing (REST/GraphQL) including authentication/authorization validation (OAuth2/OIDC/JWT), input validation, rate limiting/abuse cases, and broken object/function level authorization (BOLA/BFLA), and translate results into developer‑ready fixes.
  • Analyze scan results, remove false positives, prioritize findings based on exploitability and business impact, and provide clear, actionable remediation guidance (secure coding patterns, compensating controls, and verification steps).
  • Work hands‑on with developers, DevOps engineers, architects, and client stakeholders to embed secure coding, secure design, and shift‑left security practices, including playbooks, office hours, and remediation sprints.
  • Support threat modeling and security design reviews; convert threats into actionable security requirements, test cases, and engineering backlog items aligned to delivery timelines.
  • Track vulnerabilities through closure, validate remediation (re‑scan, proof of fix, and regression checks), and ensure issues are managed in line with client policy, risk tolerance, and SLA expectations.
  • Implement additional DevSecOps controls such as IaC scanning, secrets detection, container image scanning, and Kubernetes security checks (where applicable), including policy‑as‑code to prevent insecure deployments.
  • Strengthen software supply‑chain security by supporting SBOM generation/consumption, dependency hygiene, and build/release integrity controls (e.g., artifact signing/verification and provenance where applicable).
  • Automate repeatable security tasks using scripting (e.g., Python/Bash) and integrations (APIs/webhooks) to improve scan reliability, reporting, and developer workflow adoption.
  • Design and build AI agents / agentic workflows for AppSec automation (e.g., triage, false‑positive suppression, secure code review assistance, threat‑model generation, remediation assistance), ensuring appropriate guardrails, logging, and human‑in‑the‑loop validation.
  • Perform current‑state assessments of client DevSecOps and emerging AISecOps practices against industry standards; provide prioritized recommendations and an implementation roadmap.
  • Perform security testing across modern application surfaces—code, APIs, cloud, containers/Kubernetes—and, where applicable, AI/ML pipelines (e.g., RAG data flows, model integration points, and tool/function calling) using a combination of automated and manual techniques.
  • Produce security assessment reports, dashboards, trend analysis, and root‑cause insights for technical and non-technical stakeholders.
  • Contribute to secure SDLC standards aligned to recognized verification frameworks such as OWASP ASVS Stay current on emerging threats, AppSec tooling trends, software supply‑chain risks, and new attack surfaces introduced by AI‑enabled applications and agentic workflows.
Benefits

Visit us at http://alignity.io/careers.

Alignity Solutions is an Equal Opportunity Employer, M/F/V/D.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps-AI SSDLC Security Engineer
DevSecOps-AI SSDLC Security Engineer

Alignity Solutions • Hyderabad

Hybrid
INR 800,000 - 1,400,000
DevSecOps Engineer (SAST/DAST) 3 - 8 Yrs
DevSecOps Engineer (SAST/DAST) 3 - 8 Yrs

Alignity • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Equal Opportunity Employer
VAPT Security Engineer
VAPT Security Engineer

Alignity • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Data Security and Cloud Engineer
Data Security and Cloud Engineer

Alignity • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Equal Opportunity Employer
Application Security Engineer – SAST/DAST & Security Tooling Outage Support
Application Security Engineer – SAST/DAST & Security Tooling Outage Support

Alignity • Hyderabad

Hybrid
INR 1,200,000 - 2,000,000
Application Security Consultant (SAST & DAST)
Application Security Consultant (SAST & DAST)

Alignity • Hyderabad

Hybrid
INR 1,500,000 - 2,500,000
DevSecOps Specialist | Jobs In India
DevSecOps Specialist | Jobs In India

DigitalXNode • Ahmedabad District

On-site
INR 1,200,000 - 1,600,000
DevSecOps Engineer
DevSecOps Engineer

Exaze • Hyderabad

On-site
INR 3,500,000 - 6,000,000
DevSecOps & Product Security Engineer
DevSecOps & Product Security Engineer

Weekday • Hyderabad

Hybrid
INR 400,000 - 1,500,000
Penetration Tester
Penetration Tester

Alignity • Hyderabad

Hybrid
INR 900,000 - 1,500,000
Hybrid work
Equal Opportunity Employer