DevSecOps Engineer

Exaze

Hyderabad

Hybrid

INR 3,500,000 - 6,000,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Exaze is seeking a Senior DevSecOps Engineer to weave security into the software development lifecycle, deployment, and maintenance. You will collaborate with development, IT operations, and governance teams to embed robust security across the pipeline.

Responsibilities include automating security processes, implementing metrics, and guiding secure coding practices. The ideal candidate integrates OWASP, NIST, and industry best practices to elevate security posture.

Qualifications

  • Experience integrating security in SDLC, CI/CD, and deployment pipelines.
  • Familiarity with security frameworks (OWASP, NIST, CWE/SANS) and threat modelling.
  • Proficiency in scripting languages (Python, Ruby, Shell) and modern DevSecOps tooling.

Responsibilities

  • Develop security solutions across the software lifecycle from design to deployment.
  • Collaborate with developers, IT ops, and governance to embed security in the pipeline.
  • Automate security processes to enable CI/CD/CM for applications and infra.

Skills

Security
CI/CD
Scripting (Python)
Java/JavaScript
Threat modelling
OWASP
Communication

Tools

Docker
Kubernetes
Ansible
Chef
Terraform
CloudFormation
Nessus
Qualys
Burp Suite
ZAP
Splunk
ELK

Job description

Job Purpose

As a Senior DevSecOps Engineer, you will be responsible for integrating security into the development, deployment, and maintenance of our software products, ensuring the highest standards of security and reliability.

Key Activities / Outputs
  • Develop and implement security solutions throughout the software development lifecycle, from design to deployment and maintenance, using methodologies such as STRIDE, DREAD, CVSS, and the OWASP ASVS.
  • Work closely with developers, IT operations, and security governance and operations teams to ensure security is integrated into all aspects of the development pipeline.
  • Automate security processes and tools to enable continuous integration, continuous delivery, and continuous monitoring (CI/CD/CM) of applications and infrastructure.
  • Develop and implement metrics, reporting, and monitoring processes to track the effectiveness of DevSecOps practices, using tools like Dynatrace, ELK, Splunk, AWS CloudWatch and Sonatype Examples of metrics include vulnerability remediation times, security incidents, and code review coverage.
  • Establish a governance, review, and continuous improvement process for DevSecOps practices, ensuring alignment with organizational goals and industry best practices.
  • Perform risk assessments and threat modelling to identify potential vulnerabilities and provide recommendations for mitigation strategies.
  • Develop and enforce security policies and guidelines for application and infrastructure development, based on industry best practices and standards such as OWASP Top Ten, CWE/SANS Top 25, NIST SP 800-53, and OWASP ASVS.
  • Train and mentor developers in secure coding practices, emphasizing areas such as input validation, output encoding, and least privilege principles, as well as conducting regular security awareness sessions.
  • Conduct regular security audits, vulnerability assessments, and penetration tests to identify and remediate potential threats.
  • Stay current with industry trends, emerging threats, and best practices in DevSecOps to continuously improve our security posture.
  • Develop and maintain documentation related to security practices, policies, and procedures.
Technical Skills or Knowledge

Strong understanding of software development processes, CI/CD principles, and Agile methodologies, Expertise in various security frameworks, tools, and technologies such as OWASP, SAST, DAST, IAST, RASP, and familiarity with toolsets such as SonarQube, Veracode, Checkmarx, and Fortify, Proficient in scripting languages such as Python, Ruby, or Shell, Experience with containerization and orchestration technologies, such as Docker and Kubernetes, Familiarity with cloud platforms (AWS, Azure, GCP) and their respective security services and tools, Knowledge of networking protocols, firewalls, intrusion detection systems, and encryption technologies, Strong analytical, problem-solving, and communication skills, Software Development: This includes proficiency in programming languages such as Python, Java, JavaScript, or C#, as well as familiarity with software development methodologies like Agile or DevOps, Security Knowledge: They should be familiar with security frameworks such as OWASP (Open Web Application Security Project) and have experience in implementing security controls and practices within software development processes, DevOps Practices: This includes experience with continuous integration and continuous deployment (CI/CD) pipelines, configuration management tools like Ansible or Chef, containerization technologies such as Docker or Kubernetes, and infrastructure-as-code (IaC) tools like Terraform or CloudFormation, Security Tools and Technologies: This may include vulnerability scanning tools like Nessus or Qualys, security testing frameworks such as Burp Suite or ZAP, security information and event management (SIEM) tools like Splunk or ELK stack, and other relevant security tools, Cloud Computing: Experience with cloud security best practices, configuring and securing cloud resources, and managing cloud-based deployments is highly valuable

Preferred Technical Skills (Would be advantageous)

This position is a hybrid role based in Hyderabad which requires you to be in the office on a Tuesday, Wednesday and Thursday.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Security Engineer
DevSecOps Security Engineer

Ford • Chennai District

On-site
INR 1,500,000 - 1,800,000
DevSecOps Engineer
DevSecOps Engineer

Clinikally (YC S22) • Gurugram District

On-site
INR 1,200,000 - 2,000,000
DevSecOps Engineer (Contract-To-Hire)
DevSecOps Engineer (Contract-To-Hire)

Orcapod Consulting Services • Hyderabad

Hybrid
INR 1,800,000 - 2,400,000
Devsecops Engineer
Devsecops Engineer

Cloudxtreme • Pune District

Hybrid
INR 1,200,000 - 2,400,000
DevSecOps Engineer
DevSecOps Engineer

Delta6Labs FinTech Pvt Ltd • India

On-site
INR 1,200,000 - 1,800,000
DevSecOps Engineer
DevSecOps Engineer

Net Connect • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Devsecops Expert
Devsecops Expert

Classic Search • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru Urban

On-site
INR 1,800,000 - 2,400,000
DevSecOps
DevSecOps

Cloudxtreme • Pune District

On-site
INR 1,500,000 - 2,100,000