DevSecOps, Product Security Engineer

Jobtailor

Hyderabad

On-site

INR 1,800,000 - 3,000,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a hands-on DevSecOps Engineer to implement security checks across the SDLC and champion secure coding practices. You will review authentication, APIs, and cloud IAM, and collaborate with developers, architects, and product leadership to reduce risk.

Experience with OWASP Top 10, Python backends, React frontends, GitHub Actions, SAST, and container security is required. You will help harden pipelines and maintain audit-ready security evidence.

Qualifications

  • Hands-on DevSecOps and application/API security experience
  • Working knowledge of OWASP Top 10
  • Python backends experience
  • React applications experience
  • Strong GitHub and CI/CD security experience (pull requests, GitHub Actions, SAST, dependency scanning, secret scanning)
  • Experience securing Google Cloud environments (IAM, service accounts, least-privilege)
  • Track record of risk assessment and remediation
  • Experience securing AI platforms, SaaS integrations, or sensitive data pipelines is a plus
  • PostgreSQL and Infrastructure-as-Code security familiarity is a plus
  • GCP Security tools and container/Kubernetes security familiarity is a plus
  • Familiarity with CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, Burp Suite is a plus
  • Exposure to SIEM, cloud monitoring/MDR, and SOC 2 or ISO 27001 frameworks is good to have
  • Security experience with AI/LLM systems, agents, and RAG-based apps is good to have

Responsibilities

  • Implement security checks, scanning, and quality gates across the SDLC
  • Champion secure coding and remediation practices
  • Review authentication, authorization, APIs, tenant isolation, and access controls
  • Identify and mitigate OWASP and API security risks through threat modelling
  • Assess AI agents, prompts, connectors, and data-access risks
  • Protect against prompt injection, data leakage, tool misuse, and unsafe AI actions
  • Secure Google Cloud IAM, service accounts, networking, secrets, and workloads
  • Enforce least privilege and environment separation
  • Harden GitHub Actions, dependencies, and deployment pipelines
  • Implement secret protection, SCA, SBOM, and secure release processes
  • Establish processes to identify, prioritize, and track vulnerabilities
  • Coordinate remediation and validate fixes
  • Strengthen security logging, alerting, and investigation capabilities
  • Support incident response, root-cause analysis, and security drills
  • Maintain audit-ready security evidence
  • Support penetration testing, compliance activity, and security architecture documentation
  • Work directly with developers, architects, cloud engineers, and product leadership

Skills

DevSecOps
API security
OWASP Top 10
Python backends
React applications
GitHub & CI/CD security
SAST
Dependency scanning
Secret scanning
GCP IAM
Least privilege
Containerized workloads
Threat modelling
Risk assessment
AI platform security
SaaS integrations security
Data pipelines security
Infrastructure-as-Code security
GCP Security Command Center
Kubernetes security
CodeQL
Semgrep
SonarQube
Dependabot
Trivy
OWASP ZAP
Burp Suite
SIEM
Cloud monitoring / MDR
SOC 2 / ISO 27001
AI/LLM security

Tools

GitHub Actions
SAST
Dependency scanning
Secret scanning
CodeQL
Semgrep
SonarQube
Dependabot
Trivy
OWASP ZAP
Burp Suite
GCP Security Command Center

Job description

  • Implement security checks, scanning, and quality gates across the SDLC
  • Champion secure coding and remediation practices
  • Review authentication, authorization, APIs, tenant isolation, and access controls
  • Identify and mitigate OWASP and API security risks through threat modelling
  • Assess AI agents, prompts, connectors, and data-access risks
  • Protect against prompt injection, data leakage, tool misuse, and unsafe AI actions
  • Secure Google Cloud IAM, service accounts, networking, secrets, and workloads
  • Enforce least privilege and environment separation
  • Harden GitHub Actions, dependencies, and deployment pipelines
  • Implement secret protection, SCA, SBOM, and secure release processes
  • Establish processes to identify, prioritize, and track vulnerabilities
  • Coordinate remediation and validate fixes
  • Strengthen security logging, alerting, and investigation capabilities
  • Support incident response, root-cause analysis, and security drills
  • Maintain audit-ready security evidence
  • Support penetration testing, compliance activity, and security architecture documentation
  • Work directly with developers, architects, cloud engineers, and product leadership
Requirements
  • 4-7 Years of experience
  • Hands-on DevSecOps and application/API security experience
  • Working knowledge of OWASP Top 10, Python backends, and React applications
  • Strong GitHub and CI/CD security experience, including pull requests, GitHub Actions, SAST, dependency scanning, and secret scanning
  • Experience securing Google Cloud environments, including IAM, service accounts, least-privilege access, and containerized workloads
  • Track record of assessing real risk and driving practical remediation
  • Experience securing AI platforms, SaaS integrations, or sensitive data pipelines is good to have
  • PostgreSQL and Infrastructure-as-Code security, GCP Security Command Center, and container/Kubernetes platforms are good to have
  • Familiarity with CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, or Burp Suite is good to have
  • Exposure to SIEM, cloud monitoring/MDR, and SOC 2 or ISO 27001 frameworks is good to have
  • Security experience with AI/LLM systems, agents, and RAG-based applications is good to have
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

Sutherland Global • Hyderabad

On-site
INR 1,800,000 - 2,600,000
DevSecOps Engineer
DevSecOps Engineer

Delta6Labs FinTech Pvt Ltd • India

On-site
INR 1,200,000 - 1,800,000
DevSecOps Engineer
DevSecOps Engineer

Sutherland • India

On-site
INR 3,800,000 - 6,800,000
DevSecOps And Product Security Engineer
DevSecOps And Product Security Engineer

Weekday AI (YC W21) • Hyderabad

Hybrid
INR 400,000 - 1,500,000
Sr. DevSecOps Engineer
Sr. DevSecOps Engineer

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,500,000 - 2,000,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

IntraEdge • Hyderabad

On-site
INR 2,000,000 - 4,200,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Ecolab Global Services • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
DevSecOps Engineer
DevSecOps Engineer

Clinikally (YC S22) • Gurugram District

On-site
INR 1,200,000 - 2,000,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000