Director, DevSecOps (AI-First)

Jupiter

Bengaluru

On-site

INR 4,500,000 - 7,500,000

Full time

23 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Office in Bangalore
Direct reporting to President
Budget for tooling and agents

Job summary

Jupiter, a regulated fintech in Bengaluru, is seeking a senior leader to unify platform and security engineering across a multi-cloud estate. You’ll own CI/CD, IaC, SRE practices, and an AI-first DevSecOps approach that ships automated agent checks and secure releases.

You’ll guide a small, high-skill team, interact with regulators, and drive incident response and post-mortems on money-moving services. This is a hands-on leadership role in a fast-paced environment.

Qualifications

  • 15+ years total in software engineering, with 8+ years hands-on across DevOps / Platform / SRE and Application / Cloud Security.
  • 6+ years leading engineering teams, at least 2 as second-line (managers or senior ICs).
  • 3+ years in a regulated industry — fintech, banking, healthtech, or equivalent audit-heavy environment; RBI/PCI-DSS experience preferred.
  • Deep AWS + Kubernetes production experience (multi-account, IAM, VPC, EKS, IaC via Terraform / Terragrunt + Helm / Kustomize); OCI experience is a plus.
  • Hands-on with modern LLM tooling (Claude / GPT / agentic frameworks) for real engineering work.
  • Can read Kotlin, Scala, and TypeScript; write Python fluently.
  • Previously built the DevSecOps function at an Indian fintech under RBI supervision.
  • Ran incident command for Sev-1 affecting customer money; led post-mortem.
  • Public OSS contributions or conference talks in security/platform tooling.

Responsibilities

  • Own Platform / DevOps: CI/CD, Spinnaker pipelines, build systems, feature flags, release gates.
  • Manage multi-cloud AWS + OCI environments; IaC as source of truth with Terraform/Terragrunt and Helm/Kustomize.
  • Develop observability as a product: logs, metrics, traces, alerting; drive on-call and incident response.
  • Lead security tooling: SAST/DAST/IaC scans and CVE triage as PR checks; governance for partner integrations.

Skills

Platform tooling
Security tooling
AWS
Kubernetes
Terraform
Leadership
Python
Cloud security
LLM tooling
Kotlin/Scala/TS

Tools

Spinnaker
Terraform
Terragrunt
Helm
Kustomize
OCI

Job description

If you've spent the last decade building platform and security in fast-moving product companies, and lately found yourself thinking\"most of what my team does could be an agent\"— this is the role.

The tension we're hiring you to resolve

Jupiter is a regulated fintech. ~370 repos, ~50 engineers, live money moving 24×7, RBI-supervised partnerships (CSB, Federal), PCI-DSS card issuance, DPDP obligations, a multi-cloud AWS + OCI estate, dozens of Account Aggregator and bureau integrations. Under normal physics, you'd staff this surface with a 15-person platform team plus a 15-person AppSec org — the size of our entire engineering team.

We don't want either.

We already run one of the most AI-augmented pipelines in Indian fi ntech — our internal agent

Jarvis ships real code, triages alerts, and reviews PRs across the whole estate every day. Our engineers move fast because the paved road is intelligent. We want the same for platform and security together. That's your job.

What \"AI-first DevSecOps\" means at Jupiter

Not \"we bought a Copilot license.

  • \" It means: Deployment orchestration, capacity planning, incident triage, CVE work, threat modeling, IaC review, cost anomaly detection — all designed as agent loops first, human-supervised and continuously improved
  • Every \"senior SRE would have caught this rollback\" and every \"senior AppSec would have caught this XSS\" becomes a repeatable, evaluated agent check — codified, not tribal
  • Deploy latency, incident MTTR, security-review latency, unit cost per transaction —metrics you drive down quarterly, not queues you defend
  • Auditors and partners get automated evidence packs, not spreadsheet marathons
What you'll actually own
Platform / DevOps
  • The paved road for shipping: CI/CD, Spinnaker deploy pipelines, build systems, feature flags, release gates
  • Cloud + Kubernetes across a multi-cloud estate (AWS + OCI, multiple accounts); IaC (Terraform +Terragrunt for cloud, Helm 3 + Kustomize for K8s) as the source of truth
  • Observability platform: logs, metrics, traces, alerting as a product engineers want to use
  • SRE practice: on-call, incident command, error budgets, capacity + cost engineering
Security
  • AppSec paved road: SAST / DAST / SBOM / secret-scan / IaC scan/dependency CVE triage —as PR checks that don't get routed around
  • Cloud + K8s security posture; IAM boundaries, network segmentation for partner integrations
  • Threat modeling on every new service touching money, PII, or a partner API
  • RBI cyber framework, PCI-DSS, DPDP — as artifacts your pipelines emit, not documents your team writes; future-ready for ISO 27001 / SOC 2 when we choose to pursue them
  • Direct interface with banking partners and regulators on our security + reliability posture
Experience & background we're looking for
  • Non-negotiable 15+ years total in software engineering, of which 8+ years hands-on across DevOps / Platform / SRE and Application / Cloud Security (real depth in both — not \"managed a team that did it\")
  • 6+ years leading engineering teams, at least 2 as second-line (managing managers or senior ICs)
  • 3+ years in a regulated industry — fintech, banking, healthtech, or an equivalent audit-heavyenvironment. You've been through at least one RBI / PCI-DSS (or equivalent) audit as an owner, not a bystander. SOC 2 / ISO 27001 experience is a plus.
  • Deep AWS + Kubernetes production experience (multi-account, IAM, VPC, EKS, IaC via Terraform / Terragrunt + Helm / Kustomize). OCI experience is a plus.
  • Hands-on with modern LLM tooling (Claude / GPT / agentic frameworks) for real engineering work — you've shipped or heavily used AI dev tools in the last 12 months, not just experimented
  • Can read Kotlin, Scala, and TypeScript comfortably; write Python fluently
  • Previously built the DevSecOps function at an Indian fintech under RBI supervision
  • Ran incident command for a Sev-1 that touched customer money — and led the post-mortem
  • Public work: OSS contributions to security or platform tooling, conference talks, technical blog with depth
  • Certifications: CISSP / CCSP / OSCP (security), CKA / CKS (Kubernetes), AWS Security Specialty nice signals but we care about what you've shipped, not what you've certified
  • History of hiring and retaining strong ICs (references we can call)
  • MBA / management degree — irrelevant here
  • Big-Tech (FAANG) tenure — nice signal, not required; we've seen more Jupiter-fit talent from product startups than from BigCo
  • Prior \"Director\" title — if you're a Principal / Staff who's been operating at Director scope, apply
You know it's you if…
  • You've shipped platform tooling and security tooling that engineers didn't route around both
  • You can read Kotlin, Scala, and TypeScript, and you write Python without thinking about it
  • You've owned an on-call rota you'd want to be on
  • You've been hands-on with Claude / GPT / agentic frameworks for real work — not just chat
  • You've run platform or security in a regulated environment and know what a real audit feels like
  • You believe the future infra + security leader is 30% engineer, 30% agent-builder, 40% coach —and you're excited about the middle 30%
You should probably skip this if…
  • You want to lead a large team from day one (small strong team, senior-IC-heavy, is by design)
  • You prefer governance to building
  • You're skeptical that agents can do meaningful platform or security work — we'd rather hire someone who's already proven it to themselves
  • You want to specialize in only one side (only Sec, only DevOps) — the whole point of this role is one strong leader across both
The offer
  • Reports directly to the President.
  • Board-level visibility on infra + security posture.
  • Small strong team, budget to build (tooling, agents, headcount as we scale).
  • Bangalore, work from office.
  • Comp calibrated to senior director / VP band at leading Indian fintechs.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Manager
Product Manager

Jupiter • Bengaluru

On-site
INR 3,000,000 - 5,000,000
Security Engineer 2
Security Engineer 2

3one4 Capital • India

On-site
INR 1,200,000 - 2,400,000
DevOps Engineer
DevOps Engineer

Jupiter • Bengaluru

On-site
INR 1,200,000 - 1,800,000
DevSecOps Engineer
DevSecOps Engineer

ASCENRA TECHNOLOGIES • Varanasi

Hybrid
INR 3,600,000 - 4,800,000
Devops Engineer - SDE 2
Devops Engineer - SDE 2

Jupiter • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Executive Founders Office (Technical)
Executive Founders Office (Technical)

Remoat Teams • India

On-site
INR 60,000 - 100,000
Access to masterclasses
Exposure to executive meetings
Competitive performance bonuses
Forward Deployed Engineer (Contract) 3–5 years Remote, Bengaluru
Forward Deployed Engineer (Contract) 3–5 years Remote, Bengaluru

Realfast • Bengaluru

Remote
INR 1,200,000 - 2,400,000
Devops Engineer - SDE 2
Devops Engineer - SDE 2

Jupiter • Bengaluru Urban

Hybrid
INR 1,800,000 - 3,000,000
Software Development Engineer III — Risk Tech
Software Development Engineer III — Risk Tech

Jupiter • Bengaluru Urban

On-site
INR 4,200,000 - 6,800,000
Forward Deployed Engineer 3–5 years Remote, Bengaluru
Forward Deployed Engineer 3–5 years Remote, Bengaluru

Realfast • Bengaluru

Remote
INR 1,800,000 - 2,800,000