SecDevOps Engineer

MoneyMul

Dadri

On-site

INR 1,200,000 - 2,400,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Top-up health insurance
Collaborative startup culture
5-day work week
Professional development opportunities

Job summary

MoneyMul is seeking a vigilant SecDevOps Engineer to bridge development, operations, and security. You will secure and maintain CI/CD pipelines and IaC, ensure vulnerability management, and enforce least-privilege access across cloud environments.

You will automate security checks, integrate SAST/DAST/IA tools, and work with Docker/Kubernetes to implement runtime security policies. A strong scripting background and hands-on cloud security experience are essential.

Qualifications

  • 2–5+ years of professional experience in DevOps with a demonstrated focus on CI/CD and Security.
  • Hands-on experience with CI/CD tools (Jenkins, GitLab CI, GitHub Actions) and Git.
  • Proficiency with security scanning tools such as SonarQube, Trivy, OWASP ZAP, Burp Suite, or Snyk.
  • Solid understanding of cloud security models (GCP/AWS/Azure), including Security Groups, IAM, and VPC configurations.
  • Strong proficiency in Python, Bash, or Go for automating security tasks.
  • Experience securing Docker containers and Kubernetes clusters.
  • Familiarity with OWASP Top 10 vulnerabilities and how to mitigate them.

Responsibilities

  • Secure CI/CD implementation: Design and maintain CI/CD pipelines, integrating automated security testing tools into the build process.
  • Infrastructure security: Manage IaC using Terraform or Ansible with a focus on security compliance and hardening.
  • Vulnerability management: Monitor, scan, and patch infrastructure and applications for vulnerabilities; collaborate with developers to remediate issues.
  • IAM: Configure and audit cloud access policies to enforce the Principle of Least Privilege.
  • Container security: Implement image scanning and runtime security policies for Docker/Kubernetes.
  • Incident response: Participate in security incident response activities and root cause analysis.
  • Compliance & audit: Ensure deployments comply with standards (ISO 27001, SOC2, GDPR) and assist in audits.

Skills

CI/CD
Security automation
Scripting
Cloud security
IaC (Terraform/Ansible)
Container security
Vulnerability management
IAM & access management
Incident response
Secure by design

Tools

Jenkins
GitLab CI
GitHub Actions
SonarQube
OWASP ZAP
Trivy
Burp Suite
Snyk

Job description

Job Description:


We are seeking a vigilant and skilled SecDevOps Engineer to bridge the gap between development, operations, and security. In this role, you will not only maintain our CI/CD pipelines and infrastructure but also ensure they are secure by design. You will be responsible for \"shifting security left\"—automating security checks, managing vulnerabilities, and ensuring that our infrastructure aligns with industry compliance standards without slowing down the development velocity.


Key Responsibilities


  • Secure CI/CD Implementation: Design and maintain CI/CD pipelines, integrating automated security testing tools (SAST, DAST, SCA) directly into the build process (e.g., SonarQube, OWASP ZAP).


  • Infrastructure Security: Manage Infrastructure as Code (IaC) using Terraform or Ansible with a focus on security compliance and hardening (e.g., ensuring encrypted storage, least privilege access).


  • Vulnerability Management: Proactively monitor, scan, and patch infrastructure and applications for vulnerabilities (CVEs); collaborate with developers to remediate code-level security issues.


  • Identity & Access Management (IAM): Configure and audit cloud access policies (AWS/Azure/GCP) to enforce the Principle of Least Privilege.


  • Container Security: Secure containerized environments (Docker/Kubernetes) by implementing image scanning and runtime security policies.


  • Incident Response: Participate in security incident response activities and root cause analysis for security breaches or anomalies.


  • Compliance & Audit: Ensure infrastructure and deployments comply with security standards (ISO 27001, SOC2, or GDPR) and assist in technical audits.



Requirements


  • Experience: 2–5+ years of professional experience in DevOps with a demonstrated focus on CI/CD and Security with strong scripting/automation skills.


  • DevOps Tool chain: Strong hands‑on experience with CI/CD tools (Jenkins, GitLab CI, GitHub Actions) and Version Control (Git).


  • Security Tools: Proficiency with security scanning tools such as SonarQube, Trivy, OWASP ZAP, Burp Suite, or Snyk.


  • Cloud Security: Solid understanding of cloud security models (GCP/AWS/Azure), including Security Groups, IAM, and VPC configurations.


  • Scripting: Strong proficiency in Python, Bash, or Go to automate security tasks.


  • Containerization: Experience securing Docker containers and Kubernetes clusters.


  • Vulnerability Knowledge: Familiarity with OWASP Top 10 vulnerabilities and how to mitigate them.



Preferred Skills (Good to Have)


  • Certifications: Any Certified DevSecOps Professional (CDP) orequivalent


  • Monitoring: Experience with security monitoring and SIEM tools (e.g., Splunk, ELK Stack for security logs, Wazuh).


  • Policy as Code: Experience with tools like Open Policy Agent (OPA) or Sentinel.


  • Compliance: Basic understanding of regulatory frameworks like HIPAA, PCI‑DSS, or GDPR.



Benefits


  • Impactful Work: Opportunity to contribute to projects used by over 100 top MNC companies and a large 10 million+ customer base.




  • Direct Collaboration: Employees have the opportunity to work closely and communicate directly with the Founding Team.




  • Optimal Work Structure: We operate on a 5-day working schedule.




  • Professional Development: Committed to growth through eLearning, workshops, and the use of advanced AI models in day‑to‑day operations.




  • Comprehensive Well‑being: Provision of on‑demand comprehensive health insurance coverage with a Top‑up facility for Parents, Spouse, and Children.




  • Dynamic Environment: Experience the energy of a startup, allowing employees to take on diverse responsibilities, learn new skills, and make a difference.



Requirements:

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Operations Engineer
Staff Security Operations Engineer

Jobgether • India

On-site
INR 3,500,000 - 5,500,000
Remote-first environment
In-person team sprints abroad
Learning budget USD 2,000 (annual)
Devsecops Engineer
Devsecops Engineer

Cloudbc Labs • Dadri, Pune District, Bengaluru

On-site
INR 1,500,000 - 2,300,000
DevOps /DevSecOps Specialist
DevOps /DevSecOps Specialist

Goodfit • Dadri

Hybrid
INR 1,500,000 - 2,100,000
DevSecOps Engineer
DevSecOps Engineer

Persistent Systems Limited • Pune District

Hybrid
INR 3,000,000 - 5,500,000
Hybrid work model
Education sponsorship and certificates
Group term life insurance
Application Security Architect
Application Security Architect

Orcapod Consulting Services • Hyderabad

Hybrid
INR 4,000,000 - 7,000,000
Comprehensive health insurance
Accidental insurance coverage
Professional development programs
+2
Dev SecOps Engineer
Dev SecOps Engineer

Persistent Systems • Pune City

On-site
INR 1,200,000 - 1,800,000
Competitive salary and benefits package
Quarterly promotion cycles
Company-sponsored higher education
+2
Deputy Director - DevSecOps
Deputy Director - DevSecOps

PepsiCo • Hyderabad

On-site
INR 3,500,000 - 5,500,000
DevSecops Engineer
DevSecops Engineer

Weekday • Bengaluru

On-site
INR 1,200,000 - 2,400,000
DevSecOps Engineer
DevSecOps Engineer

Delta6Labs FinTech Pvt Ltd • India

On-site
INR 1,200,000 - 1,800,000
DevSecOps Engineer
DevSecOps Engineer

Weekday AI (YC W21) • Dadri

On-site
INR 500,000 - 3,000,000