NextRaise Logo
JobsTrackerResumes
Job MatchATS
ResumesJobsProfile
Jobs / Security Engineer in India
22 hours agoBe an early applicant
Apply with autofill
Apply with autofill
Weekday AI·22 hours ago
22 hours agoBe an early applicant

DevSecOps & Product Security Engineer

Hyderabad, IndiaFull-timeHybridMid · 4-7 years

Sign up free to see how well your resume matches this role.

About this role

This role is for one of Weekday’s clients
Salary range: Rs 400000 - Rs 1500000 (ie INR 4 - 15 LPA)


Location: Hyderabad, India — Hybrid / On-site 

Employment Type: Full-time

Experience: 4–7 Years

Reports To: IT & Cloud Manager 

We're hiring a hands-on DevSecOps & Product Security Engineer to embed security across the software development and deployment lifecycle — spanning application security, cloud security, and DevSecOps practice for modern SaaS and AI-enabled platforms. A key focus area is Stratpilot, our AI-powered business platform integrating with enterprise systems such as email, calendars, documents, CRM tools, and internal data sources. This is an engineering-focused security role, not a SOC or monitoring function. You'll work directly with developers, architects, and cloud engineers to identify risk, automate controls, strengthen CI/CD pipelines, and drive vulnerabilities through to resolution. 

Requirements

What You'll Do 

Secure Development & Application Security 

• Implement security checks, scanning, and quality gates across the SDLC, and champion secure coding and remediation practices. 

• Review authentication, authorization, APIs, tenant isolation, and access controls — identifying and mitigating OWASP and API security risks through threat modelling. 

AI Product Security 

• Assess AI agents, prompts, connectors, and data-access risks, protecting against prompt injection, data leakage, tool misuse, and unsafe AI actions. Cloud & CI/CD Security 

• Secure Google Cloud environments — IAM, service accounts, networking, secrets, and workloads — enforcing least privilege and environment separation. 

• Harden GitHub Actions, dependencies, and deployment pipelines with secret protection, SCA, SBOM, and secure release processes. 

Vulnerability Management & Monitoring 

• Establish a process to identify, prioritize, and track vulnerabilities, coordinating remediation and validating fixes. 

• Strengthen security logging, alerting, and investigation capability, and support incident response, RCA, and security drills. 

Security Assurance 

• Maintain audit-ready security evidence, and support penetration testing, compliance activity, and security architecture documentation. 

What We're Looking For 

Must-Have 

• Hands-on DevSecOps and application/API security experience, with working knowledge of OWASP Top 10, Python backends, and React applications. • Strong GitHub and CI/CD security experience — pull requests, GitHub Actions, SAST, dependency and secret scanning. 

• Experience securing Google Cloud environments: IAM, service accounts, least-privilege access, and containerized workloads. 

• A track record of cutting through scanner noise to assess real risk and drive practical remediation. 

• Strong communicator who's hands-on fixing issues, not just reporting them. 

Good to Have 

• Securing AI platforms, SaaS integrations, or sensitive data pipelines. 

• PostgreSQL and Infrastructure-as-Code security, GCP Security Command Center, and container/Kubernetes platforms. 

• Familiarity with CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, or Burp Suite. 

• Exposure to SIEM, cloud monitoring/MDR, and frameworks such as SOC 2 or ISO 27001. 

• Security experience with AI/LLM systems, agents, and RAG-based applications. 

You'll Thrive Here If You 

• Enjoy working closely with engineers and product teams, and move fluidly between code, cloud, and security analysis. 

• Prefer automation over manual process, and see security as an enabler of delivery, not a blocker. 

• Take ownership of issues through to resolution and can explain complex risk in simple, practical terms. 

• Are curious about AI-driven product security challenges. 

Why us: 

• Work across multiple modern product engineering teams and influence security architecture on real production systems. 

• Build hands-on depth in AI security, cloud security, and application security — all in one role. 

• Build scalable security automation used across multiple global clients. 

• Partner directly with engineering, architecture, and product leadership — no ivory-tower security. We value practical experience and real-world problem-solving over certifications or tool checklists.

Must-have skills

DevSecOps

Good-to-have skills

Application & API Security

AI tools
Apply faster with autofillThe NextRaise extension autofills your application in one click.Get the extension

Similar jobs

  • Lead Information Security Engineer- Architect at Wells FargoBengaluru, India
  • Information Security Engineer II at MastercardVadodara, India
  • Security Engineer - Vulnerability Management at endorlabsBengaluru, India
  • Senior Infrastructure Security Engineer at gruvePune, India
  • Lead Security Engineer - Data Security & RL for Cyberecurity at Weekday AIBengaluru, India
  • Principal Product Security Engineer at candescentBengaluru, India