DevSecOps & Product Security Engineer
Weekday AI Hyderabad, Telangana, India · ₹300K–₹1M/yr
Technology, Information and Internet · 11-50 employees
About the role
The role involves embedding security controls across the software development lifecycle and securing AI-enabled platforms. You will collaborate with engineering teams to identify vulnerabilities, automate security gates, and ensure robust remediation of security risks.
What they look for
Requirements
Candidates must have at least 2 years of hands-on experience in DevSecOps, application security, or cloud security. Proficiency in GCP, CI/CD pipelines, and secure coding practices for Python and React applications is required.
Full description
𝗧𝗵𝗶𝘀 𝗿𝗼𝗹𝗲 𝗶𝘀 𝗳𝗼𝗿 𝗼𝗻𝗲 𝗼𝗳 𝘁𝗵𝗲 𝗪𝗲𝗲𝗸𝗱𝗮𝘆'𝘀 𝗰𝗹𝗶𝗲𝗻𝘁𝘀
𝗦𝗮𝗹𝗮𝗿𝘆 𝗿𝗮𝗻𝗴𝗲: 𝗥𝘀 𝟯𝟬𝟬𝟬𝟬𝟬 - 𝗥𝘀 𝟭𝟬𝟬𝟬𝟬𝟬𝟬 (𝗶𝗲 𝗜𝗡𝗥 𝟯-𝟭𝟬 𝗟𝗣𝗔)
Experience: 2+ yrs
Location: Hyderabad, Telangana
Job Type: Full-time
We are looking for a hands-on DevSecOps & Product Security Engineer to embed security across the software development and deployment lifecycle. The role combines application security, API security, cloud security, DevSecOps, CI/CD security, and AI product security across modern SaaS and AI-enabled platforms.
The ideal candidate will work closely with developers, architects, cloud engineers, and product teams to identify security risks, automate security controls, strengthen development and deployment pipelines, and drive vulnerabilities through to effective remediation. This is an engineering-focused security role involving practical implementation and problem-solving rather than a traditional SOC or monitoring position.
Key Responsibilities
- Embed security checks, scanning, and quality gates across the software development lifecycle.
- Review application architecture, authentication, authorization, APIs, tenant isolation, and access-control mechanisms.
- Identify and mitigate OWASP Top 10 and API security risks through threat modelling and secure design practices.
- Partner with developers to identify vulnerabilities and implement practical remediation rather than simply reporting findings.
- Assess AI-powered applications, agents, prompts, connectors, and data-access workflows for security risks.
- Identify and mitigate risks involving prompt injection, data leakage, tool misuse, unauthorized data access, and unsafe AI actions.
- Secure Google Cloud environments, including IAM, service accounts, networking, secrets, and containerized workloads.
- Enforce least-privilege access and appropriate separation between development, testing, and production environments.
- Harden GitHub Actions and CI/CD pipelines through secure configurations, secret protection, dependency management, and release controls.
- Implement and manage SAST, software composition analysis, secret scanning, SBOM generation, and other automated security controls.
- Establish processes to identify, prioritize, track, remediate, and validate security vulnerabilities.
- Analyze security scanner findings, distinguish genuine risks from false positives, and prioritize remediation based on business impact.
- Strengthen security logging, alerting, investigation, and incident-response capabilities.
- Support security incidents, root-cause analysis, security drills, and corrective actions when required.
- Maintain audit-ready security evidence and support penetration testing, compliance activities, and security assessments.
- Contribute to security architecture documentation, standards, policies, and secure development practices.
- Automate repetitive security processes and integrate security controls into engineering workflows.
- Collaborate closely with engineering, architecture, product, and cloud teams to improve overall product security.
- Stay current with emerging cloud, application, DevSecOps, AI/LLM, and product security threats and practices.
What Makes You a Great Fit
- 2+ years of hands-on experience in DevSecOps, application security, product security, cloud security, or a related engineering security role.
- Strong practical understanding of DevSecOps, application security, and API security.
- Good knowledge of OWASP Top 10, common API vulnerabilities, secure coding, authentication, authorization, and access controls.
- Experience securing applications built using technologies such as Python backends and React-based frontends.
- Strong experience with GitHub, GitHub Actions, and CI/CD security.
- Hands-on knowledge of SAST, dependency scanning, secret scanning, SBOM, and secure software supply-chain practices.
- Experience securing Google Cloud Platform (GCP) environments, including IAM, service accounts, least-privilege access, and containerized workloads.
- Ability to analyze security findings, assess real-world risk, and drive vulnerabilities through to resolution.
- Experience with tools such as CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, or Burp Suiteis an advantage.
- Understanding of containers, Kubernetes, Infrastructure-as-Code, and cloud security practices is preferred.
- Exposure to AI/LLM security, AI agents, RAG applications, SaaS integrations, or sensitive data pipelines is highly desirable.
- Familiarity with PostgreSQL, GCP Security Command Center, SIEM, cloud monitoring, or MDR solutions is an advantage.
- Exposure to SOC 2, ISO 27001, penetration testing, or security compliance activities is beneficial.
- Strong scripting and automation mindset with the ability to integrate security controls into engineering workflows.
- Excellent communication skills with the ability to explain complex security risks in clear and practical terms.
- Strong ownership mindset with the ability to work collaboratively with engineering and product teams.
- Curious and proactive approach to emerging AI-driven product security and cloud security challenges.
- Practical hands-on experience and real-world problem-solving ability are highly valued.
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr