Director, DevSecOps (AI-First) (Bengaluru)

Director, DevSecOps (AI-First) (Bengaluru)

22 Aug
|
Jupiter
|
Bengaluru

22 Aug

Jupiter

Bengaluru

If you've spent the last decade building platform and security in fast-moving product companies, and lately found yourself thinking"most of what my team does could be an agent"— this is the role.

The tension we're hiring you to resolve

Jupiter is a regulated fintech. ~370 repos, ~50 engineers, live money moving 24×7, RBI-supervised partnerships (CSB, Federal), PCI-DSS card issuance, DPDP obligations, a multi-cloud AWS + OCI estate, dozens of Account Aggregator and bureau integrations. Under normal physics, you'd staff this surface with a 15-person platform team plus a 15-person AppSec org — the size of our entire engineering team.

We don't want either.

We already run one of the most AI-augmented pipelines in Indian fi ntech — our internal agent

Jarvis ships real code, triages alerts, and reviews PRs across the whole estate every day. Our engineers move fast because the paved road is intelligent. We want the same for platform and security together. That's your job.

What "AI-first DevSecOps" means at Jupiter

Not "we bought a Copilot license.

- " It means: Deployment orchestration, capacity planning, incident triage, CVE work, threat modeling, IaC review, cost anomaly detection — all designed as agent loops first, human-supervised and continuously improved
- Every "senior SRE would have caught this rollback" and every "senior AppSec would have caught this XSS" becomes a repeatable, evaluated agent check — codified, not tribal
- Deploy latency, incident MTTR, security-review latency, unit cost per transaction —metrics you drive down quarterly, not queues you defend
- Auditors and partners get automated evidence packs, not spreadsheet marathons

What you'll actually own Platform / DevOps

- The paved road for shipping: CI/CD, Spinnaker deploy pipelines, build systems, feature flags, release gates
- Cloud + Kubernetes across a multi-cloud estate (AWS + OCI, multiple accounts); IaC (Terraform +Terragrunt for cloud, Helm 3 + Kustomize for K8s) as the source of truth
- Observability platform: logs, metrics, traces, alerting as a product engineers want to use
- SRE practice: on-call, incident command, error budgets, capacity + cost engineering
- Developer experience: local dev,



preview environments, secrets provisioning, self-serve infra

Security

- AppSec paved road: SAST / DAST / SBOM / secret-scan / IaC scan/dependency CVE triage —as PR checks that don't get routed around
- Cloud + K8s security posture; IAM boundaries, network segmentation for partner integrations
- Threat modeling on every current service touching money, PII, or a partner API
- Incident response: detection, containment, forensics, post-mortems
- RBI cyber framework, PCI-DSS, DPDP — as artifacts your pipelines emit, not documents your team writes; future-ready for ISO 27001 / SOC 2 when we choose to pursue them
- Direct interface with banking partners and regulators on our security + reliability posture

Experience & background we're looking for

- Non-negotiable 15+ years total in software engineering, of which 8+ years hands-on across DevOps / Platform / SRE and Application / Cloud Security (real depth in both — not "managed a team that did it")
- 6+ years leading engineering teams, at least 2 as second-line (managing managers or senior ICs)
- 3+ years in a regulated industry — fintech, banking, healthtech, or an equivalent audit-heavyenvironment. You've been through at least one RBI / PCI-DSS (or equivalent) audit as an owner, not a bystander. SOC 2 / ISO 27001 experience is a plus.
- Deep AWS + Kubernetes production experience (multi-account, IAM, VPC, EKS, IaC via Terraform / Terragrunt + Helm / Kustomize). OCI experience is a plus.
- Hands-on with modern LLM tooling (Claude / GPT / agentic frameworks) for real engineering work — you've shipped or heavily used AI dev tools in the last 12 months, not just experimented
- Can read Kotlin, Scala, and TypeScript comfortably; write Python fluently

Strong plus





- Previously built the DevSecOps function at an Indian fintech under RBI supervision
- Ran incident command for a Sev-1 that touched customer money — and led the post-mortem
- Public work: OSS contributions to security or platform tooling, conference talks, technical blog with depth
- Certifications: CISSP / CCSP / OSCP (security), CKA / CKS (Kubernetes), AWS Security Specialty nice signals but we care about what you've shipped, not what you've certified
- History of hiring and retaining strong ICs (references we can call)

Explicit non-requirements

- MBA / management degree — irrelevant here
- Big-Tech (FAANG) tenure — nice signal, not required; we've seen more Jupiter-fit talent from product startups than from BigCo
- Prior "Director" title — if you're a Principal / Staff who's been operating at Director scope, apply

You know it's you if…

- You've shipped platform tooling and security tooling that engineers didn't route around both
- You can read Kotlin, Scala, and TypeScript, and you write Python without thinking about it
- You've owned an on-call rota you'd want to be on
- You've been hands-on with Claude / GPT / agentic frameworks for real work — not just chat
- You've run platform or security in a regulated environment and know what a real audit feels like
- You believe the future infra + security leader is 30% engineer, 30% agent-builder, 40% coach —and you're excited about the middle 30%

You should probably skip this if…

- You want to lead a large team from day one (small strong team, senior-IC-heavy, is by design)
- You prefer governance to building
- You're skeptical that agents can do meaningful platform or security work — we'd rather hire someone who's already proven it to themselves
- You want to specialize in only one side (only Sec, only DevOps) — the whole point of this role is one strong leader across both

The offer

- Reports directly to the President.
- Board-level visibility on infra + security posture.
- Small strong team, budget to build (tooling, agents, headcount as we scale).
- Bangalore, work from office.
- Comp calibrated to senior director / VP band at leading Indian fintechs.

📌 Director, DevSecOps (AI-First) (Bengaluru)
🏢 Jupiter
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: director, devsecops (ai-first) (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: director, devsecops (ai-first) (bengaluru) / bengaluru