DevSecOps Engineer
About the Role
We are looking for a hands-on DevSecOps Engineer to own our end-to-end vulnerability management
process and drive security across our cloud-native platform. This is a technical, ownership-heavy role
sitting at the intersection of security engineering and platform engineering.
You will be responsible for identifying, triaging, remediating, and reporting on vulnerabilities across our
Manager to ensure our security posture meets compliance requirements and that risk is understood,
documented, and managed appropriately.
This is not a monitoring-only role. We expect you to roll up your sleeves, open pull requests, fix Dockerfiles,
bump package versions, modify CI/CD pipelines, and own the fix through to deployment and verification.
What You Will Be Doing
Vulnerability Management
- Own the end-to-end vulnerability management lifecycle — discovery, triage, prioritisation, remediation
tracking, and closure
- Manage and maintain the vulnerability backlog, ensuring SLAs are tracked and met
CVE is equally critical in every context
- Produce regular vulnerability reports and risk dashboards for internal stakeholders and the
Compliance Manager
- Document risk acceptance decisions, mitigating controls, and remediation timelines
Vulnerability Remediation
- Remediate vulnerabilities directly — bumping dependency versions in package manifests (npm, pip,
Maven, Go modules etc.), updating base images, fixing misconfigurations
- Update and harden Dockerfiles — base image selection, multi-stage builds, non-root users, mínimal
attack surface
- Work within our Git-based workflow — raise PRs, participate in code review, deploy and verify your own
fixes end to end
1
Container & Application Security
- Integrate and maintain container image scanning in CI/CD pipelines (Trivy, Snyk, Grype or equivalent)
- Integrate Software Composition Analysis (SCA) and Static Application Security Testing (SAST) tooling into
pipelines
- Define and enforce
📌 Cloud Security Engineer (Pune)
🏢 Ensono
📍 Pune