Security Engineer - DevSecOps (India)

Security Engineer - DevSecOps (India)

29 Aug
|
Alignity Solutions
|
India

29 Aug

Alignity Solutions

India

As a Security Engineer:

You will

- Integrate, configure, and optimize SAST, SCA, and DAST tools within CI/CD pipelines to automate security testing across build, test, and release stages (including quality gates and exception workflows).
- Perform static, dynamic, and open-source dependency assessments to identify vulnerabilities including OWASP Top 10 risks, insecure libraries, exposed secrets, misconfigurations, and software supply-chain weaknesses.
- Execute API security testing (REST/GraphQL) including authentication/authorization validation (OAuth2/OIDC/JWT), input validation, rate limiting/abuse cases, and broken object/function level authorization (BOLA/BFLA), and translate results into developer-ready fixes.
- Analyze scan results, remove false positives, prioritize findings based on exploitability and business impact, and provide transparent, actionable remediation guidance (secure coding patterns, compensating controls, and verification steps).
- Work hands-on with developers, DevOps engineers, architects, and client stakeholders to embed secure coding, secure design, and shift-left security practices, including playbooks, office hours, and remediation sprints.
- Support threat modeling and security design reviews; convert threats into actionable security requirements, test cases, and engineering backlog items aligned to delivery timelines.
- Track vulnerabilities through closure, validate remediation (re-scan, proof of fix, and regression checks), and ensure issues are managed in line with client policy, risk tolerance, and SLA expectations.
- Implement additional DevSecOps controls such as IaC scanning, secrets detection, container image scanning,



and Kubernetes security checks (where applicable), including policy-as-code to prevent insecure deployments.
- Strengthen software supply-chain security by supporting SBOM generation/consumption, dependency hygiene, and build/release integrity controls (e.g., artifact signing/verification and provenance where applicable).
- Automate repeatable security tasks using scripting (e.g., Python/Bash) and integrations (APIs/webhooks) to improve scan reliability, reporting, and developer workflow adoption.
- Design and build AI agents / agentic workflows for AppSec automation (e.g., triage, false-positive suppression, secure code review assistance, threat-model generation, remediation assistance), ensuring appropriate guardrails, logging, and human-in-the-loop validation.
- Perform current-state assessments of client DevSecOps and emerging AISecOps practices against industry standards; provide prioritized recommendations and an implementation roadmap.
- Perform security testing across modern application surfacescode, APIs, cloud, containers/Kubernetesand, where applicable, AI/ML pipelines (e.g., RAG data flows, model integration points, and tool/function calling) using a combination of automated and manual techniques.
- Produce security assessment reports, dashboards, trend analysis, and root-cause insights for technical and non-technical stakeholders.
- Contribute to secure SDLC standards aligned to recognized verification frameworks such as OWASP ASVS.
- Stay current on emerging threats, AppSec tooling trends, software supply-chain risks, and new attack surfaces introduced by AI-enabled applications and agentic workflows.

📌 Security Engineer - DevSecOps (India)
🏢 Alignity Solutions
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security engineer - devsecops (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: security engineer - devsecops (india) / india