Please share CV to
[email protected] with the below details:
Total Experience- (Should be between 5 to 9 years)
Current CTC-
Expected CTC-
Notice Period-
About the Role
HCL Software is seeking a DevSecOps Engineer to embed security into how our products are built, packaged, and released. We ship software to enterprise customers under contractual and regulatory scrutiny, so the pipeline is not a convenience layer: it is a control surface and an evidence source.
You will build the tooling and automation that lets dozens of product teams meet a consistent security bar without slowing down, and you will own the software supply chain controls that back our customer attestations.
You will work directly with product engineering teams, Product Security, and the Security Architecture function, and success looks like adoption rather than dashboards.
This role is for you if you’re a self-starter who can dive in and immediately start iterating on solutions to large-scale CI/CD and supply chain security problems. You must be able ability to context switch between security analysis, DevOps, and development, and will be expected to collaborate with different teams for each.
The ideal candidate does much more than provision and monitor off-the-shelf tools from commercial vendors. They are comfortable combining FOSS, commercial, and in-house software into complete solutions, writing glue code as necessary, and operationalizing the result across a large and diverse set of environments ranging from legacy to cutting edge and to implement security improvements across them.
Key Responsibilities
Pipeline Security Engineering
- Integrate static analysis, software composition analysis, secrets detection, container scanning, and infrastructure-as-code scanning into CI/CD pipelines across multiple product groups and build/extract out reference architectures for future reuse.
- Tune scanning configuration so findings are accurate and actionable, and drive down false positives that erode developer trust.
- Define and implement policy gates that block genuinely unacceptable risk while allowing documented, time-bound exceptions.
- Support multiple build ecosystems and languages, meeting teams where their toolchain already is.
Software Supply Chain and SBOM
- Automate (CycloneDX) SBOM generation and publication across product builds, and maintain the pipelines that keep them accurate.
- Operate dependency and vulnerability intelligence tooling, mapping disclosed vulnerabilities to affected releases and customers.
- Implement build integrity controls including artifact signing, provenance, reproducibility improvements, and dependency pinning.
- Support supply chain assurance requirements and the evidence needed for tier attestation across product offerings.
Developer Enablement
- Build reusable pipeline templates, shared libraries, and paved-road patterns so teams inherit security controls by default.
- Deliver findings inside developer workflow (pull requests, IDE, chat) rather than in a separate security portal.
- Provide hands-on guidance, office hours, and documentation that helps teams fix issues rather than just triage them.
- Track adoption and remediation metrics by product group and work the gaps directly with engineering leaders.
Compliance and Release Assurance
- Automate collection of release-time security evidence for audit, customer questionnaires, and regulatory reporting.
- Partner with Product Security and PSIRT on vulnerability triage, fix verification, and advisory publication.
- Contribute to secure development lifecycle standards and keep them implementable in real pipelines.
Required Qualifications
- 5+ years in DevSecOps, application security engineering, or platform engineering with direct security ownership.
- Hands-on experience integrating and operating security scanning tooling across CI/CD systems such as GitHub Actions, GitLab CI, Jenkins, or Azure DevOps.
- Robust software engineering fundamentals: you can recognize, write, and maintain production-quality code, not only configuration.
- Working knowledge of software composition analysis, SBOM formats (CycloneDX or SPDX), and dependency risk management.
- Container and Kubernetes security experience, including image hardening and registry controls.
- Cloud platform fluency (AWS, Azure, or GCP) and infrastructure-as-code experience with Terraform or equivalent.
- Ability to influence engineering teams you do not manage, and the judgment to know when a gate helps and when it just gets bypassed.
General Security Expertise:
- In-depth understanding of security concepts, principles, and methodologies
- Familiarity with security standard organizations such as NIST, and OWASP
- Ability to translate security concepts into technical specifications and design decisions
- Proficiency in designing and architecting secure systems
- Familiarity with various design methodologies and tools
- Ability to translate security requirements into architectural diagrams and specifications
- Strong understanding of secure coding concepts and vulnerabilities
- Ability to review code and identify potential security flaws
- Experience implementing security fixes and hardening techniques across diverse codebases
- Familiarity with container security best practices, hardening containers, running containerized applications securely
- Experience with AWS, GCP, and other common cloud platforms, their security models, and suite of security technologies
- Understanding of modern cloud and web threat environments and defensive techniques
- Deep understanding of supply chain security concepts and how they're implemented across the SDLC
- Experience with SCA tooling (such as Mend/Whitesource, Trivy, etc.) and its integration into development processes
- Familiarity with SBOMs, the file formats, tooling, and usage for the same (CycloneDX preferred)
- Excellent communication and interpersonal skills
- Ability to work effectively and asynchronously across multiple teams with wide geographic distribution
- Ability to collaborate effectively with product teams, engineering managers, and security stakeholders
- Strong documentation skills
- Proficiency in common programming languages such as Python, Java, and/or C++ (more the better)
- Strong knowledge of server-side Linux as a deployment environment for both containerized and non-containerized applications
- Working knowledge of Linux security technologies and hardening practices
- Experience with vulnerability assessment, penetration testing, and/or reverse engineering, ability to translate this "red team" work into defensive knowledge
- Knowledge of security automation tools and frameworks
- Experience responding to product security vulnerabilities and other incidents
Preferred Qualifications
- Experience in a product company shipping software to enterprise customers under contractual security obligations.
- Familiarity with supply chain frameworks and standards such as SLSA, SSDF (NIST SP 800-218), and in-toto attestations.
- Experience operating Dependency-Track or comparable dependency intelligence platforms at scale.
- Experience securing AI-assisted development workflows and code generated with AI tooling.
- Certifications valued but not required: CSSLP, GWEB, cloud security certifications, or Kubernetes security credentials.
HCL Software is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
📌 DevSecops Engineer (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru