DevSecOps Lead Engineer / Application Security Lead Engineer (Chennai)

DevSecOps Lead Engineer / Application Security Lead Engineer (Chennai)

24 Sep
|
Novacis Innovations
|
Chennai

24 Sep

Novacis Innovations

Chennai

– DevSecOps Lead Engineer/ Application Security Engineer

About Us

Novacis Digital Private Limited is a US Based product-based technology company headquartered in Atlanta, GA with its Global R&D; center at IIT Madras Research Park, a hub for cutting-edge innovation. We specialize in building AI-powered digital products and analytics-driven solutions that solve real-world problems.

Our leadership team brings over 100+ years of global experience delivering scalable technology platforms and innovation labs for US Federal & State Government and Fortune 500 companies. We are enthusiastic about fostering a culture where technologists thrive by building smart, secure, and scalable products with real impact.

We are currently working on next-generation LLM based systems based on AI first principles for intelligent document processing, dynamic workflow orchestration, AI copilots, enterprise data analytics, Convolutional LLM application and natural language analytics.

Role – DevSecOps Lead Engineer/ Application Security Engineer

Experience: 7-9 Years

About the Role

We are looking for an experienced DevSecOps Lead Engineer/ Application Security Engineer to design, implement, and optimize secure cloud-native infrastructure and DevSecOps practices across our products and platforms. In this role, you will work closely with Engineering, Cloud, DevOps, and Security teams to embed security throughout the software development lifecycle and ensure scalable, resilient, and compliant cloud environments.

You will be responsible for designing secure cloud architectures, automating infrastructure and security controls, integrating security into CI/CD pipelines, implementing cloud security best practices, and driving DevSecOps maturity across AWS and Azure environments.

Required Skills

•Minimum of 7–9 years of overall IT experience with 5+ years of hands-on DevSecOps experience.

•Hands-on experience with Terraform, Jenkins, GitHub Actions, Ansible, Packer, and CI/CD automation.

•Expertise in SAST, DAST, SCA, OWASP Top 10, IAM, Zero Trust Architecture, and secure application design.

•Proficiency in Python and Bash scripting for infrastructure automation and security orchestration.

•Experience with Qualys or other vulnerability management and compliance management tools.

•Strong understanding of Infrastructure as Code (IaC), cloud governance, compliance, and security automation.

•Proven experience in leading DevSecOps initiatives, mentoring teams,



and collaborating with cross-functional stakeholders.

Key Responsibilities

CI/CD & Security Automation

•Design and secure CI/CD pipelines by integrating security controls such as: SAST, DAST, SCA, Secret scanning, Container image scanning, Infrastructure as Code (IaC) scanning.

•Implement automated security gates within deployment pipelines to ensure vulnerabilities are identified and remediated before production releases.

•Build and maintain Infrastructure as Code (Terraform) and automate provisioning using modern DevOps practices.

Container & Platform Security

•Secure Kubernetes clusters, Docker containers, container registries, and orchestration platforms using industry best practices.

•Ensure secure software supply chain practices, including image signing, artifact integrity, and dependency management.

Vulnerability & Risk Management

•Lead enterprise vulnerability management by identifying, prioritizing, tracking, and driving remediation of infrastructure, application, container, and cloud vulnerabilities.

•Coordinate security assessments, penetration testing, and remediation activities with development and infrastructure teams.

•Establish patch management, risk prioritization, and continuous security monitoring processes.

Compliance & Governance

•Support compliance initiatives such as ISO 27001, SOC 2, GDPR, and customer security requirements.

•Develop security policies, standards, technical controls, and implementation guidelines.

•Automate compliance validation and evidence collection wherever possible.

Monitoring & Incident Response

•Implement cloud security monitoring, threat detection, logging, and alerting using cloud-native and third-party security tools.

•Develop dashboards, KPIs, and executive reports to measure security posture, vulnerability trends, compliance status, and operational effectiveness.

•Participate in security incident response, root cause analysis, and post-incident remediation activities.

Innovation & Continuous Improvement

•Evaluate emerging DevSecOps technologies,



cloud security platforms, and automation tools to improve operational efficiency and reduce security risk.

•Drive continuous improvement initiatives by adopting industry best practices, security frameworks, and automation strategies.

Positive to Have:

DevSecOps Strategy & Leadership

•Lead the design, implementation, and continuous improvement of DevSecOps practices across the Secure Software Development Lifecycle (SSDLC).

•Define and drive the organization's DevSecOps strategy, security standards, and engineering best practices to enable secure-by-design product development.

•Mentor DevOps engineers and development teams on secure coding, cloud security, and security automation, fostering a security-first culture.

Cloud Security

•Design, implement, and maintain secure, scalable, and highly available cloud architectures on AWS and Azure.

•Implement and manage CSPM, CWPP platforms such as Wiz (or equivalent) to continuously assess and improve cloud security posture.

•Establish cloud governance, identity management, encryption, logging, monitoring, and network segmentation based on Zero Trust principles.

•Ensure secure configuration of cloud resources, including IAM, VPCs/VNETs, storage, compute, networking, and managed services.

Preferred Qualifications

•5+ years of experience with SAST, DAST, SCA, Secret scanning, Container image scanning, Infrastructure as Code (IaC) scanning.

•5+ years of experience with Terraform, Python automation, Ansible/Packer/GitHub Actions, and vulnerability management tools.

•Proven experience designing scalable, secure, and compliant cloud infrastructure while embedding security into the software development lifecycle.

What We Offer

•Cutting-Edge Technologies: Work on cloud-native platforms, AI/ML environments, and modern DevSecOps ecosystems using the latest tools and technologies.

•Collaborative Environment: Partner with Architects, Product Managers, Engineering Teams, and Technology Managers to deliver secure, scalable solutions.

•Career Growth: Continuous learning, certifications, mentorship, and opportunities to work on enterprise-scale cloud security initiatives in MLSecOps (Machine Learning Security Operations)

•Comprehensive Benefits: Competitive salary, health insurance, flexible work arrangements, and a supportive environment that promotes work-life balance and professional development

📌 DevSecOps Lead Engineer / Application Security Lead Engineer (Chennai)
🏢 Novacis Innovations
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: devsecops lead engineer / application security lead engineer (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: devsecops lead engineer / application security lead engineer (chennai) / chennai