รber diese DevSecOps & Product Security Engineer Stelle bei Weekday AI
๐ง๐ต๐ถ๐ ๐ฟ๐ผ๐น๐ฒ ๐ถ๐ ๐ณ๐ผ๐ฟ ๐ผ๐ป๐ฒ ๐ผ๐ณ ๐๐ต๐ฒ ๐ช๐ฒ๐ฒ๐ธ๐ฑ๐ฎ๐'๐ ๐ฐ๐น๐ถ๐ฒ๐ป๐๐
๐ฆ๐ฎ๐น๐ฎ๐ฟ๐ ๐ฟ๐ฎ๐ป๐ด๐ฒ: ๐ฅ๐ ๐ฏ๐ฌ๐ฌ๐ฌ๐ฌ๐ฌ - ๐ฅ๐ ๐ญ๐ฌ๐ฌ๐ฌ๐ฌ๐ฌ๐ฌ (๐ถ๐ฒ ๐๐ก๐ฅ ๐ฏ-๐ญ๐ฌ ๐๐ฃ๐)
Experience: 2+ yrs
Location: Hyderabad, Telangana
Job Type: Full-time
We are looking for a hands-onย DevSecOps & Product Security Engineerย to embed security across the software development and deployment lifecycle. The role combinesย application security, API security, cloud security, DevSecOps, CI/CD security, and AI product securityย across modern SaaS and AI-enabled platforms.
The ideal candidate will work closely with developers, architects, cloud engineers, and product teams to identify security risks, automate security controls, strengthen development and deployment pipelines, and drive vulnerabilities through to effective remediation. This is an engineering-focused security role involving practical implementation and problem-solving rather than a traditional SOC or monitoring position.
Requirements
Key Responsibilities
- Embed security checks, scanning, and quality gates across theย software development lifecycle.
- Review application architecture, authentication, authorization, APIs, tenant isolation, and access-control mechanisms.
- Identify and mitigateย OWASP Top 10 and API security risksย through threat modelling and secure design practices.
- Partner with developers to identify vulnerabilities and implement practical remediation rather than simply reporting findings.
- Assess AI-powered applications, agents, prompts, connectors, and data-access workflows for security risks.
- Identify and mitigate risks involvingย prompt injection, data leakage, tool misuse, unauthorized data access, and unsafe AI actions.
- Secure Google Cloud environments, includingย IAM, service accounts, networking, secrets, and containerized workloads.
- Enforce least-privilege access and appropriate separation between development, testing, and production environments.
- Hardenย GitHub Actions and CI/CD pipelinesย through secure configurations, secret protection, dependency management, and release controls.
- Implement and manage SAST, software composition analysis, secret scanning, SBOM generation, and other automated security controls.
- Establish processes to identify, prioritize, track, remediate, and validate security vulnerabilities.
- Analyze security scanner findings, distinguish genuine risks from false positives, and prioritize remediation based on business impact.
- Strengthen security logging, alerting, investigation, and incident-response capabilities.
- Support security incidents, root-cause analysis, security drills, and corrective actions when required.
- Maintain audit-ready security evidence and support penetration testing, compliance activities, and security assessments.
- Contribute to security architecture documentation, standards, policies, and secure development practices.
- Automate repetitive security processes and integrate security controls into engineering workflows.
- Collaborate closely with engineering, architecture, product, and cloud teams to improve overall product security.
- Stay current with emergingย cloud, application, DevSecOps, AI/LLM, and product security threats and practices.
What Makes You a Great Fit
- 2+ years of hands-on experienceย in DevSecOps, application security, product security, cloud security, or a related engineering security role.
- Strong practical understanding ofย DevSecOps, application security, and API security.
- Good knowledge ofย OWASP Top 10, common API vulnerabilities, secure coding, authentication, authorization, and access controls.
- Experience securing applications built using technologies such asย Python backends and React-based frontends.
- Strong experience withย GitHub, GitHub Actions, and CI/CD security.
- Hands-on knowledge of SAST, dependency scanning, secret scanning, SBOM, and secure software supply-chain practices.
- Experience securingย Google Cloud Platform (GCP)ย environments, including IAM, service accounts, least-privilege access, and containerized workloads.
- Ability to analyze security findings, assess real-world risk, and drive vulnerabilities through to resolution.
- Experience with tools such asย CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, or Burp Suiteis an advantage.
- Understanding of containers, Kubernetes, Infrastructure-as-Code, and cloud security practices is preferred.
- Exposure toย AI/LLM security, AI agents, RAG applications, SaaS integrations, or sensitive data pipelinesย is highly desirable.
- Familiarity with PostgreSQL, GCP Security Command Center, SIEM, cloud monitoring, or MDR solutions is an advantage.
- Exposure toย SOC 2, ISO 27001, penetration testing, or security compliance activities is beneficial.
- Strong scripting and automation mindset with the ability to integrate security controls into engineering workflows.
- Excellent communication skills with the ability to explain complex security risks in clear and practical terms.
- Strong ownership mindset with the ability to work collaboratively with engineering and product teams.
- Curious and proactive approach to emergingย AI-driven product security and cloud security challenges.
- Practical hands-on experience and real-world problem-solving ability are highly valued.