747,216open jobs
44,882companies
108,129added this week
Browse all
Salary
≈ $33k – $79k per year (Estimated)
Location
In office (Pune)
Seniority
Staff · 5+ years exp

Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 24, 2026.

Overview
Company
Impact
Profile match

HMH

HMH is an educational company that specializes in providing comprehensive curriculum and assessment solutions across a wide spectrum of subjects. They offer programs and resources for literacy, mathematics, science, social studies, and social-emotional learning for K-12 students. Additionally, HMH focuses on professional development for educators to enhance instructional strategies and improve student outcomes.

HMH is a learning technology company committed to delivering connected solutions that engage learners, empower educators and improve student outcomes. As a leading provider of K-12 core curriculum, supplemental and intervention solutions, and professional learning services, HMH partners with educators and school districts to uncover solutions that unlock students’ potential and extend teachers’ capabilities.

HMH serves more than 50 million students and 4 million educators in 150 countries. For more information, visit www.hmhco.com

Join our Information Security team as a Staff Security Engineer with approximately 5-8 years of hands-on experience in cloud security, application security, DevSecOps, vulnerability management, and security automation. This role will help protect our cloud and on-premises environments and support the organization’s GovRAMP security and compliance program.

Responsibilities include implementing and monitoring cloud security controls, managing vulnerabilities and security alerts, supporting GovRAMP/NIST 800-53 controls, SSP, POA&M, evidence collection, continuous monitoring, and assessments, and driving remediation activities. The role will partner with Engineering, DevOps, Architecture, Risk, and Compliance teams to integrate security into applications, CI/CD, cloud infrastructure, and data platforms.

The ideal candidate is a hands-on security professional experienced in cloud security, DevSecOps, automation, security monitoring, and compliance, with an ability to leverage modern cloud-native technologies and AI initiatives to strengthen security and enable business innovation.

Why Join Us:

At HMH, you will have the opportunity to strengthen cloud security and support GovRAMP initiatives while working with modern AWS and Azure technologies. You will collaborate with Engineering, DevOps, Architecture, Risk, and Compliance teams to protect critical applications and data, automate security processes, and drive meaningful improvements across the enterprise.

We foster a security-first, collaborative, and innovative environment that encourages continuous learning and professional growth. If you are passionate about cloud security, DevSecOps, automation, AI-driven security, and helping organizations securely scale in the cloud, we invite you to join us on our digital transformation journey.

Duties & Responsibilities include:

  • Perform application security assessments using SAST, DAST, SCA, and manual testing.
  • Identify, prioritize, track, and remediate application security vulnerabilities and findings.
  • Conduct secure code reviews, threat modeling, and security design reviews for applications and new features.
  • Perform web application and API security testing aligned with OWASP Top 10 and API Security practices.
  • Integrate security controls and testing into CI/CD pipelines and the SDLC.
  • Partner with engineering teams to implement secure coding practices and provide remediation guidance.
  • Support vulnerability triage, risk assessment, remediation, exceptions, and penetration-test findings.
  • Develop and maintain application security standards, guidelines, procedures, and documentation.
  • Support GovRAMP/NIST 800-53 control implementation, evidence collection, continuous monitoring, remediation tracking, and assessment readiness.
  • Provide security guidance and awareness to developers and engineering teams.
  • Plan, implement, and track initiatives that strengthen application security across the SDLC and GovRAMP compliance requirements.

Required Skills:

  • Hands-on experience with AWS and/or comparable cloud environments, including designing, implementing, and securing cloud and hybrid environments.
  • Approximately 5 years of experience in Application Security, Product Security, or a related security engineering role.
  • Strong understanding of OWASP Top 10, OWASP API Security, CWE, and common application vulnerabilities.
  • Hands-on experience with SAST, DAST, SCA, vulnerability management, and application security testing tools.
  • Experience testing web applications, REST APIs, and microservices, including authentication, authorization, session management, encryption, and secure API design.
  • Experience with Burp Suite or similar security testing tools and secure code review practices.
  • Knowledge of CI/CD and DevSecOps, including integrating security testing and controls into development pipelines.
  • Working knowledge of cloud security and applicable security frameworks, such as NIST, ISO 27001, SOC 2, GDPR, HIPAA, or PCI DSS.
  • Experience supporting GovRAMP/NIST 800-53 security controls, including control implementation, evidence collection, continuous monitoring, assessment support, and remediation tracking.
  • Hands-on scripting/programming experience with Python, Java, JavaScript, PowerShell, or similar languages.
  • Ability to analyze security findings, validate vulnerabilities, reduce false positives, prioritize risks, and communicate remediation recommendations effectively.
  • Strong communication and collaboration skills with developers, architects, DevOps, security, risk, and compliance teams.

Preferred Qualifications:

  • Hands-on experience securing AWS, Azure, or other enterprise cloud environments, including cloud-native services and hybrid architectures.
  • Experience supporting GovRAMP/NIST 800-53 initiatives, including security assessments, control evidence, continuous monitoring, and remediation activities.
  • Experience with threat modeling, security architecture reviews, and secure design practices for cloud applications and platforms.
  • Knowledge of container and Kubernetes security, including image security, runtime controls, and workload protection.
  • Experience with penetration testing, vulnerability assessments, or bug bounty programs.
  • Experience automating security processes using Python, PowerShell, or similar scripting languages.
  • Familiarity with DevSecOps and cloud security automation, including security controls integrated into CI/CD pipelines.
  • Relevant security certifications such as Security+, CEH, OSCP, CSSLP, or equivalent is advantageous.

The Information Technology organization is transforming to realize our mission: Become a leader in HMH’s digital transformation, and as a strategic partner, innovate and deliver highest value, competitive advantage solutions across all corporate and business functions. Our ambition is to be a digital leader through innovation and develop and deliver leading edge technology such as robotic process automation and artificial intelligence to solve some of HMH’s greatest operational business challenges. Our professionals will have business relevant skills to connect our HMH partners to technologies that propel the businesses to deliver the greatest value for HMH and our customers.

We are building a team of IT professionals with an insatiable appetite to learn, a relentless focus on customer service, a technological curiosity toward future possibilities, and a creativity in solving business challenges with leading technologies. Our team will find ways to work together, create a sense of community where it’s safe to take risks and learn together, develop our careers, and all have an opportunity to work on new technologies. We will work together, learn together and have fun together. As a team, we will lead HMH’s digital transformation.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
747,216 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Pune
≈ $30k – $76k per year (Estimated) • Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • Pune
Python
PowerShell
YARA
AI/ML
Copilot
Embeddings
AI Agents
LLM
RAG
Red Teaming
Agentic Workflows
DevOps
Splunk
Azure
AWS
Kubernetes
TCP/IP
DNS
Cybersecurity
Crowdstrike
Snort
Falco
Suricata
YARA
SentinelOne
MITRE ATT&CK
OWASP Top 10
Diamond Model
Tanium
Microsoft Entra ID
Active Directory
SIEM
Apply
≈ $28k – $63k per year (Estimated) • In office • 6+ years exp • Pune
DevOps
VPN
Cybersecurity
FortiGate
Apply
≈ $29k – $74k per year (Estimated) • In office • 8+ years exp • Pune
DevOps
Splunk
SLI/SLO/SLA
Cybersecurity
Microsoft Sentinel
MITRE ATT&CK
IBM QRadar
Google SecOps
SIEM
Apply
≈ $28k – $62k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
Python
Ruby
PowerShell
Perl
Databases
MySQL
Db2
Oracle
Cassandra
MS SQL
AI/ML
Hadoop
Spark
Apache TVM
DevOps
Splunk
Azure
CI/CD
AWS
Linux
Windows
Unix
TCP/IP
DNS
Cybersecurity
Qualys Cloud Platform
ISO 27001
MITRE ATT&CK
NIST CSF
CIS Benchmarks
CVSS
Exabeam
PKI
SIEM
DLP
OWASP
IoT
Matter
Management
Agile
Apply
≈ $33k – $73k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • High School Diploma • Bengaluru
Python
PowerShell
DevOps
Rest API
Splunk
Terraform
GCP
Azure
CI/CD
AWS
IAM
Cybersecurity
Okta
Crowdstrike
CyberArk
Qualys Cloud Platform
Zero Trust
Microsoft Entra ID
Active Directory
LDAP
Management
ServiceNow
Apply
≈ $32k – $70k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Pune
JavaScript
TypeScript
SQL
PowerShell
Node JS
Apex
Node JS
Electron
Databases
SQLite
Frontend
Angular
Mobile
Ionic
Capacitor
Cordova
DevOps
Rest API
Azure DevOps
Azure
Git
Bitbucket
Windows
Apache HTTP Server
Management
UML
QA
Playwright
Apply
Software Engineer 12 hours ago
Hybrid • Full-Time • Bachelor's Degree • Bayan Lepas
Python
JavaScript
SQL
C#
C#
ASP.NET Core
WPF
Mobile
MVVM
Apply
In office • 15+ years exp • Bachelor's Degree • Hyderabad
Python
Go
JavaScript
Java
SQL
Ruby
Node JS
Python
Flask
Django
Java
Spring Boot
DevOps
GCP
CircleCI
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
AWS Lambda
Amazon EC2
GitLab
Amazon S3
Management
Trello
Jira
Agile
Scrum
Kanban
Apply
≈ $31k – $82k per year (Estimated) • Hybrid • Contractor • Sofia
Go
JavaScript
Databases
PostgreSQL
RabbitMQ
Apache Kafka
Frontend
npm
DevOps
CI/CD
Kubernetes
JFrog Artifactory
Apply
≈ $21k – $57k per year (Estimated) • In office • Moscow
Java
Databases
PostgreSQL
Apache Kafka
DevOps
Rest API
CI/CD
Apply
Sr InfoSec Engineer 21 day ago
≈ $30k – $67k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Pune
Python
Java
PowerShell
DevOps
Terraform
Azure
CI/CD
AWS
Docker
Kubernetes
Amazon S3
IAM
Cybersecurity
ISO 27001
PCI DSS
SOC 2
GDPR
HIPAA
Least Privilege
Threat Modeling
SIEM
Management
Agile
Apply
≈ $39k – $87k per year (Estimated) • In office • 8+ years exp
JavaScript
Java
Node JS
Node JS
Express
Databases
MySQL
PostgreSQL
DynamoDB
InfluxDB
ElasticSearch
Amazon Aurora
AI/ML
AI Agents
AWS Bedrock
Frontend
GraphQL
React.js
DevOps
Terraform
GitHub Actions
Kibana
OpenTelemetry
CloudFormation
Datadog
Logstash
Prometheus
CI/CD
AWS
Docker
Kubernetes
Grafana
Platform Engineering
Chaos Engineering
Amazon EC2
FinOps
GitHub
IAM
Linux
Robotics
Apollo
Management
Agile
Apply
≈ $40k – $85k per year (Estimated) • In office • 10+ years exp • Bachelor's Degree • Pune
JavaScript
Java
SQL
Scala
Java
Maven
Spring Boot
Flyway
Liquibase
Databases
MySQL
PostgreSQL
Redis
Cassandra
Apache Kafka
Amazon Redshift
Amazon Aurora
AI/ML
Copilot
Windsurf
Spark
AI Agents
OpenAI Codex
Edge AI
DevOps
Rest API
Splunk
Datadog
Azure
Jenkins
AWS
Docker
Kubernetes
Concourse
GitHub
Amazon Kinesis
Management
Jira
Agile
QA
Gatling
Apply
≈ $23k – $60k per year (Estimated) • In office • 3+ years exp • Pune
Management
Confluence
Smartsheet
Jira
Agile
Apply
Financial Analyst 3 days ago
≈ $11k – $28k per year (Estimated) • In office • Bachelor's Degree • Pune
Analytics
Power BI
Microsoft Excel
Apply
In office • Full-Time • Bachelor's Degree • Pune
DevOps
Splunk
Incident Management
SLI/SLO/SLA
IAM
Windows
Cybersecurity
CyberArk
Apply
Principle Accountant 12 hours ago
≈ $24k – $53k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Pune
Management
Microsoft Office
Apply
≈ $32k – $70k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Pune
JavaScript
TypeScript
SQL
PowerShell
Node JS
Apex
Node JS
Electron
Databases
SQLite
Frontend
Angular
Mobile
Ionic
Capacitor
Cordova
DevOps
Rest API
Azure DevOps
Azure
Git
Bitbucket
Windows
Apache HTTP Server
Management
UML
QA
Playwright
Apply
≈ $23k – $53k per year (Estimated) • Equity • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Pune
Apply
≈ $24k – $49k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Pune
Mobile
Lottie
Design
Adobe Photoshop
Figma
Adobe After Effects
Zeplin
FigJam
Management
Miro
Agile
Apply
See all jobs
This is one of many
747,216 more open roles from verified company boards, updated every day.