683,639open jobs
39,571companies
98,002added this week
Browse all
Location
In office (Hyderabad)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Weekday is an Indian recruitment company that sources software engineers through referrals from other engineers rather than through job advertisements or agency databases. Its model pays working engineers to vouch for former colleagues they rate, turning informal knowledge about who is genuinely good into a searchable candidate pool that companies can hire from. Based in Bengaluru and backed by Y Combinator, the platform has layered AI screening and outbound sourcing on top of that referral network, and sells to startups and technology companies hiring in the Indian market.

'

: - ( - )

Experience: 2+ yrs

Location: Hyderabad, Telangana

Job Type: Full-time

We are looking for a hands-on DevSecOps & Product Security Engineer to embed security across the software development and deployment lifecycle. The role combines application security, API security, cloud security, DevSecOps, CI/CD security, and AI product security across modern SaaS and AI-enabled platforms.

The ideal candidate will work closely with developers, architects, cloud engineers, and product teams to identify security risks, automate security controls, strengthen development and deployment pipelines, and drive vulnerabilities through to effective remediation. This is an engineering-focused security role involving practical implementation and problem-solving rather than a traditional SOC or monitoring position.

Requirements

Key Responsibilities

  • Embed security checks, scanning, and quality gates across the software development lifecycle.
  • Review application architecture, authentication, authorization, APIs, tenant isolation, and access-control mechanisms.
  • Identify and mitigate OWASP Top 10 and API security risks through threat modelling and secure design practices.
  • Partner with developers to identify vulnerabilities and implement practical remediation rather than simply reporting findings.
  • Assess AI-powered applications, agents, prompts, connectors, and data-access workflows for security risks.
  • Identify and mitigate risks involving prompt injection, data leakage, tool misuse, unauthorized data access, and unsafe AI actions.
  • Secure Google Cloud environments, including IAM, service accounts, networking, secrets, and containerized workloads.
  • Enforce least-privilege access and appropriate separation between development, testing, and production environments.
  • Harden GitHub Actions and CI/CD pipelines through secure configurations, secret protection, dependency management, and release controls.
  • Implement and manage SAST, software composition analysis, secret scanning, SBOM generation, and other automated security controls.
  • Establish processes to identify, prioritize, track, remediate, and validate security vulnerabilities.
  • Analyze security scanner findings, distinguish genuine risks from false positives, and prioritize remediation based on business impact.
  • Strengthen security logging, alerting, investigation, and incident-response capabilities.
  • Support security incidents, root-cause analysis, security drills, and corrective actions when required.
  • Maintain audit-ready security evidence and support penetration testing, compliance activities, and security assessments.
  • Contribute to security architecture documentation, standards, policies, and secure development practices.
  • Automate repetitive security processes and integrate security controls into engineering workflows.
  • Collaborate closely with engineering, architecture, product, and cloud teams to improve overall product security.
  • Stay current with emerging cloud, application, DevSecOps, AI/LLM, and product security threats and practices.

What Makes You a Great Fit

  • 2+ years of hands-on experience in DevSecOps, application security, product security, cloud security, or a related engineering security role.
  • Strong practical understanding of DevSecOps, application security, and API security.
  • Good knowledge of OWASP Top 10, common API vulnerabilities, secure coding, authentication, authorization, and access controls.
  • Experience securing applications built using technologies such as Python backends and React-based frontends.
  • Strong experience with GitHub, GitHub Actions, and CI/CD security.
  • Hands-on knowledge of SAST, dependency scanning, secret scanning, SBOM, and secure software supply-chain practices.
  • Experience securing Google Cloud Platform (GCP) environments, including IAM, service accounts, least-privilege access, and containerized workloads.
  • Ability to analyze security findings, assess real-world risk, and drive vulnerabilities through to resolution.
  • Experience with tools such as CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, or Burp Suite is an advantage.
  • Understanding of containers, Kubernetes, Infrastructure-as-Code, and cloud security practices is preferred.
  • Exposure to AI/LLM security, AI agents, RAG applications, SaaS integrations, or sensitive data pipelines is highly desirable.
  • Familiarity with PostgreSQL, GCP Security Command Center, SIEM, cloud monitoring, or MDR solutions is an advantage.
  • Exposure to SOC 2, ISO 27001, penetration testing, or security compliance activities is beneficial.
  • Strong scripting and automation mindset with the ability to integrate security controls into engineering workflows.
  • Excellent communication skills with the ability to explain complex security risks in clear and practical terms.
  • Strong ownership mindset with the ability to work collaboratively with engineering and product teams.
  • Curious and proactive approach to emerging AI-driven product security and cloud security challenges.
  • Practical hands-on experience and real-world problem-solving ability are highly valued.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
683,639 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hyderabad
GCP Data Engineer 2 hours ago
In office • Full-Time • 6+ years exp • Delhi
Python
SQL
Databases
Google BigQuery
BigQuery
AI/ML
Airflow
DevOps
Terraform
GCP
CI/CD
Git
Google Cloud Run
Analytics
ETL/ELT
Dimensional Modeling
Apply
Backend Engineer 2 hours ago
In office • Full-Time • 2+ years exp • Gurgaon
Python
SQL
AI/ML
Embeddings
Prompt Engineering
AI Agents
NLP
RAG
Recommender Systems
DevOps
Vector
Management
WhatsApp
Apply
Manager 2 hours ago
In office • Full-Time • 4+ years exp • Gurgaon
Python
C++
C++
CMake
DevOps
Git
Apply
$35k – $91k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru
Python
Databases
PostgreSQL
Weaviate
Milvus
pgvector
Pinecone
AI/ML
LangGraph
LangChain
Embeddings
Prompt Engineering
NLP
LLM
RAG
Hugging Face
Recommender Systems
Agentic Workflows
Apply
Lead Engineer 2 hours ago
$39k – $90k per year (Estimated) • Remote • Full-Time • 7+ years exp
JavaScript
Java
TypeScript
Node JS
AI/ML
Model Context Protocol
Function Calling
AI Agents
LLM
Tool Use
DevOps
Rest API
CI/CD
Git
AWS
AWS Lambda
Amazon CloudWatch
API Gateway
QA
Swagger
Apply
Remote • Full-Time • 6+ years exp
JavaScript
SQL
AI/ML
Agentforce
Frontend
D3.js
Analytics
Tableau
Apply
Salesforce Engineer 2 hours ago
Remote • Full-Time • 5+ years exp
SQL
Apex
Apex
Lightning Web Components
Gearset
Copado
Analytics
Tableau
Power BI
Fivetran
Apply
QA Tester 2 hours ago
$20k – $55k per year (Estimated) • In office • Full-Time • 1+ year exp • Bengaluru
SQL
Management
Agile
Scrum
QA
Postman
Apply
$47k – $100k per year (Estimated) • In office • Full-Time • 11+ years exp • Bengaluru
DevOps
CI/CD
Management
Agile
Apply
Manager 2 hours ago
In office • Full-Time • 4+ years exp • Gurgaon
Python
C++
C++
CMake
DevOps
Git
Apply
$30k – $83k per year (Estimated) • Remote/Hybrid • 2+ years exp • Hyderabad
AI/ML
AI Agents
Cybersecurity
GDPR
Analytics
Microsoft Excel
Apply
In office • Full-Time • Hyderabad
Python
Perl
AI/ML
Copilot
AI Agents
Chips/EDA
Cadence Virtuoso
Cadence Xcelium
Synopsys StarRC
Cadence Quantus
Synopsys PrimeSim
Synopsys FineSim
Synopsys Custom Compiler
Apply
$30k – $70k per year (Estimated) • In office • Full-Time • Hyderabad
Java
TypeScript
DevOps
GitHub Actions
CI/CD
QA
Selenium
Playwright
Apply
$59k – $120k per year (Estimated) • In office • Full-Time • Hyderabad
Python
JavaScript
Java
TypeScript
SQL
Node JS
Databases
ClickHouse
ElasticSearch
Apache Kafka
OpenSearch
Trino
AI/ML
Spark
Flink
DevOps
Rest API
Terraform
Azure DevOps
CloudFormation
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Incident Management
GitHub
GitLab
Cybersecurity
MITRE ATT&CK
Apply
$38k – $84k per year (Estimated) • In office • Full-Time • Hyderabad
Python
Verilog
C++
VHDL
MATLAB
Apply
See all jobs
This is one of many
683,639 more open roles from verified company boards, updated every day.