# DevSecOps & Product Security Engineer

> Weekday AI · Hyderabad, India · Full-time · Posted 2026-09-17

**Salary:** INR 300,000–1,000,000

**Workplace:** on_site

**Department:** Weekday's Client via platform

## Description

𝗧𝗵𝗶𝘀 𝗿𝗼𝗹𝗲 𝗶𝘀 𝗳𝗼𝗿 𝗼𝗻𝗲 𝗼𝗳 𝘁𝗵𝗲 𝗪𝗲𝗲𝗸𝗱𝗮𝘆'𝘀 𝗰𝗹𝗶𝗲𝗻𝘁𝘀

𝗦𝗮𝗹𝗮𝗿𝘆 𝗿𝗮𝗻𝗴𝗲: 𝗥𝘀 𝟯𝟬𝟬𝟬𝟬𝟬 - 𝗥𝘀 𝟭𝟬𝟬𝟬𝟬𝟬𝟬 (𝗶𝗲 𝗜𝗡𝗥 𝟯-𝟭𝟬 𝗟𝗣𝗔)

Experience: 2+ yrs

Location: Hyderabad, Telangana

Job Type: Full-time

We are looking for a hands-on **DevSecOps & Product Security Engineer** to embed security across the software development and deployment lifecycle. The role combines **application security, API security, cloud security, DevSecOps, CI/CD security, and AI product security** across modern SaaS and AI-enabled platforms.

The ideal candidate will work closely with developers, architects, cloud engineers, and product teams to identify security risks, automate security controls, strengthen development and deployment pipelines, and drive vulnerabilities through to effective remediation. This is an engineering-focused security role involving practical implementation and problem-solving rather than a traditional SOC or monitoring position.

## Requirements

Key Responsibilities

-   Embed security checks, scanning, and quality gates across the **software development lifecycle**.
-   Review application architecture, authentication, authorization, APIs, tenant isolation, and access-control mechanisms.
-   Identify and mitigate **OWASP Top 10 and API security risks** through threat modelling and secure design practices.
-   Partner with developers to identify vulnerabilities and implement practical remediation rather than simply reporting findings.
-   Assess AI-powered applications, agents, prompts, connectors, and data-access workflows for security risks.
-   Identify and mitigate risks involving **prompt injection, data leakage, tool misuse, unauthorized data access, and unsafe AI actions**.
-   Secure Google Cloud environments, including **IAM, service accounts, networking, secrets, and containerized workloads**.
-   Enforce least-privilege access and appropriate separation between development, testing, and production environments.
-   Harden **GitHub Actions and CI/CD pipelines** through secure configurations, secret protection, dependency management, and release controls.
-   Implement and manage SAST, software composition analysis, secret scanning, SBOM generation, and other automated security controls.
-   Establish processes to identify, prioritize, track, remediate, and validate security vulnerabilities.
-   Analyze security scanner findings, distinguish genuine risks from false positives, and prioritize remediation based on business impact.
-   Strengthen security logging, alerting, investigation, and incident-response capabilities.
-   Support security incidents, root-cause analysis, security drills, and corrective actions when required.
-   Maintain audit-ready security evidence and support penetration testing, compliance activities, and security assessments.
-   Contribute to security architecture documentation, standards, policies, and secure development practices.
-   Automate repetitive security processes and integrate security controls into engineering workflows.
-   Collaborate closely with engineering, architecture, product, and cloud teams to improve overall product security.
-   Stay current with emerging **cloud, application, DevSecOps, AI/LLM, and product security threats and practices**.

What Makes You a Great Fit

-   **2+ years of hands-on experience** in DevSecOps, application security, product security, cloud security, or a related engineering security role.
-   Strong practical understanding of **DevSecOps, application security, and API security**.
-   Good knowledge of **OWASP Top 10**, common API vulnerabilities, secure coding, authentication, authorization, and access controls.
-   Experience securing applications built using technologies such as **Python backends and React-based frontends**.
-   Strong experience with **GitHub, GitHub Actions, and CI/CD security**.
-   Hands-on knowledge of SAST, dependency scanning, secret scanning, SBOM, and secure software supply-chain practices.
-   Experience securing **Google Cloud Platform (GCP)** environments, including IAM, service accounts, least-privilege access, and containerized workloads.
-   Ability to analyze security findings, assess real-world risk, and drive vulnerabilities through to resolution.
-   Experience with tools such as **CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, or Burp Suite**is an advantage.
-   Understanding of containers, Kubernetes, Infrastructure-as-Code, and cloud security practices is preferred.
-   Exposure to **AI/LLM security, AI agents, RAG applications, SaaS integrations, or sensitive data pipelines** is highly desirable.
-   Familiarity with PostgreSQL, GCP Security Command Center, SIEM, cloud monitoring, or MDR solutions is an advantage.
-   Exposure to **SOC 2, ISO 27001**, penetration testing, or security compliance activities is beneficial.
-   Strong scripting and automation mindset with the ability to integrate security controls into engineering workflows.
-   Excellent communication skills with the ability to explain complex security risks in clear and practical terms.
-   Strong ownership mindset with the ability to work collaboratively with engineering and product teams.
-   Curious and proactive approach to emerging **AI-driven product security and cloud security challenges**.
-   Practical hands-on experience and real-world problem-solving ability are highly valued.

## Apply

[Apply at Weekday AI](https://apply.workable.com/weekday-1/j/8B24846A6C/apply)

---
Powered by [Workable](https://www.workable.com)
