Skip to main content
← Back to Jobs

Security Engineer - DevSecOps

Alignity Solutionsβ€’Hyderabad
Full-time
πŸ‘οΈ 0 viewsβ€’πŸ“ 0 applicationsβ€’Posted 8/29/2026β€’Expires 10/2/2026
Tailor Resume for This JobCheck ATS Score

Get alerts for roles like this

More Security Engineer - DevSecOps roles in Hyderabad β€” straight to your inbox. No account needed.

Applying to this role? Tailor your rΓ©sumΓ© to this job description in one click, then download it clean β€” no watermark, no subscription.

Job Description

As a Security Engineer: You will: - Integrate, configure, and optimize SAST, SCA, and DAST tools within CI/CD pipelines to automate security testing across build, test, and release stages (including quality gates and exception workflows). - Perform static, dynamic, and open-source dependency assessments to identify vulnerabilities including OWASP Top 10 risks, insecure libraries, exposed secrets, misconfigurations, and software supply-chain weaknesses. - Execute API security testing (REST/GraphQL) including authentication/authorization validation (OAuth2/OIDC/JWT), input validation, rate limiting/abuse cases, and broken object/function level authorization (BOLA/BFLA), and translate results into developer-ready fixes. - Analyze scan results, remove false positives, prioritize findings based on exploitability and business impact, and provide clear, actionable remediation guidance (secure coding patterns, compensating controls, and verification steps). - Work hands-on with developers, DevOps engineers, architects, and client stakeholders to embed secure coding, secure design, and shift-left security practices, including playbooks, office hours, and remediation sprints. - Support threat modeling and security design reviews; convert threats into actionable security requirements, test cases, and engineering backlog items aligned to delivery timelines. - Track vulnerabilities through closure, validate remediation (re-scan, proof of fix, and regression checks), and ensure issues are managed in line with client policy, risk tolerance, and SLA expectations. - Implement additional DevSecOps controls such as IaC scanning, secrets detection, container image scanning, and Kubernetes security checks (where applicable), including policy-as-code to prevent insecure deployments. - Strengthen software supply-chain security by supporting SBOM generation/consumption, dependency hygiene, and build/release integrity controls (e.g., artifact signing/verification and provenance where applicable). - Automate repeatable security tasks using scripting (e.g., Python/Bash) and integrations (APIs/webhooks) to improve scan reliability, reporting, and developer workflow adoption. - Design and build AI agents / agentic workflows for AppSec automation (e.g., triage, false-positive suppression, secure code review assistance, threat-model generation, remediation assistance), ensuring appropriate guardrails, logging, and human-in-the-loop validation. - Perform current-state assessments of client DevSecOps and emerging AISecOps practices against industry standards; provide prioritized recommendations and an implementation roadmap. - Perform security testing across modern application surfacescode, APIs, cloud, containers/Kubernetesand, where applicable, AI/ML pipelines (e.g., RAG data flows, model integration points, and tool/function calling) using a combination of automated and manual techniques. - Produce security assessment reports, dashboards, trend analysis, and root-cause insights for technical and non-technical stakeholders. - Contribute to secure SDLC standards aligned to recognized verification frameworks such as OWASP ASVS. - Stay current on emerging threats, AppSec tooling trends, software supply-chain risks, and new attack surfaces introduced by AI-enabled applications and agentic workflows.

Required Skills

CI/CDGraphQLKubernetesMachine LearningPython

The best-paying roles in your field. Every week. Free.

Join 10,000+ professionals getting job alerts and salary insights in their inbox

We respect your privacy. Unsubscribe anytime with one click.