Role Overview
We are seeking an experienced Senior DevSecOps & AI Security Engineer to strengthen security across applications, cloud-native platforms, DevSecOps pipelines, and AI/LLM-based solutions. The role focuses on application security, offensive security testing, vulnerability management, secure code reviews, cloud security, and emerging AI security practices.
Primary Skills
- Application Security – SAST, DAST, Secure Code Review
- Penetration Testing – Web, API, Mobile
- AI/LLM Security – Prompt Injection, Jailbreak & Model Security
- DevSecOps & CI/CD Security
- Vulnerability Management & Remediation
- Security Automation using Python
Secondary Skills
- Azure Cloud Security
- Container & Kubernetes Security
- SCA & Open-Source Security
- GitHub Security Controls
- Threat Modeling & Risk Assessment
- Security Governance & Developer Enablement
Key Responsibilities
Security Assessment & Testing
- Perform penetration testing across web, API, mobile, cloud-native, and AI-powered applications.
- Conduct secure code reviews and identify application security weaknesses.
- Validate findings from SAST, DAST, SCA, and container security tools.
- Perform vulnerability analysis, root-cause investigation, and remediation validation.
AI Security
- Assess AI/LLM applications for security vulnerabilities and misuse scenarios.
- Conduct prompt injection, manipulation, and jailbreak testing.
- Evaluate AI deployment architectures and recommend appropriate security controls.
- Support secure AI adoption across enterprise platforms.
DevSecOps & Automation
- Integrate security controls into CI/CD pipelines and deployment workflows.
- Implement shift-left security practices.
- Automate security validation and reporting using Python.
- Optimize vulnerability assessment and remediation workflows.
- Enhance security monitoring and policy enforcement across development environments.
Cloud & Container Security
- Perform Azure cloud security assessments.
- Review Kubernetes and containerized workloads for security risks.
- Analyze container images and deployment configurations.
- Recommend cloud-native security practices and remediation actions.
Vulnerability Management & Governance
- Review and validate vulnerabilities identified by enterprise security tools.
- Prioritize findings based on exploitability, business risk, and operational impact.
- Drive remediation with engineering teams and verify effectiveness.
- Support security governance, compliance, and audit activities.
Stakeholder Engagement
- Collaborate with development, DevOps, architecture, and product teams.
- Provide guidance on secure coding and vulnerability remediation.
- Mentor engineering teams on security-first development.
- Present security findings and recommendations to technical and business stakeholders.
Required Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or related field.
- 6+ years of experience in Application Security, DevSecOps, Offensive Security, or Security Engineering.