Security / DevSecOps Engineer
Embed practical security into Pulse design, code, cloud infrastructure and operations. Protect customer, employee and operational data while enabling delivery teams to meet the six-month deadline through automated controls and risk-based decisions.
The facts before you apply
What you'll do and what you'll bring
Key Responsibilities
- Maintain threat models and security requirements for web, mobile, APIs and cloud
- Review session/JWT, RBAC, tenant/ownership and sensitive-data controls
- Integrate SAST, dependency, secret, container and IaC scanning into CI
- Conduct secure design and code reviews for critical flows
- Coordinate DAST, penetration testing and remediation verification
- Define IAM, encryption, secrets, logging and incident-response standards
- Run security test cases including negative authorisation paths
- Maintain risk register, exceptions and launch security evidence
Essential Qualifications & Skills
- OWASP web, API and mobile security
- Spring Security/JWT and authorisation concepts
- AWS IAM, KMS, WAF, networking and secrets
- SAST/DAST/SCA/container scanning
- Threat modelling and secure SDLC
- Incident response and clear risk communication
Expected outcomes
- Complete threat models and minimum security baseline
- Automate CI security gates
- Verify authentication and authorisation negative paths
- Close critical/high findings before launch
- Deliver incident-response and security-monitoring runbooks
Success measures
- Critical/high vulnerability ageing
- Security-control coverage
- Authorisation defect escapes
- Detection and response readiness
Preferred qualifications and behavioural fit
Preferred Qualifications
Behavioural Competencies
What to expect if you join
The role works in a cross-functional, documentation-first and architecture-led product environment. Candidates must be comfortable with hands-on ownership, transparent decisions, code/design review, automated quality controls and production accountability. The six-month MVP excludes unnecessary microservices, Kubernetes, speculative AI and other scope not approved through product governance.
Application evidence: CV, role-relevant portfolio or work sample where applicable, and concise examples showing personal contribution and measurable outcomes. Final compensation, work arrangement and joining date will be confirmed during the recruitment process. DataArtha Solutions is committed to fair, respectful and merit-based selection.
Apply for Security / DevSecOps Engineer
If this role matches your experience, send your resume and a short note to careers@dataartha.in. We review every application and reach out if there's a good match for your profile.