Now Hiring

Security / DevSecOps Engineer

Embed practical security into Pulse design, code, cloud infrastructure and operations. Protect customer, employee and operational data while enabling delivery teams to meet the six-month deadline through automated controls and risk-based decisions.

Information Security India - Kochi preferred / hybrid 7-10 years in application and cloud security Full-time

The facts before you apply

DepartmentInformation Security
Reports ToSolution Architect / Security Owner
Experience7-10 years in application and cloud security
EmploymentFull-time
LocationIndia - Kochi preferred / hybrid
Direct ReportsNone initially

What you'll do and what you'll bring

Key Responsibilities

  • Maintain threat models and security requirements for web, mobile, APIs and cloud
  • Review session/JWT, RBAC, tenant/ownership and sensitive-data controls
  • Integrate SAST, dependency, secret, container and IaC scanning into CI
  • Conduct secure design and code reviews for critical flows
  • Coordinate DAST, penetration testing and remediation verification
  • Define IAM, encryption, secrets, logging and incident-response standards
  • Run security test cases including negative authorisation paths
  • Maintain risk register, exceptions and launch security evidence

Essential Qualifications & Skills

  • OWASP web, API and mobile security
  • Spring Security/JWT and authorisation concepts
  • AWS IAM, KMS, WAF, networking and secrets
  • SAST/DAST/SCA/container scanning
  • Threat modelling and secure SDLC
  • Incident response and clear risk communication

Expected outcomes

  • Complete threat models and minimum security baseline
  • Automate CI security gates
  • Verify authentication and authorisation negative paths
  • Close critical/high findings before launch
  • Deliver incident-response and security-monitoring runbooks

Success measures

  • Critical/high vulnerability ageing
  • Security-control coverage
  • Authorisation defect escapes
  • Detection and response readiness

Preferred qualifications and behavioural fit

Preferred Qualifications

CISSP, CSSLP, CEH, OSCP or cloud-security certification Mobile application security Privacy and Indian data-protection awareness

Behavioural Competencies

Risk-based judgement Constructive enablement Adversarial thinking Confidentiality and integrity

What to expect if you join

The role works in a cross-functional, documentation-first and architecture-led product environment. Candidates must be comfortable with hands-on ownership, transparent decisions, code/design review, automated quality controls and production accountability. The six-month MVP excludes unnecessary microservices, Kubernetes, speculative AI and other scope not approved through product governance.

Application evidence: CV, role-relevant portfolio or work sample where applicable, and concise examples showing personal contribution and measurable outcomes. Final compensation, work arrangement and joining date will be confirmed during the recruitment process. DataArtha Solutions is committed to fair, respectful and merit-based selection.

Apply for Security / DevSecOps Engineer

If this role matches your experience, send your resume and a short note to careers@dataartha.in. We review every application and reach out if there's a good match for your profile.