Hiring: DevSecOps Associate - Source Code Review Security
Location: Pune
No of Openings: 1
Key Responsibilities
Perform deep manual source code reviews across web, API, mobile, cloud-native, and microservices architectures
Identify and validate critical security vulnerabilities including:
- Broken Access Control
- Injection Flaws
- Authentication & Authorization Issues
- SSRF, XXE, Deserialization
- Business Logic Vulnerabilities
- Privilege Escalation
- Cloud & Container Security Weaknesses
- AI/LLM Security Risks
- Conduct:
- Secure Architecture Reviews
- Threat Modeling
- API Security Assessments
- Cloud Security Reviews
- Infrastructure-as-Code (IaC) Reviews
- Secure SDLC Assessments
- Technical Expertise Required
- Java, Spring Boot, .NET, Python, Node.js, Go, Rust, PHP
- React, Angular, Vue, Next.js
- Android & iOS Security
- Kubernetes, Docker, Terraform
- OWASP ASVS, OWASP Testing Guide, MITRE CWE, NIST Frameworks
3.Security Tooling Experience
- Checkmarx
- Fortify
- Veracode
- Semgrep
- Snyk
- Trivy
What We're Looking For
- 1-2+ years of Application Security experience
- Expertise in Manual Secure Code Review
- Strong Secure SDLC and DevSecOps background
- Ability to provide developer-focused remediation guidance
- Experience reviewing enterprise-scale codebases and security architectures
Preferred Certifications
If you have a passion for secure software development, offensive security, and building resilient applications at scale, we'd love to hear from you.