Live opening · Posted 7 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
DevSecOps Engineer
ABOUT SHESHI
Bringing Sanctity to Numbers
Sheshi is a Financial Operating System — the governed infrastructure layer that converts raw financial data into results that organisations can completely trust. Governed, auditable, period-locked, and traceable to the source.
We are headquartered in Bangalore, building an enterprise-grade product for the global market.
Security cannot be an afterthought in a platform that governs financial data. As DevSecOps Engineer, you embed security into every stage of how Sheshi builds and ships software — from the first line of code to what runs in production. You make secure practice automatic, not an extra step engineers have to remember.
WHY SHESHI
What Makes This Role Worth Doing
Security with real stakes. You are securing a platform that governs enterprise financial data — the work has genuine weight.
Build the practice from scratch. You define how security gets embedded into Sheshi's engineering lifecycle from the ground up.
A path toward enterprise certification. You will drive Sheshi's readiness for SOC 2, ISO 27001, or equivalent — work that directly unlocks larger enterprise deals.
Partnership, not isolation. You work closely with engineering and the SRE function, embedded in how the platform is built.
Continuous Validation & Periodic Audits: Establish a recurring VAPT cadence to identify and evaluate security flaws in the system.
RESPONSIBILITIES
What You Will Own
Secure CI/CD
Own security integration across the CI/CD pipeline — static and dynamic analysis, dependency scanning, and secrets detection.
Ensure no code reaches production without passing defined security checks.
Vulnerability and Risk Management
Own vulnerability management across applications and infrastructure — scanning, tracking, and driving remediation.
Run regular security assessments and coordinate penetration testing as the platform matures.
Application and Infrastructure Security
Embed secure coding practices into the development lifecycle — OWASP alignment, secure API design, and input validation standards.
Own infrastructure security configuration in partnership with the SRE function — access control, encryption, and secrets management.
Compliance and Security Culture
Drive readiness for enterprise security certifications — SOC 2, ISO 27001, or equivalent — as the platform scales.
Own audit logging and traceability standards that support governance and customer compliance needs.
Provide security guidance to engineering teams as part of everyday development, not a separate compliance exercise.
WHAT WE ARE LOOKING FOR
Your Background and Strengths
Experience
4-8 years in DevSecOps, application security, or security engineering roles.
Proven experience embedding security into CI/CD pipelines for a SaaS product.
Track record of driving vulnerability management and remediation at pace.
Technical Depth
Strong understanding of OWASP practices, secure coding principles, and common vulnerability classes.
Hands-on experience with security tooling — SAST, DAST, dependency scanning, and secrets detection.
Working knowledge of AWS security services — IAM, KMS, Security Hub, GuardDuty, or equivalent.
Familiarity with compliance frameworks — SOC 2, ISO 27001 — and what they require operationally.
Scripting proficiency in Python, Bash, or similar for security automation.
How You Work
You build security into the pipeline, so it becomes automatic, not something teams remember to do.
You communicate risk clearly to both technical and non-technical stakeholders.
You balance security rigour with development speed, treating them as complementary, not opposing.
You stay current on emerging threats and bring that awareness back into how Sheshi builds.
Nice to Have
Experience in a regulated, financial, or compliance-sensitive SaaS environment.
Direct experience achieving SOC 2 or ISO 27001 certification for a growing SaaS company.
Familiarity with Node.js and React application security considerations.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.