
Real job — pulled straight from Fynd’s careers page · Verified August 27, 2026 · No reposts.
Job description
Fynd is hiring a DevSecOps Engineer — a full-time, based in Mumbai, India role. Apply directly on Fynd's careers page below.
Agentic DevSecOps Engineer | SDE‑2
Location: Mumbai, India
Department: Information Security
Experience: 4+ yrs
- Own the security stages of the CI/CD estate (Jenkins, Azure DevOps, GitHub Actions), including SAST, SCA, and secrets detection, such that Critical and High severity findings are prevented from reaching production without impeding release velocity.
- Reduce false positives through custom validation, thereby maintaining engineering confidence in security gates.
- Secure the software supply chain, including SBOM generation, dependency and base‑image provenance, and the governance of secrets and non‑human identities across pipelines.
- Harden self‑managed Kubernetes clusters across multiple clouds: RBAC, admission control, network policy, node and operating‑system hardening, and managed‑image patching pipelines.
- Build and operate cloud security posture and external attack‑surface tooling on GCP, encompassing IAM, organisational policy, and service‑account hygiene, together with automated remediation of identified misconfigurations.
- Engineer detection‑as‑code upon the existing observability stack (Prometheus, Grafana, ELK), including eBPF‑based runtime security.
- Participate in the security on‑call rotation and contribute to incident triage, containment, and post‑incident review.
- Engineer the vulnerability pipeline: a single consolidated queue enriched with reachability and exploitability context, governed by severity‑based SLAs, and operating on the principle of find → validate → prioritise → hand over to engineering.
- Design and build agentic security systems: LLM tool calling and MCP, structured outputs, evaluation harnesses that verify agent output, and deterministic‑first architecture with bounded LLM judgement and human override.
- Secure AI systems in production, including prompt‑injection resistance, tool‑permission scoping, MCP server security, and threat modelling aligned to the OWASP LLM Top 10 and emerging agentic threat taxonomies.
- Engineer automated threat modelling and secure design review: threat models generated and maintained from design documents, API specifications, and infrastructure‑as‑code, with human review reserved for high‑risk changes.
- Define and enforce API security standards as code: specification linting, authentication and authorisation conformance checks, and continuous discovery of undocumented or unauthenticated endpoints.
- Build continuous multi‑tenant isolation assurance: automated cross‑tenant access probes executed against production‑representative environments, with regressions treated as release‑blocking defects.
- Integrate mobile application security testing into the build pipeline for released applications.
- Engineer the vetting pipeline for third‑party extensions and marketplace submissions: automated static and dynamic screening, credential and secret detection, and permission review prior to listing.
- Build automated data discovery and classification across datastores and pipelines, maintaining a continuously refreshed map of personal data and its flows.
- Enforce privacy controls as code: detection of personal data in logs and analytics, retention and deletion enforcement, and encryption and key‑management posture checks.
- Automate the fulfilment of data‑principal requests (access, correction, erasure) and the supporting evidence trail, aligned to the Digital Personal Data Protection Act and applicable frameworks.
- Build behaviour‑driven, personalised security training: modules generated and assigned from observed events — a committed secret, a policy breach, a phishing simulation failure — targeted to the individual, their role, and the systems they touch.
- Measure enablement by behaviour change (repeat‑incident rate, time to remediate), not by completion rates.
- Automate backup assurance: scheduled restore testing with integrity verification, on the principle that an unverified restore is not a backup.
- Engineer disaster‑recovery validation: automated failover exercises and game days measured against defined RTOs and RPOs.
- Practise chaos engineering across Kubernetes workloads and critical dependencies: controlled fault injection to verify graceful degradation under failure.
- Practise security chaos engineering: controlled injection of security failures — a disabled control, a dropped admission webhook, a simulated credential exposure — to verify that detection and response operate as designed.
- Validate detections continuously through automated adversary emulation.
- Automate the collection of continuous control evidence (ISO 27001, CIS Benchmarks) in support of ongoing audit readiness.
- Proficiency in Python, together with Go or advanced shell scripting, and a record of shipping production‑quality tooling rather than scripts.
- Hands‑on GCP security experience: IAM, networking, and organisational policy, including a working command of authorisation paths.
- Kubernetes internals and container security on self‑managed clusters.
- Linux administration and security hardening.
- Terraform and policy‑as‑code.
- Depth in code, build, and release management: Git, together with Jenkins, Azure DevOps, or GitHub Actions; familiarity with web servers and reverse proxies (Nginx or equivalent).
- Fluency in agentic AI‑assisted engineering (Claude Code or equivalent), driven by written specifications and test harnesses, together with the judgement to review AI‑generated code for security defects. Effectiveness of AI leverage is treated as a measure of performance.
- Demonstrable evidence of building: a public repository, tooling, automation, or technical writing.
- Two to five years of relevant experience; demonstrated delivery will be given due weight alongside tenure.
- eBPF runtime security tooling (Falco, Tetragon); distributed tracing and APM applied as security evidence.
- Chaos engineering tooling (Chaos Mesh, LitmusChaos) and adversary emulation frameworks (Atomic Red Team, Caldera, or equivalent).
- Exposure to privacy engineering under the Digital Personal Data Protection Act or the GDPR.
- Mobile application security testing tooling.
- Working literacy in Kafka, MongoDB, and MySQL; Ansible.
- GCP Professional Cloud Security Engineer; Certified Kubernetes Security Specialist (CKS).
- Bug bounty or CTF background.
Get DevSecOps Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for DevSecOps Engineer at Fynd?
The required skills for DevSecOps Engineer at Fynd include: Python, Go, Bash, CI/CD, Kubernetes, GCP, IAM, Terraform, Git, Jenkins, Azure DevOps, GitHub Actions, LLM, GDPR, Kafka, MongoDB, MySQL, Ansible.
What is the seniority level for DevSecOps Engineer at Fynd?
DevSecOps Engineer at Fynd is a Mid Level / Senior level position.
How do I apply for DevSecOps Engineer at Fynd?
You can view the full description and apply for DevSecOps Engineer at Fynd on EchoJobs: https://echojobs.io/job/fynd-agentic-devsecops-engineer-sde-2-dxw08.