
Lead DevSecOps Engineer
GoKwik
Posted 2026-06-03
INR 5,000,000 - INR 7,000,000 per year
Tech & Engg
Job Description
Ovii's Interpretation of the Role
The Lead DevSecOps Engineer will own security automation across GoKwik's CI/CD pipelines, cloud‑native architecture, and compliance programs, ensuring the platform scales securely for billions in GMV. This senior individual‑contributor role partners with engineering, security, and governance teams to embed guardrails, lead incident response, and foster a blameless security culture.
Role Snapshot
- Lead security automation across CI/CD
- Own cloud‑native security architecture
- Drive incident response and postmortems
- Maintain SOC2, ISO 27001, PCI‑DSS compliance
- Mentor engineering teams on security best practices
- Automate IAM, secrets, and policy enforcement
Must-Have Requirements
- CI/CD security (SAST, DAST, vulnerability scanning)
- Cloud security fundamentals (IAM, WAF, KMS, CSPM)
- Kubernetes security (RBAC, PodSecurity, NetworkPolicies)
- Automation scripting (Python, Go, Bash)
- Security tooling integration (Vault, Prisma, Aqua, Trivy)
- Compliance frameworks (SOC2, ISO 27001, PCI‑DSS)
- Incident response leadership
- DevSecOps
- Cloud Security Engineering
Nice-to-Have Signals
- AI/LLM security frameworks
- Fast‑scaling SaaS/eCommerce experience
- Familiarity with AI risk models
- Fast‑scaling SaaS/eCommerce
- eCommerce
- SaaS
Work Setup
- Location: Bangalore, India
- Work mode: ONSITE
- Employment type: Full-Time
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Education requirement
- Certifications
- Relocation
- Notice period
- Travel
- Security clearance
- Coding test
- Portfolio
- GitHub
- Writing sample
- Cover letter
What You'll Likely Work On
- Build secure CI/CD pipelines with automated scanning and testing
- Design and enforce cloud‑native security architectures that are secure by default
- Automate secrets management, IAM policy enforcement, and compliance validation
- Lead security incident response, coordinate remediation, and run blameless postmortems
- Run training, awareness, and culture‑building programs for DevSecOps
- Maintain continuous compliance readiness for SOC2, ISO 27001, and PCI‑DSS
- Integrate best‑in‑class security tools (Vault, Prisma, Aqua, Trivy) across the stack
Good Fit If You Have
- Exposure to AI/LLM security frameworks
- Experience in fast‑scaling SaaS or eCommerce environments
- Strong scripting ability in Python, Go, or Bash
- Comfortable influencing cross‑functional engineering teams
Skills
- CI/CD security (SAST, DAST, vulnerability scanning)
- Cloud security fundamentals (IAM, WAF, KMS, CSPM)
- Kubernetes security (RBAC, PodSecurity, NetworkPolicies)
- Automation scripting (Python, Go, Bash)
- Security tooling integration (Vault, Prisma, Aqua, Trivy)
- Compliance frameworks (SOC2, ISO 27001, PCI‑DSS)
- Incident response & threat modelling
- AI/LLM security fundamentals