DevSecOps Associate - Source Code Review Security
Hiring: DevSecOps Associate - Source Code Review Security
Location: Pune
No of Openings: 1
Key Responsibilities
Perform deep manual source code reviews across web, API, mobile, cloud-native, and microservices architectures
Identify and validate critical security vulnerabilities including:
Broken Access Control
Injection Flaws
Authentication & Authorization Issues
SSRF, XXE, Deserialization
Business Logic Vulnerabilities
Privilege Escalation
Cloud & Container Security Weaknesses
AI/LLM Security Risks
Conduct:
- Secure Architecture Reviews
- Threat Modeling
- API Security Assessments
- Cloud Security Reviews
- Infrastructure-as-Code (IaC) Reviews
- Secure SDLC Assessments
Technical Expertise Required
- Java, Spring Boot, .NET, Python, Node.js, Go, Rust, PHP
- React, Angular, Vue, Next.js
- Android & iOS Security
- Kubernetes, Docker, Terraform
- OWASP ASVS, OWASP Testing Guide, MITRE CWE, NIST Frameworks
3.Security Tooling Experience
- Checkmarx
- Fortify
- Veracode
- Semgrep
- Snyk
- Trivy
What We're Looking For
- 1-2+ years of Application Security experience
- Expertise in Manual Secure Code Review
- Strong Secure SDLC and DevSecOps background
- Ability to provide developer-focused remediation guidance
- Experience reviewing enterprise-scale codebases and security architectures
Preferred Certifications
If you have a passion for secure software development, offensive security, and building resilient applications at scale, we'd love to hear from you.
Job Details
Experience
Entry · 1–2 yrs