+ Post Job +
Home Cybersecurity

Associate DevSecOps Engineer

📍 Surat 🏷️ Cybersecurity 💰 ₹90,000 / month

Vesu in Surat has an Associate DevSecOps Engineer opening, full time, on site, with a security team embedding vulnerability checks directly into the software delivery pipeline rather than treating security as a separate review that happens after the fact. Two years of experience is the expectation, enough to have already worked with at least one CI/CD pipeline in a real production context.

The role covers monitoring systems for potential threats, investigating and responding to security incidents, and implementing measures that protect company data, all with a specific focus on catching issues during the build and deployment process itself rather than only after something reaches production. An associate here spends real time embedded with development teams, not sitting apart from them in a separate security silo.

What you'll be doing

  • Integrate security scanning into CI/CD pipelines
  • Run vulnerability scans and triage findings by real risk, not just severity score
  • Support incident investigation and response when issues are identified
  • Collaborate with development teams to fix vulnerabilities without derailing release timelines

Required skills are CI/CD security integration, vulnerability scanning tools, scripting for automating checks, and comfort working across at least one major cloud platform. A bachelor's degree in cybersecurity, information technology, or a related field is expected, along with familiarity with security monitoring tools, vulnerability assessment, and incident response practices.

Good to have

  • Familiarity with container security scanning specifically, beyond general application scanning
  • Any scripting experience in Python for building custom security tooling
  • A security certification such as CompTIA Security+, though not mandatory at this level

Vesu has become one of Surat's more established residential and commercial tech pockets, and the development teams this role works alongside ship on a fairly tight release cadence, which means the security checks built into the pipeline need to run fast enough not to become the bottleneck everyone routes around.

Naukri Mitra has listed a handful of cybersecurity roles from this employer, and associates who joined recently describe the collaborative relationship with developers as the most distinctive part of the role, since a security engineer here who's seen as an obstacle rather than a partner tends to get worked around, and the team is explicit that earning developer trust is part of the actual job.

Interviews include a scenario round on triaging a vulnerability scan's findings and a technical discussion of pipeline security concepts. Candidates who can prioritize findings by actual exploitability, not just severity labels, tend to interview well.

Onboarding for this role runs roughly two to three weeks, split between shadowing a current team member and working through a small, low-risk real task under review before moving to independent ownership. The team has found that a slower, more deliberate ramp-up produces fewer costly mistakes down the line than throwing someone straight into full ownership from day one.

A pipeline that passes every security scan can still ship a vulnerability if the scan itself was misconfigured to skip a certain file type, and this team runs periodic audits specifically checking that the scanning configuration hasn't quietly drifted from what was originally intended.

Release cadence for this product runs roughly every two weeks, and the security scanning built into that pipeline needs to complete within a tight window to avoid becoming the bottleneck everyone quietly routes around, which is part of why tuning scan performance is treated as seriously as tuning scan coverage.

The team holds a monthly review specifically looking at false positive rates from the vulnerability scanning tools, since a scanner that cries wolf too often gets ignored by developers eventually, and tuning that signal-to-noise ratio is treated as seriously as catching genuine vulnerabilities in the first place.

The security team tracks mean time to remediation for findings across the pipeline closely, and associates are expected to balance thorough investigation against the reality that a vulnerability sitting unaddressed for too long is itself a growing risk, regardless of how interesting the underlying technical detail might be.

Associates here rotate periodically between offensive-leaning work, like vulnerability triage, and defensive-leaning work, like pipeline hardening, a structure the team maintains specifically because understanding both perspectives makes each type of work sharper than specializing narrowly from the start would.

Benefits

  • Health insurance for the employee
  • Paid time off
  • Provident fund contributions
  • Relocation assistance and accommodation support for candidates moving to Surat

This role is based at Vesu, Surat, pin code 395007, five days a week on site. Pay is up to ₹90,000 a month. The team hopes to fill this seat within five weeks.

Frequently Asked Questions

Both. Associates rotate periodically between offensive-leaning work like vulnerability triage and defensive-leaning work like pipeline hardening, since understanding both makes each sharper.
Yes, if the scan itself was misconfigured to skip a certain file type, which is why the team runs periodic audits checking that scanning configuration hasn't quietly drifted.
Roughly every two weeks, and the scanning built into that pipeline needs to complete within a tight window so it doesn't become the bottleneck everyone routes around.
A scenario round on triaging vulnerability scan findings and a technical discussion of pipeline security concepts, where prioritizing by actual exploitability matters.
Pay is up to ₹90,000 a month, and the team hopes to fill the seat within five weeks.
Apply Now