This opportunity is with Incepteo Labs, a company specializing in building secure, scalable digital products for global clients. The role is based in Hyderabad, India, with a hybrid/on-site work model, and is suited for mid-senior level professionals with 4 to 7 years of experience. Reporting to the IT & Cloud Manager, the position focuses on embedding security throughout the software development and deployment lifecycle. You will work closely with developers, architects, and cloud engineers to enhance application security, cloud security, and DevSecOps practices, particularly for AI-enabled SaaS platforms like Stratpilot, an AI-powered business platform integrating with enterprise systems.
Key Responsibilities
Secure Development & Application Security: Implement security checks, scanning, and quality gates across the software development lifecycle. Champion secure coding practices and remediation efforts. Review authentication, authorization, APIs, tenant isolation, and access controls, identifying and mitigating OWASP and API security risks through threat modeling.
AI Product Security: Assess risks related to AI agents, prompts, connectors, and data access. Protect against prompt injection, data leakage, tool misuse, and unsafe AI actions.
Cloud & CI/CD Security: Secure Google Cloud environments by managing IAM, service accounts, networking, secrets, and workloads with a focus on least privilege and environment separation. Harden GitHub Actions, dependencies, and deployment pipelines using secret protection, software composition analysis (SCA), software bill of materials (SBOM), and secure release processes.
Vulnerability Management & Monitoring: Establish processes to identify, prioritize, and track vulnerabilities. Coordinate remediation efforts and validate fixes. Enhance security logging, alerting, and investigation capabilities, supporting incident response, root cause analysis, and security drills.
Security Assurance: Maintain audit-ready security evidence. Support penetration testing, compliance activities, and documentation of security architecture.
Required Qualifications
Hands-on experience in DevSecOps and application/API security, with a solid understanding of OWASP Top 10 vulnerabilities. Proficiency with Python backends and React applications is essential. Strong expertise in GitHub and CI/CD security, including pull requests, GitHub Actions, static application security testing (SAST), dependency scanning, and secret scanning.
Experience securing Google Cloud environments, including IAM, service accounts, least-privilege access, and containerized workloads. Proven ability to distinguish genuine security risks from scanner noise and drive practical remediation. Excellent communication skills with a hands-on approach to resolving security issues.
Preferred Qualifications and Benefits
Experience securing AI platforms, SaaS integrations, or sensitive data pipelines is advantageous. Familiarity with PostgreSQL security, Infrastructure-as-Code, Google Cloud Security Command Center, and container orchestration platforms like Kubernetes is a plus. Knowledge of security tools such as CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, or Burp Suite is desirable.
Exposure to SIEM, cloud monitoring/MDR solutions, and compliance frameworks such as SOC 2 or ISO 27001 is beneficial. Experience with AI/LLM systems, agents, and retrieval-augmented generation (RAG) applications is also valued.
You will thrive in this role if you enjoy collaborating closely with engineering and product teams, seamlessly navigating between code, cloud infrastructure, and security analysis. A preference for automation over manual processes and viewing security as an enabler rather than a blocker is important. Taking ownership of security issues through to resolution and explaining complex risks in clear, practical terms will help you succeed. Curiosity about AI-driven product security challenges is highly encouraged.
Why Join Incepteo Labs?
You will have the opportunity to work across multiple modern product engineering teams and influence security architecture on live production systems. This role offers hands-on experience in AI security, cloud security, and application security all at once. You will contribute to building scalable security automation used by global clients and collaborate directly with engineering, architecture, and product leadership. Incepteo values practical experience and real-world problem-solving over certifications or tool checklists, fostering a collaborative and impactful security culture.
Must-have skills: DevSecOps
Good-to-have skills: Google Cloud Platform (GCP), AI security, SaaS security, Kubernetes, Infrastructure-as-Code, security scanning tools