DevSecOps Manager

Bengaluru | Full-time

Apply

About MoEngage:

MoEngage is an insights-led customer engagement platform trusted by 1,350+ global consumer brands, including McAfee, Flipkart, Domino’s, Nestle, Deutsche Telekom, and OYO. MoEngage combines data from multiple sources to help brands gain a 360-degree view of their customers. MoEngage Analytics arms marketers and product owners with insights into customer behavior.

Brands can leverage MoEngage Personalize to orchestrate journeys and build 1:1 conversations across the website, mobile, email, social, and messaging channels. MoEngage Inform, the transactional messaging infrastructure, helps unify promotional and transactional communication to a single platform for better insights and lower costs. MoEngage’s AI Suite helps marketers develop winning copies and creatives, optimize campaigns and channels that boost engagement, and help with faster execution.

For over a decade, consumer brands in 60+ countries have been using MoEngage to power digital experiences for over a billion monthly customers. With offices in 15 countries, MoEngage is backed by Goldman Sachs Asset Management, B Capital, Steadview Capital, Multiples Private Equity, Eight Roads, F-Prime Capital, Matrix Partners, Ventureast, and Helion Ventures.

MoEngage was named a Contender in The Forrester Wave™: Real-Time Interaction Management, Q1 2024 report, and Strong Performer in The Forrester Wave™ 2023 report. MoEngage was also featured as a Leader in the IDC MarketScape: Worldwide Omni-Channel Marketing Platforms for B2C Enterprises 2023.

About the Role :

We are seeking a highly experienced DevSecOps Manager to lead the architecture and execution of our entire DevSecOps framework. Your core mission is to champion the "Secure by Design" philosophy and leverage a deep engineering mindset to drive the program. This perspective will be essential for facilitating faster issue identification and building proactive solutions to mitigate potential issues and delivery blockers. You will balance aggressive high-velocity delivery goals with uncompromising security and compliance to build a secure, resilient and highly scalable system.

You will have deep technical ownership of our Multi-Cloud environment (AWS & GCP), container orchestration (Kubernetes), and CI/CD workflows, while proactively managing our Cloud Security Posture.

Roles & Responsibilities:

1.Security Architecture & Design Define and own the overall security architecture for cloud environments, applications, and internal platforms
Design Zero Trust security models including micro-segmentation, identity-aware access, and least-privilege
policies
Establish secure design patterns and guardrails for engineering teams to build against
Partner with SRE to ensure infrastructure provisioned meets security baselines and design standards


2.Cloud Security & Compliance
Own IAM governance and access policies across AWS & GCP, enforcing Principle of Least Privilege
Manage CSPM tools (Wiz / AWS Security Hub / GCP SCC) — define rules, triage findings, and drive
remediation with SRE
Own compliance posture against CIS, SOC2, ISO 27001, and PCI-DSS; define automated compliance
checks
Manage secrets and TLS/PKI certificate lifecycle policies (HashiCorp Vault, AWS/GCP KMS)
Define and enforce API security standards (OWASP API Top 10) across all exposed services
Maintain SBOM processes and SLA-based vulnerability remediation workflows
Application Security
Embed security gates into CI/CD pipelines (SAST, DAST, dependency scanning, image scanning via
Trivy/Wiz)
Define and enforce container security standards — Kubernetes Network Policies, Pod Security Standards.

3.Falco runtime policies, image signing
Coordinate third-party pen tests and red team assessments; own remediation cycles
Define secure coding standards and review processes in partnership with engineering leads
Observability & Incident Response
Define security logging standards and own SIEM integration and alerting rules
Lead incident response during live security events; drive post-mortem culture
Define DR/BCP security requirements and validate with SRE that RTO/RPO targets are met


4.Leadership & Strategy
Own DevSecOps budget, vendor contracts, and tooling decisions
Report security posture and risk status to the CISO and executive stakeholders
Manage, mentor, and grow a team of DevSecOps engineers
Drive security awareness training across engineering and product teams
Own the change management and security review process for new features and infrastructure changes

Requirements:

Core DevOps & Systems:

  • OS: Expert-level Linux administration and hardening [mandatory].
  • Scripting: Python & Shell for automation and security tooling integration [mandatory].
  • SCM: GitHub (Security features: Dependabot, CodeQL).

Cloud & Security:

  • Cloud Providers: AWS (GuardDuty, Inspector, KMS, WAF) & GCP (IAM, VPC Service Controls) [mandatory].
  • Cloud Security: Experience with CSPM tools (Wiz) and Compliance frameworks (CIS).
  • Container Security: Kubernetes Network Policies, Pod Security Standards, Image Signing.

Tools Stack:

  • Orchestration: Kubernetes, Docker.
  • IaC: Terraform.
  • CI/CD: Jenkins, Harness, Woodpecker.
  • Config Mgmt: Ansible, Chef.

Observability: NewRelic, Prometheus, Grafana, ELK Stack.

At MoEngage, we respect and value differences. We believe that when people from diverse backgrounds and perspectives collaborate, we create the most value – for our clients, our employees, and society. We embrace diversity and uphold a strong set of values. We are committed to inclusivity and take pride in providing equal opportunities for success and growth.

Employment at MoEngage is based solely on professional competence, skills, and experience. We stand firmly against all forms of discrimination and support equal rights and opportunities regardless of gender, ethnicity, abilities, age, identity, orientation or expression, marital status (including pregnancy), religion and beliefs, or any other status protected by law.

It is our policy to comply with all applicable national, state, and local laws related to non-discrimination and equal opportunity. MoEngage is truly a place where everyone can bring their passions, authentic selves, and talents to work, collaborating to drive progress and solve meaningful challenges.

Why Join Us!
At MoEngage, we are passionate about our team and technology - see below to know more about us.
Life@MoEngage
Tech@MoEngage
Scale @MoEngage
We handle more than a billion messages every day. Rest assured, you will be surrounded by really smart and passionate people as we scale much more to build a world-class technology team.