Senior Staff Engineer (AI Developer - DevSecOps Tools)
On-site Ā· Mumbai, Maharashtra, India
Job Summary
Senior Staff Engineer to design, develop, and maintain AI-powered automation solutions that integrate security into CI/CD pipelines and the software development lifecycle. Build intelligent security automation for CI/CD platforms, develop ML models to detect pipeline anomalies, enhance LLM-powered remediation for IaC using Terraform/ARM/Helm, implement Retrieval-Augmented Generation with internal policies, orchestrate AI workflows across multiple security tools, create NLP-based analyses of security scan outputs, expose AI capabilities via scalable REST APIs using FastAPI or Flask, and automate security workflows in Kubernetes/Docker environments. Collaborate with engineering, DevSecOps, cloud, and security teams to improve automation reliability and developer experience, while delivering dashboards and monitoring for security posture and pipeline health.
Required Qualifications
- 7.5+ years of experience
- Strong software engineering with hands-on AI/ML or security automation
- Proficient in Python with libraries including Scikit-learn, PyTorch, Pandas, NumPy
- Experience building AI-powered applications with ML, LLMs, automation, or intelligent workflows
- Strong DevSecOps practices and hands-on security tools including SAST, SCA, secrets detection, IaC scanning (Checkov, Terrascan), container image scanning (Trivy)
- Experience integrating security automation into CI/CD pipelines (Azure DevOps, GitHub Actions, Jenkins, GitLab CI)
- Hands-on Docker and Kubernetes (AKS/EKS)
- Policy-as-code with OPA/Rego and Kubernetes security enforcement
- Experience with LLM APIs (Azure OpenAI, OpenAI) and prompt engineering, RAG, AI-assisted code analysis
- Experience building REST APIs and microservices with FastAPI or Flask
- Cloud platform knowledge (Azure, AWS, GCP) and cloud-native security concepts
- Infrastructure-as-Code (Terraform, ARM templates, Helm)
- Secrets management (HashiCorp Vault, Azure Key Vault)
- Understanding of MLOps, model deployment, monitoring, drift detection, CI/CD for ML
- Event-driven architectures and messaging (Azure Event Hub, AWS EventBridge, GCP Pub/Sub)
- Familiarity with security platforms (Prisma Cloud, Wiz, Aqua Security, Snyk)
- Experience with LangChain/Semantic Kernel/AutoGen or similar AI orchestration frameworks
- GitOps tools (ArgoCD, Flux) and policy frameworks (HashiCorp Sentinel, Cedar)
- Integrations with Jira/ServiceNow/Azure Sentinel SOAR
- Bachelorās or Masterās degree in CS/IT/Engineering or related field
- Security certifications desirable (CompTIA Security+, CEH, CKS, SC-200, AZ-900, AWS Security Specialty, GCP Pro Cloud Security Engineer)
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf ā no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.