hirly

Fynd

Agentic DevSecOps Engineer | SDE‑2

Mumbai, India

Apply through hirly

hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.

hirly's read of this role

Seniority
Mid level
Country
IN
Work mode
On-site / unstated
First seen by hirly
23 Sept 2026

Derived automatically from the posting. Sign up to see how the role scores against your own resume.

the posting

Fynd is a frontier technology company. We started at the intersection of technology and retail because that is where technology was the least available. Over the years, we became one of India’s largest retail technology platforms. But retail was the entry point, not the boundary. Today, Fynd builds intelligent software that runs business operations. Not tools that help people work faster, but systems that absorb entire functions: manufacturing, marketing, logistics, commerce, quality control. We sit inside our customers’ businesses, harvest deep domain context, and build AI systems that operate autonomously. We are expanding from retail into manufacturing, generative media, physical AI, and healthcare.

Role Overview

Fynd operates an AI‑native security function. The function builds and operates its own controls — security gates within CI/CD, cloud‑posture and attack‑surface tooling, detection pipelines, and agentic systems that identify, validate, and prioritise risk across a multi‑cloud estate. The mandate extends, through automation, into product security, privacy engineering, security enablement, and resilience. The role holder will own such controls end to end, applying AI tooling as the primary force multiplier.

Candidates are not expected to hold prior expertise in every area listed below. Candidates are expected to demonstrate the capacity to close knowledge gaps rapidly and independently through the disciplined use of AI tooling: specifying the work, building it, verifying it, and owning the outcome.

What will you do at Fynd?

CI/CD Security and Software Supply Chain

  • Own the security stages of the CI/CD estate (Jenkins, Azure DevOps, GitHub Actions), including SAST, SCA, and secrets detection, such that Critical and High severity findings are prevented from reaching production without impeding release velocity.
  • Reduce false positives through custom validation, thereby maintaining engineering confidence in security gates.
  • Secure the software supply chain, including SBOM generation, dependency and base‑image provenance, and the governance of secrets and non‑human identities across pipelines.

Cloud and Kubernetes Security

  • Harden self‑managed Kubernetes clusters across multiple clouds: RBAC, admission control, network policy, node and operating‑system hardening, and managed‑image patching pipelines.
  • Build and operate cloud security posture and external attack‑surface tooling on GCP, encompassing IAM, organisational policy, and service‑account hygiene, together with automated remediation of identified misconfigurations.

Detection and Response

  • Engineer detection‑as‑code upon the existing observability stack (Prometheus, Grafana, ELK), including eBPF‑based runtime security.
  • Participate in the security on‑call rotation and contribute to incident triage, containment, and post‑incident review.

Vulnerability Management Engineering

Engineer the vulnerability pipeline: a single consolidated queue enriched with reachability and exploitability context, governed by severity‑based SLAs, and operating on the principle of find → validate → prioritise → hand over to engineering.

Agentic Security Engineering

  • Design and build agentic security systems: LLM tool calling and MCP, structured outputs, evaluation harnesses that verify agent output, and deterministic‑first architecture with bounded LLM judgement and human override.
  • Secure AI systems in production, including prompt‑injection resistance, tool‑permission scoping, MCP server security, and threat modelling aligned to the OWASP LLM Top 10 and emerging agentic threat taxonomies.

Product and Application Security Automation

  • Engineer automated threat modelling and secure design review: threat models generated and maintained from design documents, API specifications, and infrastructure‑as‑code, with human review reserved for high‑risk changes.
  • Define and enforce API security standards as code: specification linting, authentication and authorisation conformance checks, and continuous discovery of undocumented or unauthenticated endpoints.
  • Build continuous multi‑tenant isolation assurance: automated cross‑tenant access probes executed against production‑representative environments, with regressions treated as release‑blocking defects.
  • Integrate mobile application security testing into the build pipeline for released applications.
  • Engineer the vetting pipeline for third‑party extensions and marketplace submissions: automated static and dynamic screening, credential and secret detection, and permission review prior to listing.

Privacy Engineering Automation

  • Build automated data discovery and classification across datastores and pipelines, maintaining a continuously refreshed map of personal data and its flows.
  • Enforce privacy controls as code: detection of personal data in logs and analytics, retention and deletion enforcement, and encryption and key‑management posture checks.
  • Automate the fulfilment of data‑principal requests (access, correction, erasure) and the supporting evidence trail, aligned to the Digital Personal Data Protection Act and applicable frameworks.

Security Enablement Automation

  • Build behaviour‑driven, personalised security training: modules generated and assigned from observed events — a committed secret, a policy breach, a phishing simulation failure — targeted to the individual, their role, and the systems they touch.
  • Measure enablement by behaviour change (repeat‑incident rate, time to remediate), not by completion rates.

Resilience and Chaos Engineering

  • Automate backup assurance: scheduled restore testing with integrity verification, on the principle that an unverified restore is not a backup.
  • Engineer disaster‑recovery validation: automated failover exercises and game days measured against defined RTOs and RPOs.
  • Practise chaos engineering across Kubernetes workloads and critical dependencies: controlled fault injection to verify graceful degradation under failure.
  • Practise security chaos engineering: controlled injection of security failures — a disabled control, a dropped admission webhook, a simulated credential exposure — to verify that detection and response operate as designed.
  • Validate detections continuously through automated adversary emulation.

Compliance Automation

Automate the collection of continuous control evidence (ISO 27001, CIS Benchmarks) in support of ongoing audit readiness.

Some Sepecific Requirements

  • Proficiency in Python, together with Go or advanced shell scripting, and a record of shipping production‑quality tooling rather than scripts.
  • Hands‑on GCP security experience: IAM, networking, and organisational policy, including a working command of authorisation paths.
  • Kubernetes internals and container security on self‑managed clusters.
  • Linux administration and security hardening.
  • Terraform and policy‑as‑code.
  • Depth in code, build, and release management: Git, together with Jenkins, Azure DevOps, or GitHub Actions; familiarity with web servers and reverse proxies (Nginx or equivalent).
  • Fluency in agentic AI‑assisted engineering (Claude Code or equivalent), driven by written specifications and test harnesses, together with the judgement to review AI‑generated code for security defects. Effectiveness of AI leverage is treated as a measure of performance.
  • Demonstrable evidence of building: a public repository, tooling, automation, or technical writing.
  • Two to five years of relevant experience; demonstrated delivery will be given due weight alongside tenure.

Preferred Qualifications (Nice to Have)

  • eBPF runtime security tooling (Falco, Tetragon); distributed tracing and APM applied as security evidence.
  • Chaos engineering tooling (Chaos Mesh, LitmusChaos) and adversary emulation frameworks (Atomic Red Team, Caldera, or equivalent).
  • Exposure to privacy engineering under the Digital Personal Data Protection Act or the GDPR.
  • Mobile application security testing tooling.
  • Workin

Browse similar roles

Is this role actually a fit for you?

hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.

Score it against my resume
Agentic DevSecOps Engineer | SDE‑2 at Fynd — hirly