Director, DevSecOps (AI-First)
Jupiter · Bengaluru, Karnataka, India
قدّم وتابع مع أبلاي إيدجIf you've spent the last decade building platform and security in fast-moving product companies, and lately found yourself thinking"most of what my team does could be an agent"— this is the role.The tension we're hiring you to resolveJupiter is a regulated fintech. ~370 repos, ~50 engineers, live money moving 24×7, RBI-supervised partnerships (CSB, Federal), PCI-DSS card issuance, DPDP obligations, a multi-cloud AWS + OCI estate, dozens of Account Aggregator and bureau integrations. Under normal physics, you'd staff this surface with a 15-person platform team plus a 15-person AppSec org — the size of our entire engineering team.We don't want either.We already run one of the most AI-augmented pipelines in Indian fi ntech — our internal agentJarvis ships real code, triages alerts, and reviews PRs across the whole estate every day. Our engineers move fast because the paved road is intelligent. We want the same for platform and security together. That's your job.What "AI-first DevSecOps" means at JupiterNot "we bought a Copilot license." It means: Deployment orchestration, capacity planning, incident triage, CVE work, threat modeling, IaC review, cost anomaly detection — all designed as agent loops first, human-supervised and continuously improvedEvery "senior SRE would have caught this rollback" and every "senior AppSec would have caught this XSS" becomes a repeatable, evaluated agent check — codified, not tribal Deploy latency, incident MTTR, security-review latency, unit cost per transaction —metrics you drive down quarterly, not queues you defendAuditors and partners get automated evidence packs, not spreadsheet marathonsWhat you'll actually ownPlatform / DevOpsThe paved road for shipping: CI/CD, Spinnaker deploy pipelines, build systems, feature flags, release gatesCloud + Kubernetes across a multi-cloud estate (AWS + OCI, multiple accounts); IaC (Terraform +Terragrunt for cloud, Helm 3 + Kustomize for K8s) as the source of truthObservability platform: logs, metrics, traces, alerting as a product engineers want to useSRE practice: on-call, incident command, error budgets, capacity + cost engineeringDeveloper experience: local dev, preview environments, secrets provisioning, self-serve infraSecurityAppSec paved road: SAST / DAST / SBOM / secret-scan / IaC scan/dependency CVE triage —as PR checks that don't get routed aroundCloud + K8s security posture; IAM boundaries, network segmentation for partner integrationsThreat modeling on every new service touching money, PII, or a partner APIIncident response: detection, containment, forensics, post-mortemsRBI cyber framework, PCI-DSS, DPDP — as artifacts your pipelines emit, not documents your team writes; future-ready for ISO 27001 / SOC 2 when we choose to pursue themDirect interface with banking partners and regulators on our security + reliability postureExperience & background we're looking forNon-negotiable 15+ years total in software engineering, of which 8+ years hands-on across DevOps / Platform / SRE and Application / Cloud Security (real depth in both — not "managed a team that did it")6+ years leading engineering teams, at least 2 as second-line (managing managers or senior ICs)3+ years in a regulated industry — fintech, banking, healthtech, or an equivalent audit-heavyenvironment. You've been through at least one RBI / PCI-DSS (or equivalent) audit as an owner, not a bystander. SOC 2 / ISO 27001 experience is a plus.Deep AWS + Kubernetes production experience (multi-account, IAM, VPC, EKS, IaC via Terraform / Terragrunt + Helm / Kustomize). OCI experience is a plus.Hands-on with modern LLM tooling (Claude / GPT / agentic frameworks) for real engineering work — you've shipped or heavily used AI dev tools in the last 12 months, not just experimentedCan read Kotlin, Scala, and TypeScript comfortably; write Python fluentlyStrong plusPreviously built the DevSecOps function at an Indian fintech under RBI supervisionRan incident command for a Sev-1 that touched customer money — and led the post-mortemPublic work: OSS contributions to security or platform tooling, conference talks, technical blog with depthCertifications: CISSP / CCSP / OSCP (security), CKA / CKS (Kubernetes), AWS Security Specialty nice signals but we care about what you've shipped, not what you've certifiedHistory of hiring and retaining strong ICs (references we can call)Explicit non-requirementsMBA / management degree — irrelevant hereBig-Tech (FAANG) tenure — nice signal, not required; we've seen more Jupiter-fit talent from product startups than from BigCoPrior "Director" title — if you're a Principal / Staff who's been operating at Director scope, applyYou know it's you if…You've shipped platform tooling and security tooling that engineers didn't route around bothYou can read Kotlin, Scala, and TypeScript, and you write Python without thinking about itYou've owned an on-call rota you'd want to be onYou've been hands-on with Claude / GPT / agentic frameworks for real work — not just chatYou've run platform or security in a regulated environment and know what a real audit feels likeYou believe the future infra + security leader is 30% engineer, 30% agent-builder, 40% coach —and you're excited about the middle 30%You should probably skip this if…You want to lead a large team from day one (small strong team, senior-IC-heavy, is by design)You prefer governance to buildingYou're skeptical that agents can do meaningful platform or security work — we'd rather hire someone who's already proven it to themselvesYou want to specialize in only one side (only Sec, only DevOps) — the whole point of this role is one strong leader across bothThe offerReports directly to the President.Board-level visibility on infra + security posture.Small strong team, budget to build (tooling, agents, headcount as we scale).Bangalore, work from office.Comp calibrated to senior director / VP band at leading Indian fintechs.