FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

DevSecOps Engineer, Product Security
Weekday (YC W21). Implement security checks, scanning, and quality gates across the SDLC .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in implementing security measures across the SDLC, with a focus on secure coding practices, vulnerability management, and risk assessment in cloud environments. Proficient in driving remediation efforts and collaborating with cross-functional teams to enhance application and API security.
Highest-signal resume keywords
DevSecOps ExperienceApplication/API SecurityGoogle Cloud SecurityOWASP Top 10 KnowledgeCI/CD Security Practices
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Secure Coding PracticesVulnerability IdentificationThreat ModellingPythonReactPostgreSQLInfrastructure-as-Code SecurityContainer SecurityGitHub ActionsSAST
Soft Skills
CollaborationProblem-SolvingAnalytical Thinking
Tools & Technologies
GCP Security Command CenterCodeQLSemgrepSonarQubeDependabotTrivyOWASP ZAPBurp SuiteSIEMCloud Monitoring
Certifications & Qualifications
SOC 2ISO 27001
Industry Keywords
AI SecuritySaaS IntegrationsSecurity ArchitectureIncident ResponseSecurity Drills
Tech Stack
Tools & technologiesCloudGoogle Cloud PlatformKubernetesPostgresPythonReactSDLC
About the role
Key responsibilities & impact- Implement security checks, scanning, and quality gates across the SDLC
- Champion secure coding and remediation practices
- Review authentication, authorization, APIs, tenant isolation, and access controls
- Identify and mitigate OWASP and API security risks through threat modelling
- Assess AI agents, prompts, connectors, and data-access risks
- Protect against prompt injection, data leakage, tool misuse, and unsafe AI actions
- Secure Google Cloud IAM, service accounts, networking, secrets, and workloads
- Enforce least privilege and environment separation
- Harden GitHub Actions, dependencies, and deployment pipelines
- Implement secret protection, SCA, SBOM, and secure release processes
- Establish vulnerability identification, prioritization, tracking, remediation coordination, and fix validation
- Strengthen security logging, alerting, and investigation capabilities
- Support incident response, root-cause analysis, and security drills
- Maintain audit-ready security evidence
- Support penetration testing, compliance activities, and security architecture documentation
- Work with developers, architects, cloud engineers, and product teams to drive vulnerabilities through resolution
Requirements
What you’ll need- 4–7 years of experience
- Hands-on DevSecOps and application/API security experience
- Working knowledge of OWASP Top 10, Python backends, and React applications
- Strong GitHub and CI/CD security experience, including pull requests, GitHub Actions, SAST, dependency and secret scanning
- Experience securing Google Cloud environments, including IAM, service accounts, least-privilege access, and containerized workloads
- Ability to assess real risk and drive practical remediation
- Experience securing AI platforms, SaaS integrations, or sensitive data pipelines preferred
- PostgreSQL and Infrastructure-as-Code security, GCP Security Command Center, and container/Kubernetes platforms preferred
- Familiarity with CodeQL, Semgrep, SonarQube, Dependabot, Trivy, OWASP ZAP, or Burp Suite preferred
- Exposure to SIEM, cloud monitoring/MDR, and SOC 2 or ISO 27001 preferred
- Security experience with AI/LLM systems, agents, and RAG-based applications preferred
Benefits
Comp & perks- Work across multiple modern product engineering teams and influence security architecture on real production systems
- Build hands-on depth in AI security, cloud security, and application security
- Build scalable security automation used across multiple global clients
- Partner directly with engineering, architecture, and product leadership