IAM Architect (AI Security & Identity) at NeoGenCode Technologies Pvt Ltd · Mumbai · 10 - 20 years · ₹18L - ₹28L / yr · Raised funding · Posted 7 Jul 2026

Job Title : IAM Architect (AI Security & Identity)
Experience : 10+ Years
Location : Mumbai (Goregaon East)
Work Mode : Hybrid – 3 Days Work From Office
Contract Duration : 12 Months
Background Verification (BGV) : Mandatory
Job Summary :
We are looking for an experienced IAM Architect to design and implement secure Identity & Access Management (IAM) architectures for enterprise applications, with a focus on AI-enabled solutions.
The ideal candidate should have deep expertise in authentication, authorization, privileged access management, identity lifecycle, and modern identity standards.
Mandatory Skills :
Architect-level IAM expertise, Identity Lifecycle Management (ILM), Access Provisioning, Privileged Access Management (PAM), OIDC, OAuth2, SAML, LDAP, Kerberos, REST APIs, Java/.NET, Microservices, React/Angular, Linux Shell & PowerShell scripting, AI/LLM security, Agentic AI, Secure Token/Credential Management, MCP (or similar) integration, Enterprise IAM Architecture.
Key Responsibilities :
- Design enterprise IAM architecture and reusable security patterns.
- Define secure authentication and authorization models for workforce, customer, and non-human identities.
- Integrate modern authentication protocols (OIDC, OAuth2, SAML) into enterprise applications.
- Develop architecture documents, threat models, security controls, and implementation guidelines.
- Build POCs and validate IAM solutions through APIs, middleware, and policy enforcement.
- Drive secure adoption of AI/Agentic solutions within IAM while ensuring governance and compliance.
- Collaborate with engineering, security, and business stakeholders to implement best practices.
Required Skills :
- Architect-level experience in Identity & Access Management (IAM).
- Strong expertise in Identity Lifecycle Management, Access Provisioning, and Privileged Access Management (PAM).
- Hands-on knowledge of OIDC, OAuth2, SAML, LDAP, Kerberos, REST APIs (SOAP is a plus).
- Experience with Java and/or .NET, microservices, and modern web technologies (React/Angular).
- Scripting experience with Linux Shell and PowerShell.
- Understanding of AI/LLM security, agent-based architectures, token/credential management, and secure tool integrations (MCP or similar).
- Excellent communication and documentation skills.
Preferred :
- Experience in Financial Services or other regulated industries.
- Experience defining enterprise IAM standards and reference architectures adopted across multiple teams.

About NeoGenCode Technologies Pvt Ltd
About
Welcome to Neogencode Technologies, an IT services and consulting firm that provides innovative solutions to help businesses achieve their goals. Our team of experienced professionals is committed to providing tailored services to meet the specific needs of each client. Our comprehensive range of services includes software development, web design and development, mobile app development, cloud computing, cybersecurity, digital marketing, and skilled resource acquisition. We specialize in helping our clients find the right skilled resources to meet their unique business needs. At Neogencode Technologies, we prioritize communication and collaboration with our clients, striving to understand their unique challenges and provide customized solutions that exceed their expectations. We value long-term partnerships with our clients and are committed to delivering exceptional service at every stage of the engagement. Whether you are a small business looking to improve your processes or a large enterprise seeking to stay ahead of the competition, Neogencode Technologies has the expertise and experience to help you succeed. Contact us today to learn more about how we can support your business growth and provide skilled resources to meet your business needs.
Candid answers by the company
IT & Engineering Talent Staffing
- Provides full-time and contract-based hiring, delivering handpicked, pre‑screened developers across tech stacks—ranging from web, mobile, AI/ML, Web3/blockchain.
- Maintains a bench o vetted candidates, offering fast delivery of interview-ready profiles—often within 24 hours.
- Offers payroll management, handling compliance, tax, attendance, and documentation for both contractors and full-time employees.
2. End-to-End Project Delivery
- Delivers full-stack development solutions: web, mobile, cloud, AI/ML, Blockchain/Web3.
- Manages entire project lifecycle—requirements gathering, design (UI/UX), development, deployment, and ongoing support .
3. Additional Offerings
- Expands into cybersecurity consulting, digital marketing, and cloud platform services (like AWS, GCP, Azure) .
- Provides strategic IT consulting to align technology solutions with business objectives
Similar jobs (10)
Job Description:
Lead regional transformation programs, driving the entire solution architecture lifecycle,
from conceptualization to execution, with a focus on agile and DevOps practices.
Accountable for leading the IT Architecture for all projects and programs, focusing on
innovative business and IT solutions in the insurance domain, such as new-age digital
platforms, cloud-native applications, AI/ML-powered decision-making, and data-driven
insights.
Preferred skills
• Demonstrated expertise in developing cloud-native, microservices-based, and API
driven insurance solutions, leveraging modern architectural patterns and emerging
technologies such as AI/ML, big data, and IoT.
• Thorough understanding of common patterns, frameworks, and reference
architectures for the Insurance domain, with a focus on digital transformation and
innovation.
• Proven experience in leading regional transformation programs, driving the adoption
of agile and DevOps practices.
• Asia regional experience is an advantage.
Qualifications
Minimum Bachelor's degree, preferably with a Master's degree in Computer Science,
Engineering, or a related discipline.
• 15+ years of IT experience, with a minimum of 7+ years in the insurance industry,
focusing on the application of emerging technologies.
About the Role
We are looking for an experienced Solution Architect / Technical Lead to lead solution architecture, system integrations, and Azure platform design for a Visitor Management System project in Abu Dhabi.
The ideal candidate will have 10+ years of experience in software projects, strong expertise in Microsoft Azure, solution architecture, integrations, and enterprise application design, along with the ability to lead technical teams and stakeholders.
Key Responsibilities
- Lead the overall solution architecture and technical design of the Visitor Management System.
- Design and implement scalable, secure, and high-performing solutions on Microsoft Azure.
- Define Azure cloud architecture, infrastructure components, networking, security, and deployment strategies.
- Lead integration architecture between the Visitor Management System and external/enterprise applications.
- Design and oversee APIs, web services, and system integrations.
- Provide technical leadership throughout the software development lifecycle.
- Review existing systems and recommend improvements in architecture, scalability, performance, and security.
- Prepare technical architecture documents, solution designs, integration specifications, and technical documentation.
- Work closely with development, infrastructure, security, and project management teams.
- Troubleshoot complex technical and architectural issues and provide effective solutions.
- Ensure solutions follow enterprise architecture, security, and coding best practices.
- Participate in technical discussions with clients and stakeholders and translate business requirements into technical solutions.
- Mentor and guide technical teams on architecture and implementation.
Required Technical Skills
- Strong experience in Solution Architecture / Technical Architecture
- Strong hands-on experience with Microsoft Azure
- Azure platform and cloud architecture
- Azure services, infrastructure, networking, and security
- API and system integration
- REST APIs / Web Services
- Microservices and distributed application architecture
- Enterprise application architecture
- Database architecture and SQL
- Azure DevOps / CI-CD
- Identity & Access Management / Microsoft Entra ID
- Cloud security, scalability, performance, and high availability
- Software development lifecycle and Agile methodologies
Required Experience
- 10+ years of experience in software projects
- Proven experience as a Solution Architect, Azure Architect, Technical Architect, or Technical Lead
- Strong experience designing and implementing enterprise-level software solutions
- Experience leading technical teams and working with multiple stakeholders
- Experience with Azure-based architecture and integrations
- Experience in visitor management, access control, security systems, or similar enterprise systems will be an advantage
Greetings from zealous sevices!
GoLang (Soln Architect) -(9 AM to 6PM)
Experience: 10-12 Yrs
Need a senior Solution Architect - No BGV - ok with consultants
Own end-to-end solution architecture for a cloud-based cybersecurity platform operating at massive scale (millions of assets), spanning multiple product modules and a broad third-party integration ecosystem.
What They'll Do
Define and own the overall solution architecture across multiple product modules (e.g., detection, response, asset inventory, reporting), ensuring they work as a coherent, scalable system rather than disconnected parts
Design for scale: architecture that reliably handles millions of assets/endpoints with predictable performance, cost, and reliability as volume grows
Lead cloud infrastructure architecture decisions, compute, storage, networking, multi-region/multi-tenant strategy, disaster recovery
Architect and govern third-party integrations (SIEM/SOAR, ticketing, identity providers, cloud provider APIs, threat intel feeds, etc.), define integration patterns, data contracts, and reusable frameworks rather than one-off connections
Create and maintain architecture roadmaps, capacity plans, and technical strategy aligned with product/business roadmap
Set architectural standards and guardrails (scalability, security, data flow, API design) across engineering teams
Act as the technical bridge between engineering, product, security, and infrastructure/DevOps teams
Conduct architecture reviews, threat-model system designs, and identify scaling bottlenecks or single points of failure before they hurt production
Own key non-functional requirements: performance, availability, security, cost-efficiency, compliance
Support presales/enterprise customer conversations on architecture, especially for large or complex deployments
Evaluate and select core technologies (data stores, messaging systems, orchestration, IaC tooling)
What They Should Have
8–12+ years in software/infra engineering, with 4+ years specifically in a solution/enterprise architect role
Proven experience architecting systems at scale (millions of records/assets/events), not just designing on paper, but having operated such systems in production
Deep cloud architecture expertise (AWS/GCP/Azure), multi-account/multi-tenant design, cost optimization, networking, IAM
Strong grasp of distributed systems patterns: data partitioning, eventual consistency, event-driven architecture, caching strategies
Experience designing integration architectures (APIs, webhooks, message queues) across many heterogeneous third-party systems
Security architecture fluency,this is a security product, so the architect must think adversarially about their own system
Ability to produce architecture documentation (C4 diagrams, ADRs, data flow diagrams) that both engineers and executives can use
Track record of cross-functional influence, able to align multiple engineering teams around a shared architecture without direct authority
Cybersecurity domain knowledge (SIEM/EDR/CNAPP/CSPM concepts, threat detection pipelines), or equivalent adjacent domain with fast ramp-up ability
Nice to Have
Experience with specific integration ecosystems relevant to your product (e.g., Splunk, ServiceNow, Okta, AWS Security Hub)
Familiarity with IaC (Terraform), service mesh, and Kubernetes at scale Enterprise/regulated-industry experience (SOC 2, FedRAMP, ISO 27001) shaping architecture decisions
Prior experience scaling a product from ""hundreds of thousands"" to ""tens of millions"" of managed assets

We are seeking an experienced Solution Architect with deep expertise in Wi-Fi technologies (focus on Cisco Meraki and Cisco Enterprise), and authentication technologies (Cisco Identity Services Engine), to lead the design, implementation, and optimization of our network strategy. The ideal candidate will possess a strong technical background in Wi-Fi design, hands-on experience with python scripts, and a proven track record of delivering secure, scalable, and robust solutions in complex environments.
Solution Architecture and Design :
• Architect for design, integration and management of Cisco Meraki and Enterprise solution.
• Architect for design, integration and management of Authentication solution.
• Analyze current business processes, IT infrastructure, and security requirements to develop security of our network solution.
• Develop high-level and detailed architecture diagrams, technical documentation, and integration designs.
• Ensure solutions align with enterprise security architecture, regulatory requirements (GDPR, SOX, etc.), and industry best practices.
Technical Competencies
• Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
• Strong expertise on Wi-Fi standards and protocols
• Strong expertise on Cisco Meraki, Cisco Enterprise
• Strong expertise on Authentication mechanisms and protocols – Cisco Identity Services Engine OR ISE knowledge is a must have.
• Expertise on Infrastructure as code (Python, Ansible, AWX)
• 10+ years of experience in complex network environments
• Certification : Cisco CCIE Wireless is strong advantage for this position
• Certification : Cisco CCIE Security is strong advantage for this position
• General shift business hours : from 10:30 AM to 7:30 PM IST
Position
Solution Architect/Technical Architect
Experience
· 12 - 16+ years of overall IT experience
· Significant hands-on experience working as a Solution/Technical Architect
Education
· B.Tech / M.Tech / MCA / MBA or equivalent
Certifications
· TOGAF® certification (Level 1/2) preferred to ensure alignment with enterprise architecture standards
· Microsoft Certified: Azure Solutions Architect Expert (AZ-305) and other supporting certifications such as AZ-104, AZ-400, or AZ-500 preferred.
Key Responsibilities
· Define and evolve the target architecture for .NET-based distributed platform.
· Architect highly configurable solutions on Azure with strong focus on scalability, tenant isolation, resilience, maintainability, and speed of delivery.
· Lead solution design across ASP.NET Core services, REST APIs, event-driven workflows, background processing, integration patterns, and shared platform capabilities.
· Drive adoption of modern .NET and cloud-native patterns including microservices, domain-driven design, event-driven architecture, API-first design, and secure service-to-service communication.
· Partner with engineering teams on real implementation decisions, review critical designs and code paths, and provide hands-on guidance for performance, operability, and production readiness.
· Architect Azure-native deployment patterns using AKS, containers, API Management, Service Bus/Event Grid or equivalent messaging, Key Vault, managed observability, and CI/CD automation.
· Work with data and platform teams on PostgreSQL-backed service design, data access patterns, caching strategies, and database performance for high-volume transactional workloads.
· Define non-functional requirements and architecture guardrails around performance, scalability, availability, recoverability, security, compliance, and cost efficiency.
· Embed DevSecOps and observability into platform design through telemetry, tracing, alerting, diagnostics, secrets management, and release governance.
· Evaluate emerging technologies, AI-assisted engineering enablers, and modernization options pragmatically, with clear build-vs-buy and risk-reward trade-offs.
· Mentor senior engineers and technical leads, contribute to architectural governance, and create reusable patterns, reference implementations, and standards across teams.
· Bachelor’s or master’s degree in computer science, Engineering, or a related field.
· 12–16 years of experience in software engineering, solution architecture, or platform engineering, with significant experience in Microsoft technology stacks.
Essential Qualification and Skills
· Strong hands-on expertise in C#, .NET / .NET Core / .NET 8, ASP.NET Core, Web APIs, background services, and enterprise application design.
· Deep experience in architecting distributed systems using microservices, asynchronous messaging, event-driven design, and API-led integration patterns.
· Strong Azure architecture experience, preferably across AKS, App Services, Functions, API Management, Key Vault, Service Bus, Event Grid, Storage, monitoring, and identity integration patterns.
· Experience designing and supporting platforms, configurable product architectures, and integration-heavy enterprise solutions.
· Strong understanding of relational databases and performance engineering, especially SQL Server and/or PostgreSQL, including schema design, indexing, query tuning, and transaction handling.
· Solid grasp of non-functional architecture including performance, scalability, availability, fault isolation, observability, and disaster recovery.
· Strong understanding of application and platform security including authentication, authorization, secrets management, encryption, secure coding, and compliance-oriented design.
· Experience with containers, Kubernetes, CI/CD, infrastructure automation, and modern DevSecOps practices.
· Ability to make sound architecture decisions with a balance of pragmatism, delivery speed, engineering quality, and long-term maintainability.
· Strong communication and stakeholder management skills across product, engineering, architecture, operations, security, and client-facing teams.
Skills & Competencies
· Experience in insurance, Insurtech, BFSI, or other regulated, transaction-heavy domains.
· Exposure to policy administration, billing, accounting, claims, workflow orchestration, or reporting platforms within the insurance value chain.
· Experience with architecture frameworks and modelling approaches such as TOGAF, domain-driven design, UML, C4, or equivalent practical architecture methods.
· Familiarity with mixed technology landscapes involving .NET, Java/Spring Boot, enterprise workflow tools, and integration ecosystems.
· Experience with observability and reliability tooling such as Datadog, Dynatrace, Application Insights, Open Telemetry, Grafana, or similar.
· Working knowledge of Angular, React, or modern web application architecture patterns.
· Exposure to AI-enabled engineering, intelligent automation, or embedding AI capabilities into enterprise platforms.
· Leadership experience across globally distributed or virtual teams.
Company Description
Appiness Interactive Pvt. Ltd. is a Bangalore-based product development and UX firm that specializes in digital services for startups to fortune-500s. We work closely with our clients to create a comprehensive soul for their brand in the online world, engaged through multiple platforms of digital media. Our team is young, passionate, and aggressive, not afraid to think out of the box or tread the un-trodden path in order to deliver the best results for our clients. We pride ourselves on Practical Creativity where the idea is only as good as the returns it fetches for our clients.
Role Overview
We are looking for an experienced Senior Cloud Security Engineer with 7+ years of experience, including strong hands-on expertise in AWS Cloud Security. The candidate will be responsible for designing, implementing, assessing, and continuously improving security across AWS cloud environments. The role requires strong knowledge of cloud security architecture, IAM, network security, threat detection, vulnerability management, incident response, security monitoring, encryption, and DevSecOps.
This is a highly technical position. Hands-on technical expertise will be given significantly more importance than communication skills. Good written and verbal communication is sufficient.
Key Responsibilities
- Design and implement secure AWS cloud architectures.
- Establish and maintain AWS security best practices and security controls.
- Implement IAM, RBAC, least-privilege access, MFA, federation and privileged access controls.
- Secure AWS networking including VPCs, Security Groups, NACLs, routing, private/public subnets and VPC endpoints.
- Implement and manage AWS security services including:
- AWS IAM
- AWS KMS
- AWS CloudTrail
- Amazon GuardDuty
- AWS Security Hub
- AWS Config
- AWS WAF
- AWS Secrets Manager
- Monitor and investigate security events, threats and suspicious activities.
- Lead or participate in cloud security incident response and root-cause analysis.
- Conduct vulnerability assessments and coordinate remediation.
- Perform AWS security posture reviews and identify misconfigurations.
- Review cloud architectures and provide security recommendations.
- Implement encryption and data protection controls.
- Secure CI/CD pipelines and support DevSecOps practices.
- Review Infrastructure as Code for security risks.
- Implement security automation wherever possible.
- Work with engineering, DevOps and infrastructure teams to embed security into the development lifecycle.
- Establish security standards, policies and controls for AWS environments.
- Support compliance requirements and security audits.
- Mentor junior engineers and provide technical guidance.
Mandatory Technical Skills
Must Have
- 7+ years of overall IT/Security/Cloud experience
- Strong AWS Cloud Security experience
- Hands-on AWS security architecture
- AWS IAM
- IAM policies, roles, permissions and least privilege
- AWS networking security
- VPC, Security Groups and NACLs
- CloudTrail and security logging
- GuardDuty
- Security Hub
- KMS and encryption
- Vulnerability management
- Cloud security monitoring
- Incident response
- Security hardening
- Security architecture/design
Good to Have
- AWS Organizations / SCP
- Terraform / CloudFormation
- DevSecOps
- CI/CD security
- Docker/Kubernetes security
- SAST/DAST/SCA
- SIEM tools
- Python/Bash/PowerShell scripting
- CIS Benchmarks
- NIST
- ISO 27001
- SOC 2
- AWS security certifications
DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.
1. Primary Must-Have Competencies (Core Priorities)
A. AWS Networking & VPC Topology (Top Priority)
- Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
- Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
- Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.
B. AWS Security, IAM Architecture & Compliance
- Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
- Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
- Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.
C. Infrastructure as Code (IaC) & Containerization
- Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
- Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).
D. Architecture Documentation & Systems Mapping
- Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.
2. Secondary Competency (Strong Advantage, Not Mandatory)
- Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
- Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.
Skill: Java Architect
Location: Pune Baner Office
Note: Client F2F is mandate
Budget:33 LPA
Experience: 10+ Years
Mandate Skills- Cloud+ Java Architect
Who are we looking for?
We are looking for a Technical Architect, having strong software design and development experience of 9+ years on Core Java, Spring Boot, REST API, AWS & Microservices.
Technical Skills:
Proficient in software Design and development and familiar with technologies - Java, Java-J2EE, Spring Boot, Hibernate, Ajax, REST API, Microservices etc.
Working knowledge of JVM internals
Working knowledge in Mongo DB
Working knowledge of any database (MySQL or HSQLDB)
Working knowledge of No-SQL database (Mongo or Dynamo DB)
Working experience with messaging (JMS/RabbitMQ)
R & D on new advanced cloud-based technologies in a test-driven agile development.
Experience in designing and architecting systems with high scalability and performance requirements
Ability to design infrastructure for performance evaluation and reporting of cloud-based services, namely AWS
In depth knowledge of key AWS services like EC2, S3, Lambda, CloudWatch etc.
Certification on AWS architecture desirable
Roles and Responsibilities:
Participate and contribute in platform requirements/story development.
Contribute to the solutioning, design and design alternatives to the requirements/stories and also participate in design reviews.
Involve in Platform Sprint activities.
Development of assigned stories in appropriate languages defined for each module.
Participate in peer code reviews
Develop use cases and do unit test cases and execute them part of continuous integration pipeline.
Understand stack deployment and resolve issues with components in stacks across the ecommerce platform.
Process Skills:
Agile – Scrum and Test-Driven Development
Qualification:
Bachelor of Engineering (Computer background preferred)
We’re on hunt for AI Architect
Responsibilities:
- 10–15+ years overall experience, with recent hands-on AI/GenAI architecture ownership.
- Must have architected enterprise AI platforms/solutions end-to-end, not just individual ML models or PoCs.
- Strong GenAI/LLM production experience: RAG, embeddings, vector DBs, hybrid search, reranking, evaluation, guardrails.
- Strong Agentic AI understanding: agents, tool calling, workflows, orchestration, human-in-the-loop.
- Experience taking AI solutions from architecture → production → scale, ideally across multiple business teams/use cases.
- Strong cloud architecture — Azure/AWS preferred; hybrid/on-prem experience is a plus.
- Must understand enterprise security, governance, Responsible AI, observability and LLMOps/MLOps.
- Should be able to articulate build-vs-buy, MVP-vs-target architecture, cost/performance/security tradeoffs.
- Strong stakeholder-facing / consulting ability — can work with business leaders, engineering, security and data teams and influence without authority.
There is scope to move to the US for this role if you are aligned for the same, else this will be a WFO role from Hyderabad location
Job Title: AppSec / AI Security Engineer
Employment Type: Full-time/ Permanent
Location: Indore (Work from Office)
About the Role
We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.
If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.
Key Responsibilities
- Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
- Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
- Develop structured code review workflows incorporating specifications, scan results, and code provenance.
- Optimize security scanning tools to reduce false positives and drive developer adoption.
- Investigate and manage security findings using established remediation and documentation processes.
- Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
- Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.
Required Skills & Experience
- Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
- Experience implementing automated security scanning and enforcement — not just operating existing tools.
- Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
- Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
- Ability to design, build, and own security automation and governance solutions from the ground up.
- Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
- Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
- Strong analytical mindset and ability to independently assess security risk across internal and external codebases.
Preferred Qualifications
- ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
- Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
- Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
- AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
- Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
- Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).
About Company:
Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.
For more info, please visit our website: https://5exceptions.com





