Job description

**Job Description** **About Persistent** We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what's next. Our offerings and proven solutions create a unique competitive advantage for our clients by giving them the power to see beyond and rise above. We work with many industry-leading organizations across the world, including 20 Fortune 50 companies and 4 of the 5 top banks in both the US and India, and numerous innovators across the healthcare ecosystem. Our disruptor's mindset, commitment to client success, and agility to thrive in the dynamic environment have enabled us to sustain our growth momentum. Persistent has been recognised across top industry platforms for innovation, leadership, and inclusion. We reported $1,654.4M FY26 revenue with 17.4% Y-o-Y growth. We have delivered 24 sequential quarters of growth with $436.0M in Q4 FY26 revenue, up 3.2% Q-o-Q and 16.2% Y-o-Y growth. Our 27,500+ global team members, located in 18 countries, have been instrumental in helping market leaders transform their industries. **About Position:** We are seeking a highly skilled Cyber Security Engineer with expertise in Application Security, Code Security, Secrets Management, and DevSecOps. The ideal candidate will work closely with Engineering, DevOps, Infrastructure, and Development teams to strengthen security across source code repositories, CI/CD pipelines, cloud-native platforms, and containerized environments. This role is critical in establishing secure development practices, reducing organizational risk, and driving security-by-design principles across the software development lifecycle. - **Role: Cyber Security Engineer** - **Location: Pune** - **Experience: 8 to 12 Years** - **Job Type: Full Time Employment** **What You'll Do:** - Identify, analyze, and remediate security vulnerabilities across source code repositories using automated and manual assessment techniques. - Implement and enforce secure coding standards and application security best practices across engineering teams. - Manage and secure sensitive information such as API keys, passwords, tokens, certificates, and credentials using enterprise secrets management solutions. - Integrate security controls and automated scanning tools into CI/CD pipelines. - Perform security assessments and vulnerability remediation activities for applications, repositories, and development environments. - Collaborate with Development, DevOps, and Engineering teams to prioritize and resolve security findings based on business impact and risk. - Support secure deployment and configuration of containerized applications using Docker and Kubernetes. - Work with Infrastructure and Platform teams to harden operating environments and reduce attack surfaces. - Automate security validation, monitoring, and remediation workflows using Python-based tools and scripts. - Support repository security, branch protection, access controls, and governance policies. - Monitor security alerts, vulnerabilities, and threat indicators and drive remediation activities. - Maintain security standards, policies, technical documentation, and remediation guidelines. - Participate in architecture reviews and security design assessments. - Promote security awareness and a security-first culture within engineering teams. - Support compliance, audit, and governance initiatives related to secure software development. **Expertise You'll Bring:** - 8-12 years of experience in Cyber Security, Application Security, DevSecOps, or Secure Software Engineering. - Strong understanding of secure software development lifecycle (SSDLC) principles. - Hands-on experience identifying and remediating application security vulnerabilities. - Deep knowledge of OWASP Top 10 - Secure Coding Practices - Threat Modeling - Vulnerability Management - Risk Assessment - Experience implementing Security-by-Design principles within software development environments. - Strong experience with GitHub or equivalent source code management platforms. - Knowledge of repository security controls, branch protection, access management, and governance. - Experience reviewing code for security vulnerabilities and insecure patterns. - Understanding of software supply chain security and dependency management. - Experience working with Software Composition Analysis (SCA) tools. - Hands-on expertise with enterprise secrets management solutions. - Experience managing API Keys - Access Tokens - Credentials - Certificates - Encryption Keys - Knowledge of vault technologies and Key Management Systems (KMS). - Understanding of secrets rotation, encryption, and secure credential management practices. - Experience integrating security controls into CI/CD pipelines. - Strong understanding of DevSecOps methodologies and automation frameworks. - Knowledge of continuous security testing and compliance validation. - Experience implementing automated security gates within deployment pipelines. - Familiarity with release management and secure deployment processes. - Strong hands-on experience with Docker - Kubernetes - Container Security - Experience securing containerized workloads and Kubernetes environments. - Knowledge of container hardening, image scanning, and runtime security controls. - Exposure to cloud platforms such as Microsoft Azure - AWS - Google Cloud Platform (GCP) - Understanding of cloud-native security architectures and controls. - Strong Python programming and scripting skills. - Experience developing automation for security monitoring, scanning, and remediation. - Knowledge of Linux operating systems and administration fundamentals. - Ability to automate security workflows and operational processes. - Hands-on experience with security tools such as SonarQube - Snyk - Cycode - Checkmarx - Veracode - Fortify - OWASP ZAP - Experience with Static Application Security Testing (SAS