DevSecOps Engineer

Posted 2 Days Ago
Be an Early Applicant
Pune, Mahārāshtra, IND
Hybrid
Mid level
Food • Information Technology • Logistics • Retail
The Role
Embed application security into CI/CD pipelines, investigate and remediate vulnerabilities, perform code reviews and threat modeling, implement security integrations and automations, and collaborate with engineering and corporate security to improve developer security practices.
Summary Generated by Built In
Company Description

Metro Global Solution Center (MGSC) is internal solution partner for METRO, a €31.6 Billion international wholesaler with operations in more than 30 countries. The store network comprises a total of 623 stores in 21 countries, of which 522 offer out-of-store delivery (OOS), and 94 dedicated depots. In 12 countries, METRO runs only the delivery business by its delivery companies (Food Service Distribution, FSD). 

HoReCa and Traders are core customer groups of METRO. The HoReCa section includes hotels, restaurants, catering companies as well as bars, cafés and canteen operators. The Traders section includes small grocery stores and kiosks. The majority of all customer groups are small and medium-sized enterprises as well as sole traders. METRO helps them manage their business challenges more effectively. 

MGSC, location wise is present in Pune (India), Düsseldorf (Germany) and Szczecin (Poland). We provide HR, Finance, IT, Strategy, Branding & Business operations support to 31 countries, speak 24+ languages and process over 18,000 transactions a day. We are setting tomorrow’s standards for customer focus, digital solutions, and sustainable business models. For over 10 years, we have been providing services and solutions from our two locations in Pune and Szczecin. This has allowed us to gain extensive experience in how we can best serve our internal customers with high quality and passion. We believe that we can add value, drive efficiency, and satisfy our customers.

Job Description

  • Embed application security controls into CI/CD pipelines to provide accurate, actionable, and timely feedback to engineers.
  • Support the investigation, remediation, and validation of application security findings including the management of exceptions and false positives.
  • Conduct targeted code reviews in partnership with engineers and platform teams to identify security issues early and improve coding practices
  • Implement and maintain security controls, integrations, and automations required to ensure security and privacy by default across applications and their APIs.
  • Perform threat modeling exercises to identify abuse cases, threat actors, and appropriate preventative and detective controls
  • Participate actively in the engineer community led by METRO Corporate Information Security to define best practices, align way-of-working, prioritize and execute on the needed activities across application and API platforms.

Qualifications

Security experience in one, or more of the following:

  • Application security experience identifying, investigating, and remediating vulnerabilities across all stages of the SDLC.
  • Hands on experience writing and reviewing code and contributing to developer workflows such as design reviews, planning, and implementation.
  • Proven experience designing, implementing, and improving security tooling and CI/CD integrations, with focus on reducing noise and prioritizing risk.
  • Strong focus on developer experience with the ability to communicate security issues clearly.
  • Familiarity with application architectures, including monolithic and microservice based designs.
  • Solid understanding of frameworks such as OWASP Top 10, SAMM, ASVS, and FIRST principles
  • Comfort working across one or more programming languages such as Java, C++, Python, JavaScript or similar.

And:

  • Experience with LLMs, AI, and agentic coding platforms such as Github Co-pilot, Gemini, or Claude Code.
  • Proven experience as a security subject-matter expert, mentoring and raising awareness to security mandates.

Skills Required

  • Embed application security controls into CI/CD pipelines
  • Investigate, remediate, and validate application security findings, manage exceptions and false positives
  • Conduct targeted code reviews with engineers and platform teams
  • Implement and maintain security controls, integrations, and automations to ensure security and privacy by default across applications and APIs
  • Perform threat modeling exercises to identify abuse cases and controls
  • Application security experience across all stages of the SDLC
  • Hands-on experience writing and reviewing code and contributing to developer workflows
  • Designing, implementing, and improving security tooling and CI/CD integrations with focus on reducing noise and prioritizing risk
  • Strong focus on developer experience and ability to communicate security issues clearly
  • Familiarity with application architectures including monolithic and microservice designs
  • Solid understanding of OWASP Top 10, SAMM, ASVS, and FIRST principles
  • Comfort working across programming languages such as Java, C++, Python, JavaScript or similar
  • Experience with LLMs, AI, and agentic coding platforms (e.g., GitHub Copilot, Gemini, Claude Code)
  • Proven experience as a security subject-matter expert, mentoring and raising awareness
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
86,740 Employees
Year Founded: 1964

What We Do

METRO AG is a leading international wholesale and retail group offering food and non-food products under brands like METRO and MAKRO. It serves hotels, restaurants, caterers, and grocery stores, and develops digital solutions for its wholesale business.

Similar Jobs

In-Office
Pune, Mahārāshtra, IND
100000 Employees
In-Office
Pune, Mahārāshtra, IND
100000 Employees

Checkmarx Logo Checkmarx

Devsecops Engineer

Software • Cybersecurity
Hybrid
Pune, Mahārāshtra, IND
902 Employees

Checkmarx Logo Checkmarx

Devsecops Engineer

Software • Cybersecurity
Hybrid
Pune, Mahārāshtra, IND
902 Employees

Similar Companies Hiring

Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account