Job Summary:
We are seeking a highly skilled and experienced Security Development Engineer (SecDev Engineer - III) to design, develop, and secure enterprise-grade products and solutions built on Microsoft technologies. This role demands expertise in secure software development, DevSecOps practices, and cloud security, with a strong focus on embedding security into the development lifecycle. You will play a critical role in ensuring secure, scalable, and resilient application development across our platforms.
Key responsibilities:
• Design, develop, and maintain secure applications across cloud and on-prem environments. • Implement secure coding practices and integrate security into the SDLC (DevSecOps). • Perform code reviews, vulnerability assessments, and remediation. • Build and manage secure CI/CD pipelines with integrated security controls. • Design and implement Azure cloud security controls. • Implement identity and access management (Azure AD, RBAC). • Perform threat modelling and risk assessments. • Improve monitoring and threat detection capabilities. • Collaborate with DevOps, InfraOps, and Security teams. • Mentor junior engineers and contribute to documentation. Technology skills, Competencies and Experience: Application & Security Engineering: • .NET / API / web application security experience • Secure coding practices (OWASP Top 10) • Experience with SAST, DAST tools • Strong understanding and Experience in executing a Security Software Development lifecycle • Gathering/Identifying Security and Privacy requirements • Performing Security and Privacy Risk Assessments in support of the development process• Providing guidance on controls and mitigations for reported security issues • Experience protecting sensitive data and vulnerabilities on Cloud resources • Hands-on experience with web application penetration testing • Excellent communication - verbal and written • Leadership qualities including self-accountability, work-prioritization, meeting facilitation, time management, team co-ordination
Cloud & Microsoft Stack: • Azure IaaS and PaaS services • App Services, Functions, Key Vault, Networking,Logic apps
Identity & Access Management: • Azure AD, RBAC, Conditional Access • OAuth and OpenID Connect
DevSecOps & Automation: • Azure DevOps / GitHub Actions / Jenkins • Infrastructure as Code (Terraform, ARM, Bicep)
Monitoring & Threat Detection: • Microsoft Defender, Azure Sentinel (preferred) • Log analysis and alert response
Scripting & Automation: • PowerShell • Python / Bash (preferred)
Qualification: • Bachelor's degree in Computer Science, Information Technology, or a related field.
Experience: • 6 to 10 years of overall IT experience. • 3-5 years in application security, cloud security, or DevSecOps. • Experience in enterprise product or solution development preferred. Nice to have: • Azure security certifications (AZ-500, SC-200, SC-300) • Knowledge of threat modeling frameworks (STRIDE, MITRE) • Experience in API security • Experience in GenAI related solutioning for security review • Integrate AI-enabled security tools into CI/CD pipelines to support continuous security validation
Work location: Wipfli India, Bengaluru
Skills Required
- Bachelor's degree in Computer Science, Information Technology, or related field
- 6 to 10 years overall IT experience
- 3-5 years in application security, cloud security, or DevSecOps
- .NET and Web API development experience with web application security
- Secure coding practices and knowledge of OWASP Top 10
- Experience with SAST and DAST tools
- Experience executing a Security Software Development Lifecycle (SDLC)
- Performing security and privacy risk assessments and gathering security/privacy requirements
- Hands-on web application penetration testing experience
- Azure cloud security experience (design and implement Azure IaaS/PaaS controls)
- Experience with Azure services: App Services, Functions, Key Vault, Logic Apps, Networking
- Identity and Access Management: Azure AD, RBAC, Conditional Access, OAuth, OpenID Connect
- Build and manage secure CI/CD pipelines (Azure DevOps, GitHub Actions, Jenkins)
- Infrastructure as Code: Terraform, ARM, Bicep
- Monitoring and threat detection experience (Microsoft Defender)
- Experience with Azure Sentinel
- PowerShell scripting skills
- Python or Bash scripting (preferred)
- Excellent verbal and written communication, leadership and mentoring skills
- Experience in enterprise product or solution development
- Azure security certifications (AZ-500, SC-200, SC-300)
- Knowledge of threat modeling frameworks (STRIDE, MITRE)
- Experience in API security and GenAI security solutioning (nice to have)
Wipfli Compensation & Benefits Highlights
-
Leave & Time Off Breadth — Flexible Time Off (unlimited-style PTO) and a broad menu of days off—such as wellness/floating days, paid volunteer time, and even sabbaticals—are highlighted across many roles. Hybrid/remote options further enable practical flexibility in scheduling time away.
-
Parental & Family Support — Generous paid family leave is paired with family-formation benefits including adoption, surrogacy, and fertility services, plus medical travel and gender-affirming care. These offerings signal strong support for a wide range of family needs.
-
Retirement Support — A 401(k) with company match alongside profit-sharing contributions is consistently advertised in current job materials. This pairing strengthens long-term savings beyond standard retirement plans.
Wipfli Insights
What We Do
Wipfli is a leading national advisory and accounting firm with nearly 100 years of serving ambitious middle-market organizations. We understand our clients' unique challenges and help them succeed on their terms through assurance, tax, advisory, outsourcing and technology services. With 2,900+ associates and global alliances, we combine national capabilities with local relationships. "Wipfli" is the brand name under which Wipfli LLP and Wipfli Advisory LLC and its respective subsidiary entities provide professional services. Wipfli LLP and Wipfli Advisory LLC (and its respective subsidiary entities) practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. Wipfli LLP is a licensed independent CPA firm that provides attest services to its clients, and Wipfli Advisory LLC provides tax and business consulting services to its clients. Wipfli Advisory LLC and its subsidiary entities are not licensed CPA firms.
Why Work With Us
At Wipfli, people count. Our people are core to everything we do — the catalyst behind our ability to create exceptional impact and extraordinary results. We believe in flexibility. We focus on relationships. We encourage each individual to follow their own path. And we seek feedback openly, from all.
Gallery
Wipfli Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Freedom to work from anywhere! Wipfli takes a flexible approach in allowing employees to choose to be remote, hybrid, or in-office.





.jpeg)






.jpeg)


