Lead DevSecOps Engineer

Posted Yesterday
Be an Early Applicant
2 Locations
In-Office
Expert/Leader
eCommerce
The Role
Lead DevSecOps initiatives across the engineering lifecycle: embed SAST/DAST and vulnerability scanning into CI/CD, design secure cloud-native architectures, automate secrets and IAM controls, integrate security tooling, lead incident response, run training and blameless postmortems, and own compliance readiness (SOC2, ISO 27001, PCI-DSS).
Summary Generated by Built In
About GoKwik
GoKwik is a growth operating system designed to power D2C and eCommerce brands from checkout optimisation and reducing return-to-origin (RTO), to payments, retention, and post-purchase engagement. Today, GoKwik enables over 15,000+ merchants worldwide, processes around $2 billion in GMV, and is strengthening its AI-powered infrastructure. Backed by RTP Global, Z47, Peak XV, and Think Investments and bolstered by a $13 million growth round in June 2025 (total funding: $68 million), GoKwik is scaling aggressively across India and the UK.

Why This Role Matters
At GoKwik, Security isn’t a bolt-on, it’s a core part of how we build, ship, and scale. As a Lead DevSecOps Engineer, you’ll ensure every layer of our infrastructure and development lifecycle is secure, compliant, and resilient. You’ll work end-to-end with Engineering teams, from design and deployment using agentic platforms to operations and optimisation, embedding security guardrails into CI/CD pipelines, automating IAM and compliance checks, and reducing human error to near zero. You’ll also shape a culture where security is a shared responsibility, not a last-minute review, while staying battle-ready with AI first thinking to lead incident response and drive blameless learning. In short, you’ll own the frameworks and practices that let GoKwik grow fast without ever compromising trust, directly protecting $2B+ GMV and thousands of merchants who rely on us every day.


What You'll Own
  • Build secure CI/CD pipelines by embedding vulnerability scanning, SAST, and DAST, ensuring every release ships fast and safe.
  • Partner with engineering and security teams to design cloud-native architectures that are secure by default and resilient at scale.
  • Automate the boring stuff, from secrets management and IAM policy enforcement to compliance validation checks, cutting down human error and accelerating delivery.
  • Integrate best-in-class security tools (Vault, Prisma, Aqua, Trivy, etc.) into every layer of our infrastructure
  • Take the lead during security incidents, coordinating response across teams and ensuring issues are remediated quickly and effectively.
  • Drive a proactive DevSecOps culture by running training, awareness programs, and blameless postmortems that turn incidents into learnings.
  • Own compliance readiness (SOC2, ISO 27001, PCI-DSS), working closely with governance and legal to keep us always audit-prepared without slowing down engineering.


Who You Are
  • 8-12 years of hands-on and leading experience in DevSecOps or Cloud Security Engineering within fast-scaling SaaS or eCommerce environments.
  • Exposure to AI/LLM security frameworks and modern AI risk models.
  • Strong grasp of AppSec and Cloud Security fundamentals, from IAM, WAF, and KMS to CSPM best practices.
  • Practical experience with Kubernetes security (RBAC, PodSecurity, NetworkPolicies) and keeping clusters production-hardened.
  • Comfortable with threat modelling, incident response, and security compliance frameworks (ISO, SOC2, PCI-DSS).
  • Solid coding/scripting skills (Python, Go, Bash, etc.) to automate controls and eliminate repetitive manual work.
  • Someone who doesn’t just know the theory but has battle-tested experience in securing systems at scale.

Why GoKwik
At GoKwik, we aren’t just building tools, we’re rewriting the playbook for eCommerce in India. We exist to solve some of the most complex challenges faced by digital-first brands: low conversion rates, high RTO, and poor post-purchase experience. Our checkout and conversion stack powers 500+ leading D2C brands and marketplaces and we’re just getting started.

Skills Required

  • 8-12 years hands-on and leading experience in DevSecOps or Cloud Security Engineering
  • Exposure to AI/LLM security frameworks and modern AI risk models
  • Strong grasp of AppSec and Cloud Security fundamentals (IAM, WAF, KMS, CSPM)
  • Practical experience with Kubernetes security (RBAC, PodSecurity, NetworkPolicies)
  • Experience embedding vulnerability scanning, SAST, and DAST into CI/CD pipelines
  • Solid coding/scripting skills to automate controls (Python, Go, Bash)
  • Experience integrating security tools (Vault, Prisma, Aqua, Trivy)
  • Hands-on experience with secrets management and automating IAM policy enforcement
  • Comfortable with threat modelling and incident response leadership
  • Practical knowledge of compliance frameworks and readiness (SOC2, ISO 27001, PCI-DSS)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
New Delhi, Delhi
265 Employees
Year Founded: 2020

What We Do

GoKwik is a data & technology led enabler, building a full-stack solution suite for eCommerce and D2C brands to help them unlock business growth. Embarked on a mission to democratise the shopping experience, GoKwik enables eCommerce brands to deliver superlative customer experience across the shopping funnel thereby boosting conversion rates and revenue growth. It also solves for other critical pain points of the industry such as COD RTO (Return to Origin) and helps brands manage the RTO problem while offering COD as a payment channel. With its recent addition of a third product: KwikChat, GoKwik is solving for low ROIs on marketing campaigns through 30+ Whatsapp use cases such as abandoned cart recovery, click to whatsapp ad campaigns & headless checkout. 1 in 3 shoppers is already shopping on the GoKwik network that has helped 500+ brands scale their businesses with higher GMV realisation & profit margins. It is helmed by Chirag Taneja (Co-Founder and Chief Executive Officer), Vivek Bajpai (Co-Founder and Chief Technology Officer), and Ankush Talwar (Co-Founder and Chief Data Scientist). GoKwik is backed by investors such as Sequoia Capital, Matrix Partners India, RTP Global & Think Investments. GoKwik's team has deep knowledge in the space of eCommerce with people having previous experience in Flipkart, Razorpay, Swiggy, Myntra, Nykaa, and more.

Similar Jobs

BlackRock Logo BlackRock

Application Engineer

Fintech • Information Technology • Financial Services
In-Office
Gurugram, Haryana, IND
25000 Employees

Mastercard Logo Mastercard

Manager, Analytics & Metrics

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Gurugram, Haryana, IND
38800 Employees

Mastercard Logo Mastercard

Consultant

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Gurugram, Haryana, IND
38800 Employees

Capco Logo Capco

Artificial Intelligence Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account