Senior Engineer - Azure Active Directory
India
Job Description
Senior Engineer - Azure Active Directory
Bengaluru, Karnataka

Job Summary

ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.

Key Responsibilities

ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.

Skill Requirements

ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.

Other Requirements

ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.