HCLSoftware DevSecOps Engineer 2026
DevSecOps • Application Security • Software Supply Chain Security
📍 Bengaluru
🏢 Hybrid
💼 Full-Time
🎯 5–9 Years
The position is based in Bengaluru, Karnataka and follows a hybrid, full-time work model. The job is aimed at professionals with significant hands-on experience across DevSecOps, application security engineering or platform engineering.
According to the job listing, candidates should have total experience in the 5–9 years range. The role requires practical experience integrating security controls into CI/CD pipelines, working with software supply chain security, SBOMs, containers, Kubernetes, cloud platforms and infrastructure as code.
This is not simply a role focused on provisioning security tools. HCLSoftware is looking for an engineer who can combine open-source, commercial and internally developed technologies, automate security controls and work directly with product engineering and security teams.
HCLSoftware DevSecOps Engineer 2026 – Quick Details
| Company | HCLSoftware |
| Role | DevSecOps Engineer |
| Location | Bengaluru, Karnataka, India |
| Work Mode | Hybrid |
| Employment | Full-Time |
| Experience | 5–9 Years Total Experience |
| Job Function | Engineering |
| Primary Areas | DevSecOps, Application Security, CI/CD, Supply Chain Security |
Table of Contents
About the HCLSoftware DevSecOps Engineer Role
The HCLSoftware DevSecOps Engineer role focuses on embedding security into the way enterprise software products are built, packaged and released.
The position involves building tooling and automation that enables product teams to meet consistent security requirements without unnecessarily slowing down development.
The engineer will also work on software supply chain controls that support customer assurance, contractual requirements and regulatory expectations.
The role requires collaboration with Product Engineering, Product Security and Security Architecture functions.
Candidates should be comfortable moving between security analysis, DevOps and software development while working with multiple teams and different technology environments.
What makes this role different?
The role goes beyond simply provisioning or monitoring commercial security tools. The engineer is expected to combine FOSS, commercial and in-house technologies, write supporting automation and operationalize security solutions across diverse environments.
Pipeline Security Engineering
A major part of the HCLSoftware DevSecOps Engineer role is integrating security controls directly into CI/CD pipelines.
- Integrate static analysis into CI/CD pipelines.
- Integrate software composition analysis.
- Implement secrets detection.
- Integrate container scanning.
- Implement infrastructure-as-code scanning.
- Build reusable reference architectures.
- Tune scanning configurations to improve accuracy.
- Reduce false positives that can affect developer trust.
- Define and implement security policy gates.
- Support multiple build ecosystems and programming languages.
The role requires a practical understanding of how security tooling fits into real engineering workflows rather than operating security controls in isolation.
Software Supply Chain Security & SBOM
Software supply chain security is another major responsibility in this opportunity. The engineer will work with software composition, dependency intelligence, SBOM generation and build integrity.
Key Responsibilities
- Automate CycloneDX SBOM generation and publication.
- Maintain pipelines that keep SBOM information accurate.
- Operate dependency and vulnerability intelligence tooling.
- Map disclosed vulnerabilities to affected releases and customers.
- Implement artifact signing.
- Improve software provenance.
- Improve reproducibility.
- Implement dependency pinning.
- Support supply chain assurance requirements.
- Maintain evidence required for product attestations.
Familiarity with SBOM formats such as CycloneDX or SPDX and dependency risk management is specifically relevant to this role.
Developer Enablement
HCLSoftware is looking for security engineers who can make security controls easier for development teams to adopt.
- Build reusable pipeline templates.
- Create shared libraries.
- Develop paved-road patterns.
- Deliver security findings inside developer workflows.
- Integrate findings into pull requests, IDEs and chat workflows.
- Provide hands-on technical guidance.
- Conduct office hours and support sessions.
- Create technical documentation.
- Help engineering teams fix security issues rather than only triaging them.
- Track adoption and remediation metrics.
Compliance & Release Assurance
Security evidence and release assurance are also important parts of the role.
- Automate collection of release-time security evidence.
- Support audit requirements.
- Support customer security questionnaires.
- Support regulatory reporting.
- Partner with Product Security and PSIRT.
- Participate in vulnerability triage.
- Verify security fixes.
- Support advisory publication.
- Contribute to secure development lifecycle standards.
Required Qualifications
The HCLSoftware DevSecOps Engineer position is intended for experienced professionals. The job listing specifies 5+ years of experience in DevSecOps, application security engineering or platform engineering with direct security ownership, while the hiring instructions specify total experience between 5 and 9 years.
5+ years with direct security ownership
GitHub Actions, GitLab CI, Jenkins or Azure DevOps
Production-quality coding ability
CycloneDX or SPDX
Container and Kubernetes security
AWS, Azure or GCP
Terraform or equivalent
Ability to influence engineering teams
General Security Expertise
Candidates should have broad security knowledge along with practical experience applying security concepts to modern software environments.
Security Knowledge
- Security concepts, principles and methodologies
- NIST and OWASP
- Secure system design and architecture
- Security requirements and technical specifications
- Architectural diagrams and security specifications
- Secure coding concepts
- Code review and security flaw identification
- Security fixes and hardening
- Container security and hardening
- Cloud security models
- Modern cloud and web threat environments
- Software supply chain security
Tools & Technologies
Python
Java
C++
Linux
AWS
GCP
Kubernetes
Terraform
Trivy
Mend / Whitesource
CycloneDX
SBOM
Additional Security Experience
- Vulnerability assessment
- Penetration testing
- Reverse engineering
- Security automation
- Product security vulnerability response
- Security incident response
- Linux security technologies
- Server-side Linux administration and security
Preferred Qualifications
- Experience in a product company shipping software to enterprise customers with contractual security obligations.
- Familiarity with supply chain frameworks and standards such as SLSA.
- Knowledge of SSDF, including NIST SP 800-218.
- Familiarity with in-toto attestations.
- Experience operating Dependency-Track or similar dependency intelligence platforms at scale.
- Experience securing AI-assisted development workflows.
- Experience securing code generated with AI tooling.
Certifications:
CSSLP, GWEB, cloud security certifications and Kubernetes security credentials are valued but are not required.
Communication & Collaboration Skills
The position requires strong collaboration because the engineer will work across product teams, engineering managers, security stakeholders and geographically distributed teams.
- Excellent communication skills
- Strong interpersonal skills
- Ability to work asynchronously across distributed teams
- Ability to collaborate with product teams
- Ability to work with engineering managers
- Ability to work with security stakeholders
- Strong technical documentation skills
- Ability to influence teams without direct management authority
How to Apply for HCLSoftware DevSecOps Engineer 2026
The job poster has specifically requested candidates to share their CV with the hiring team along with key career information.
📩 CV Submission Details
Email:
monica_sharma@hcl-software.com
Please include the following details:
- Total Experience
- Current CTC
- Expected CTC
- Notice Period
The hiring information specifies a total experience range of 5–9 years. Candidates should ensure their resume clearly highlights relevant DevSecOps, application security, CI/CD, cloud, Kubernetes, SBOM and software supply chain experience.
Resume Checklist for DevSecOps Candidates
- ☑️ Mention total DevSecOps/security experience clearly
- ☑️ Highlight CI/CD security implementation
- ☑️ Mention GitHub Actions, GitLab CI, Jenkins or Azure DevOps
- ☑️ Include SCA and vulnerability scanning experience
- ☑️ Highlight SBOM/CycloneDX/SPDX knowledge
- ☑️ Mention Kubernetes and container security
- ☑️ Include AWS, Azure or GCP experience
- ☑️ Mention Terraform or infrastructure-as-code experience
- ☑️ Highlight OWASP/NIST/security architecture knowledge
- ☑️ Include Python, Java or C++ where relevant
- ☑️ Mention Linux and security hardening experience
Explore More Jobs
Looking for more technology, cybersecurity and engineering opportunities? Explore the latest openings on
TeluguNewzz
and browse the
Jobs & Careers
section.
Frequently Asked Questions
1. What is the HCLSoftware DevSecOps Engineer role?
It is a DevSecOps and security engineering role focused on CI/CD security, software supply chain security, SBOMs, application security, cloud, containers and developer security enablement.
2. Where is the HCLSoftware DevSecOps Engineer job located?
The role is based in Bengaluru, Karnataka, India, with a hybrid work arrangement.
3. How much experience is required?
The job poster specifies total experience between 5 and 9 years. The required qualifications also mention 5+ years in DevSecOps, application security engineering or platform engineering with direct security ownership.
4. What CI/CD platforms are relevant?
The listing specifically mentions GitHub Actions, GitLab CI, Jenkins and Azure DevOps.
5. Is Kubernetes security required?
Yes. Container and Kubernetes security experience, including image hardening and registry controls, is included among the required qualifications.
6. Which cloud platforms are relevant?
The role asks for cloud platform fluency across AWS, Azure or GCP.
7. Is Terraform experience required?
Infrastructure-as-code experience with Terraform or an equivalent technology is listed as a required qualification.
8. Are security certifications mandatory?
No. Certifications such as CSSLP, GWEB, cloud security certifications and Kubernetes security credentials are valued but are not required.
9. How should candidates apply?
The job poster asks candidates to share their CV with Monica Sharma at monica_sharma@hcl-software.com along with total experience, current CTC, expected CTC and notice period.
⚠️ Important Note
This post is based on the supplied HCLSoftware DevSecOps Engineer job listing. Salary, exact application deadline and other hiring conditions were not specified in the supplied listing. Candidates should verify the latest vacancy status and application instructions before sharing personal information.
Final Takeaway
The HCLSoftware DevSecOps Engineer 2026 opportunity is aimed at experienced professionals who can bring security directly into modern software development and delivery workflows.
Candidates with strong experience in CI/CD security, application security, SBOM, software supply chain security, Kubernetes, cloud platforms, Terraform, Linux, OWASP and security automation may find this role particularly relevant.
If your background combines security engineering, DevOps and software development, this Bengaluru hybrid opportunity is worth exploring.
⚠️ Disclaimer
This article is provided for informational purposes only. Job availability, experience requirements, hiring process, compensation, work arrangements and application details may change. Please verify the latest information through the employer or official job-posting source before applying. TeluguNewzz does not guarantee an interview, selection or job offer.
📢 Share This Opportunity
Know someone with DevSecOps, cybersecurity, application security or cloud security experience?
❤️ Share this job with your friends & groups!