Search Jobs

Search by job, company or skills

Security Engineer

Security Engineer

shortlist design
  • Posted 17 hours ago
  • Be among the first 10 applicants

Job Description

We are a hiring company that helps brands hire talents.

Security Engineer @ Product Team, Bangalore, Onsite.

What You'll Do

Security Posture & Vulnerability Management

Own the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teams

  •  Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure
  • Perform static and dynamic application security testing (SAST/DAST) and track findings to closure
  • Manage a responsible disclosure / bug bounty programme and triage external security reports
  • Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively

Production System Security

  • Harden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcement
  • Implement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practices
  • Oversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controls
  • Conduct threat modelling for new product features and infrastructure changes before they ship
  • Define and enforce secure coding standards; embed security reviews into the engineering workflow

AI-Driven Threat Defence

  • Identify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud
  • Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools, AI-assisted workflows) and establish guardrails
  • Stay current on the evolving AI threat landscape and translate research into practical defensive controls

Compliance & Audits

  • Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readiness
  • Liaise with external auditors, certification bodies, and enterprise clients during security assessments
  • Maintain security policies, procedures, and documentation to audit-ready standards at all times
  • Track regulatory changes across applicable frameworks and update internal controls accordingly

Security Training & Culture

  • Design and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modules
  • Champion a security-first engineering culture — make secure-by-default the path of least resistance for every team
  • Build incident response playbooks and lead tabletop exercises to keep the team prepared
  • Act as the internal point of contact for security questions, escalations, and policy guidance

What We're Looking For

Must-Have

  • 4–5 years of hands-on experience in application security, infrastructure security, or a broad security engineering role
  • Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments
  • Strong working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoring
  • Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices
  • Deep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence management
  • Solid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcement
  • Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment
  • Strong written communication — able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiences
  • Ownership mindset — you don't wait for security incidents; you prevent them

Good to Have

  • Industry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent
  • Experience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similar
  • Familiarity with mobile security (Android/iOS) — relevant given product's SDK footprint
  • Experience running a bug bounty or responsible disclosure programme
  • Prior work at a fintech, identity, or developer-tools company where security is product-critical
  • Experience with SIEM tools, log analysis platforms, or threat detection pipelines

More Info

Job Type:
Industry:
Employment Type:

Key Skills

SOC 2

PCI-DSS

penetration tests

AI-powered attack vectors

EDR tools

dependency scanning

About Company

Similar Jobs

5-7 yrs
Bengaluru, India
Skills:
Endpoint SecurityPenetration TestingNetwork securityEncryptionWeb Application FirewallIdentity And Access ManagementIncident ResponseVulnerability assessmentSecurity MonitoringDDoS protectionRisk prioritizationSecurity reviewsRemediation tracking and verification
6-9 yrs
Bengaluru, India
Skills:
security automation threat modeling secure coding JavaDASTBashJavascriptDevSecOpsApplication SecurityAPI SecurityPythonGoSCASAST
8-12 yrs
Bengaluru, India
Skills:
Data Center MigrationNatDnsVLANDHCPStatic RoutingQosSsl VpnBGPPalo AltoIpsec VpnOSPFSIEM IntegrationAzure FirewallAzure Virtual WANAzure Network Virtual AppliancesMonitoring ManagementFortiManagerCloud Network SecurityECMPFortinet SD-WANFortiAnalyzerFortinet FirewallspanoramaAzure MonitorAzure Load Balancer
5-10 yrs
Bengaluru, India
Skills:
DASTPenetration TestingApplication SecurityVaptOwasp Top 10Security Testing ToolsOffensive SecurityAdversarial Machine LearningAI ML ArchitecturesAI Security TestingSCASASTAPI Security TestingExploitations
6-10 yrs
Bengaluru, India
Skills:
remediation threat modeling security automation secure sdlc DASTVulnerability ManagementCloud SecurityApplication SecurityPythonAWSJavaVulnerability AssessmentGitDevSecOpsOwaspRest ApisAzureGenAIAI AgentsClaudeCWESASTAI-driven Vulnerability DiscoveryExploitability AnalysisLLMsCVECI/CDMCPOpenAIPrompt Engineering