Search by job, company or skills

Security Engineer

Security Engineer

shortlist design
4-6 Years
Not Disclosed
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

We are a hiring company that helps brands hire talents.

Security Engineer @ Product Team, Bangalore, Onsite.

What You'll Do

Security Posture & Vulnerability Management

Own the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teams

  • Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure
  • Perform static and dynamic application security testing (SAST/DAST) and track findings to closure
  • Manage a responsible disclosure / bug bounty programme and triage external security reports
  • Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively

Production System Security

  • Harden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcement
  • Implement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practices
  • Oversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controls
  • Conduct threat modelling for new product features and infrastructure changes before they ship
  • Define and enforce secure coding standards; embed security reviews into the engineering workflow

AI-Driven Threat Defence

  • Identify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud
  • Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools, AI-assisted workflows) and establish guardrails
  • Stay current on the evolving AI threat landscape and translate research into practical defensive controls

Compliance & Audits

  • Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readiness
  • Liaise with external auditors, certification bodies, and enterprise clients during security assessments
  • Maintain security policies, procedures, and documentation to audit-ready standards at all times
  • Track regulatory changes across applicable frameworks and update internal controls accordingly

Security Training & Culture

  • Design and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modules
  • Champion a security-first engineering culture — make secure-by-default the path of least resistance for every team
  • Build incident response playbooks and lead tabletop exercises to keep the team prepared
  • Act as the internal point of contact for security questions, escalations, and policy guidance

What We're Looking For

Must-Have

  • 4–5 years of hands-on experience in application security, infrastructure security, or a broad security engineering role
  • Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments
  • Strong working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoring
  • Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices
  • Deep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence management
  • Solid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcement
  • Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment
  • Strong written communication — able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiences
  • Ownership mindset — you don't wait for security incidents; you prevent them

Good to Have

  • Industry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent
  • Experience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similar
  • Familiarity with mobile security (Android/iOS) — relevant given product's SDK footprint
  • Experience running a bug bounty or responsible disclosure programme
  • Prior work at a fintech, identity, or developer-tools company where security is product-critical
  • Experience with SIEM tools, log analysis platforms, or threat detection pipelines

More Info

Job Type:
Industry:
Employment Type:

Key Skills

About Company

Similar Jobs

3-5 yrs
Bengaluru, India
Skills:
vulnerability research , product security , Java, Vulnerability Management, Typescript, Application Security, Javascript, Python, LLM pipelines, AI agentic systems, Go, VEX, CVSS, EPSS, OSV, CVE, CWE, SCA, SAST, SBOM formats, purls, NVD
6-8 yrs
Bengaluru, India
Skills:
DAST, Security Testing, Vulnerability Assessments, Secure Code Review, Penetration Testing, AWS, Gcp, Containers, Azure, Kubernetes, software supply chains, OWASP Top 10 vulnerabilities, OAuth 2.0, SAST, JWT security, threat modelling, AI ML threat modelling, cloud-native platforms, OpenID Connect, prompt injection testing, cloud security best practices, SCA, cryptographic controls, CI CD pipelines, vulnerability remediation, Responsible AI, OIDC
6-8 yrs
Bengaluru, India
Skills:
Iam, Python, AWS, CrewAI, IGA, K8S, LLM Guardrails, Go, OWASP LLM Top 10, AutoGPT, LangGraph, EWS Early Warning Systems, Semantic Firewalls
6-9 yrs
Bengaluru, India
Skills:
Nat, Cisco Asa, Logging, Cisco Ise, Siem, network security principles, change management tools, F5 Firewall, F5 Web Application Firewall, access control rules, ITSM ticketing, IPS technologies, routing-related changes, Cisco FMC, VPN configurations, firewall policies, Cisco FTD, enterprise monitoring
5-7 yrs
Bengaluru, India
Skills:
product security , threat modeling , Application Security, Vulnerability Management, Software Engineering, security engineering, secure design reviews, secure SDLC practices, technical risk assessments, clear technical guidance, modern application security principles