Search by job, company or skills

Senior Security Engineer

Senior Security Engineer

oolka
4-8 Years
Not Disclosed
Early Applicant
  • Posted 19 hours ago
  • Be among the first 10 applicants

Job Description

About the role

Oolka is looking for a hands-on senior security engineer to own security across our AWS cloud infrastructure, application layer, and data protection posture for a consumer fintech platform handling sensitive financial and personal data. You'll be the primary driver of threat detection, vulnerability management, data protection, and incident response — working closely with engineering to build security into the SDLC rather than bolting it on afterward. This is a hybrid infrastructure-security and application-security role with a compliance dimension, suited to someone who's comfortable moving between AWS console/IaC work, code review, and writing the occasional policy or audit response.

What you'll own

Cloud infrastructure & threat detection — Design and maintain our AWS security baseline (account structure, network segmentation, IAM least-privilege) and run our detection stack (GuardDuty, Security Hub, CloudTrail, Config). You'll be the first responder when something looks anomalous, and you'll own the tooling that makes anomalies visible in the first place rather than discovered after the fact.

Data protection & PII— Own encryption strategy (KMS key management, field-level encryption/tokenization for high-sensitivity data like PAN and credit information), data classification (Macie), and access governance across RDS, MongoDB, and S3. You'll also own data handling policy for non-production environments — making sure real customer PII never ends up in staging/QA.

Application security & vulnerability management— Build and maintain our SAST/SCA/secrets-scanning pipeline in CI/CD, triage and drive remediation of findings with engineering teams, run or coordinate periodic penetration testing, and review code/architecture for injection vulnerabilities (SQL, NoSQL, and increasingly prompt injection in our AI-assisted features).

Perimeter & availability — Own our WAF rule sets, DDoS protection posture (Shield, rate limiting), and API-level abuse protection, balancing security controls against legitimate traffic and product experience.

AI/LLM security — As we ship AI-assisted features, own the security review of what data and actions those features can access — enforcing least-privilege scoping, human-approval gates for high-impact actions, and audit logging, in line with current OWASP LLM guidance (prompt injection, excessive agency).

Governance & incident response — Maintain our incident response plan and run periodic tabletop exercises (alongside our existing DR drill practice), support ISO 27001/RBI/DPDP-aligned control documentation, and represent security in external audits.

What you'll need

4–8+ years in security engineering, with genuine hands-on depth in at least two of: cloud security (AWS strongly preferred), application security, or data protection engineering — plus working familiarity with the others. Practical experience with AWS security services (GuardDuty, Security Hub, IAM, KMS, WAF, Shield) rather than just conceptual knowledge. Comfortable reading and reviewing application code (not just infra) — you don't need to be a full-time developer, but you need to be able to spot an injection flaw or an overprivileged service account in a PR. Experience building or operating a CI/CD security pipeline (SAST/SCA/secrets scanning). Solid understanding of encryption, key management, and secure credential handling in production systems.

Strong pluses

Prior experience in a regulated fintech/financial services environment (RBI cybersecurity framework, PCI-DSS, or equivalent regional regulation) is a significant advantage given our regulatory context. Exposure to India's DPDP Act or equivalent data protection regimes. Experience securing an LLM/AI-powered feature in production, not just in theory. Relevant certifications (AWS Security Specialty, OSCP, CISSP) are a plus but not a substitute for demonstrated hands-on work.

How you'll work

You'll partner closely with engineering leadership rather than operating as a separate gatekeeping function — the goal is security that ships with the product, not security that blocks it after the fact. Expect to spend meaningful time in AWS console/Terraform, in code review, and in conversation with auditors.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

About Company

Similar Jobs

3-5 yrs
Bengaluru, India
Skills:
Dynamic application security testing (DAST), Model Context Protocol (MCP) servers and integrations, security automation , Burp Suite, Javascript, Postman, Azure, Python, AWS, OWASP Web and API Top 10 risks, Security incident investigations, API penetration testing, GenAI security testing, OWASP ZAP, SCA, AI red teaming, SAST
5-7 yrs
Bengaluru, India
Skills:
Endpoint Security, Penetration Testing, Network security, Encryption, Web Application Firewall, Identity And Access Management, Incident Response, Vulnerability assessment, Security Monitoring, DDoS protection, Risk prioritization, Security reviews, Remediation tracking and verification
7-9 yrs
Bengaluru, India
Skills:
SIEM and SOAR platforms, malware functionality and persistence mechanisms, DevOps toolsets and programming languages, AWS security controls and services, data analysis modeling and correlation at scale
5-7 yrs
Bengaluru, India
Skills:
Java, DAST, Golang, C, Hipaa, CSPM, Gcp, Javascript, Iso 27001, Pci, Azure, Python, AWS, IaC scanning, SOC2, Linode, FedRAMP, SCA, SAST
5-7 yrs
Bengaluru, India
Skills:
automation, Dns, Api Gateway, Scripting, Http, AWS, Proxies, Networking, Tls, Python, Kubernetes, Iam, Docker, load-balancing, Go, AWS WAF, akamai