03 Aug
|
Circles
|
Haryana
Job Summary
Were looking for a hands-on Security Engineer to strengthen our security posture across applications, APIs, and cloud infrastructure. This IC role focuses on secure architecture support, application security testing, and penetration testing, with the automation skills to scale security work partnering closely with Engineering and DevOps to embed security throughout the SDLC.
Role Details
- Job Title: Security Engineer
- Department: Information Security
- Reports To: Head of Security Engineering
- Experience: 4-6 years
- Type: Independent Contributor (IC)
- Location: Bangalore
Key Responsibilities
Secure Architecture & Threat Modeling
- Support threat modeling sessions (STRIDE, PASTA, or equivalent) for recent applications, features, and platform changes, under guidance from senior security staff
- Conduct security architecture reviews for applications, APIs, and cloud services
- Apply and help document secure design patterns; provide security input during design and development
Application & API Security
- Execute and help maintain the Application Security program: SAST, DAST, and SCA scanning configuration, triage, and false-positive analysis
- Support integration of security testing into CI/CD pipelines and DevSecOps workflows
- Test REST and GraphQL APIs against the OWASP API Security Top 10 (broken object/function-level authorization, excessive data exposure, rate limiting, business logic abuse)
- Work directly with engineering teams to explain findings, recommend fixes, and track remediation to closure
Penetration Testing & Vulnerability Management
- Perform internal penetration tests across web applications, APIs, and cloud infrastructure
- Support and help coordinate external penetration testing engagements
- Manually validate scanner findings to confirm exploitability and reduce noise before findings reach engineering backlogs
- Track vulnerabilities through the remediation lifecycle and help maintain remediation SLAs
Security Automation
- Build automation in Python (or equivalent) for security scanning, findings de-duplication, ticketing, and reporting
- Help integrate security tooling into CI/CD to reduce manual, repetitive security tasks
- Identify opportunities to automate recurring testing and reporting workflows
Required Qualifications
- 3-6 years of hands-on experience in Cybersecurity, Application Security, or Security Engineering
- Working experience in:
- Threat modeling and secure architecture review
- Microservice architecture
- Penetration testing [Web, API, Mobile] and vulnerability management
- SAST, DAST
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Engineer II, Security Engineering (Haryana)
🏢 Circles
📍 Haryana