04 Aug
|
Marcura India
|
Mumbai
04 Aug
Marcura India
Mumbai
The Staff Security Engineer, AI & Application Security is the first and only dedicated security engineering hire at Marcura, and is accountable for establishing the companys security engineering capability end to end. Because this is currently the single role focused wholly on security, the mandate is deliberately broad and deliberately hands on: it spans offensive assurance, defensive engineering, secure architecture and technical governance across applications, APIs, cloud infrastructure and the groups growing and varied estate of large language models commercial APIs, hosted models, and internally integrated AI features. The role exists to give Marcura an independent, evidence based and continuously improving view of its technical risk, and to make secure delivery the default rather than an afterthought.
The role holder personally executes penetration testing and AI red team exercises, designs and hardens defensive controls, reviews architecture early in the delivery lifecycle, defines secure by design patterns for LLM and agentic systems, and acts as trusted advisor to product, engineering, data and operations teams adopting AI.
The role operates within a hybrid model: Marcura retains eSentire as its Managed Detection and Response (MDR) partner and commissions independent external penetration testing, so the role holder is not expected to build a security operations centre or to be the sole source of assurance. Instead, the role holder owns these partnerships technically directing them, tuning and validating their output, closing the gaps they do not cover, and ensuring internal and external testing are complementary rather than duplicative. Critically, the role owns prioritisation: with finite capacity in a single headcount,
the role holder is expected to make explicit, defensible judgements about what Marcura tackles in house, what is deferred, and what is delivered through partners, and to build the case for further investment as the function matures.
Responsibilities: 1.
Security
Strategy, Roadmap and Prioritisation: Define and maintain a prioritised security roadmap for Marcura in order to ensure that finite capacity in a single security headcount is spent on the highest material risk, by assessing the current posture, setting a small number of clear objectives per period, making explicit decisions on what is done in house versus deferred or delivered via external partners, and building the evidence based case for further investment. 2.
Secure Architecture and Design Review: Review the architecture and design of new and changing systems in order to prevent security weaknesses being built in rather than discovered later, by embedding lightweight threat modelling into the delivery lifecycle, defining reusable secure design patterns, and giving teams timely, pragmatic decisions rather than blocking gates. 3.
AI and LLM Security Advisory: Act as the groups trusted AI security advisor in order to enable fast, secure adoption of AI across the business, by engaging early in design, defining secure by design patterns for LLM, RAG and agentic systems, and giving teams clear,
proportionate guidance rather than blanket restrictions. 4.
AI Security Framework and Standards: Build and maintain a practical AI security framework and set of engineering standards in order to make secure AI deployment repeatable and auditable as the estate grows, by aligning to OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF and translating them into concrete controls, checklists and acceptance criteria, and by maintaining a live inventory of deployed models and their controls. 5.
Internal Penetration Testing Programme: Establish and personally run Marcuras internal penetration testing capability in order to provide continuous, in depth assurance between and beyond scheduled external tests, by defining scope, methodology, tooling, reporting standards and a prioritised testing calendar covering applications, APIs, cloud infrastructure and internal services. 6.
External Penetration Test Ownership: Own and direct Marcuras independent external penetration testing in order to preserve genuine independence of assurance over systems the role holder has helped design, by setting scope and objectives, selecting and managing testing partners, ensuring internal and external coverage are complementary rather than duplicative, challenging the technical quality of findings, and integrating results into a single prioritised remediation backlog. 7.
Hands On Offensive Testing and Red Teaming: Execute technical penetration tests and red team exercises against production and pre production systems in order to find exploitable weaknesses before adversaries do, by combining manual testing, custom tooling and automation, and proving impact through demonst .
📌 Staff Security Engineer, AI & Application Security (Mumbai)
🏢 Marcura India
📍 Mumbai