Who We Are
At BKN301, we build fintech solutions that enable banks, fintechs, and merchants to grow and innovate across emerging markets.
We’re a London-based financial technology group, with offices in Milan (Italy), Doha (Qatar), and and San Marino, and an international footprint that’s rapidly expanding.
We move quick, think globally, and act as one team — transforming ideas into real, scalable fintech solutions every day.
Why Join Us
Joining BKN301 means becoming part of a fast-growing international fintech, where technology and people evolve together.
Here, every idea counts: you’ll have a tangible impact on strategic projects, learn continuously, and help build something meaningful from the ground up.
You’ll join a company that values each person’s contribution, gives space to experiment, and promotes an open approach to innovation — because our success comes from the people who make it possible.
Your Role
As a Senior Security Engineer on our Red Team, you will emulate real adversary tactics, techniques, and procedures to find out where our defenses actually hold and where they only look like they do. You will lead penetration tests, adversarial simulations, and threat-led engagements against the systems that run our core banking, issuing, and acquiring services. Your insights will help harden the security of our mission-critical financial services.
A few examples of your responsibilities
- Adversarial Simulations: Plan and run full-scope attacks against our BaaS platform, from initial access all the way through to objectives that matter in core banking, issuing, and acquiring.
- Penetration Testing: Test applications, APIs, cloud infrastructure, and Kubernetes workloads, and report what you find in a way people can act on.
- Exploitation and post-exploitation: Take findings past proof of concept. Escalate, move laterally, establish persistence, and document each step so it can be remediated and replayed.
- API and business logic abuse: Go after the flaws no scanner will catch broken object-level authorization, tenant isolation failures, replay and idempotency abuse in payment flows.
This is where the money is, and it is where we most need your eyes.
- Evasion : Work against production-grade defenses. Get past EDR and AV, defeat detection logic, and keep your telemetry low, so we learn what our controls genuinely catch rather than what the vendor promised.
- Tooling and infrastructure: Build your own offensive tooling and stand up C2 infrastructure and redirectors that survive a long engagement without being burned.
- Purple teaming: Sit down with the Blue Team, map coverage against MITRE ATT&CK;, measure how much they actually detected, and help turn your successful TTPs into new detection logic.
- Regulatory testing: Support our threat-led testing obligations under DORA and TIBER-EU, along with the periodic testing and segmentation validation PCI/DSS requires.
- Research: Keep up with what is happening in financial services threat activity, and bring it into engagements rather than leaving it in a reading list.
- Reporting: Write findings that hold up in front of both an engineering lead and a compliance officer, with real risk assessment and remediation steps that can be picked up and done.
What We’re Looking For
Essential Requirements
- Experience in in offensive security, with real experience owning engagements end to end: scoping, rules of engagement, execution, and debrief.
- Deep evasion knowledge. Bypassing EDR and AV, defeating detection logic, and operating quietly.
- Experience building and hiding C2 infrastructure and redirectors that stay alive through an engagement.
- Proficiency in scripting languages (e.g., Go, Python, C/C++, or PowerShell).
- Strong grasp of attacking Windows domains and Microsoft Entra ID, including modern identity attack paths against tokens,
conditional access, and federation.
- Hands-on experience attacking cloud and Kubernetes environments: workload identity abuse, container escape, admission control bypass, and attack paths through CI/CD and the supply chain.
- Comfort with adversarial tooling such as Cobalt Strike and Burp Suite, and with attack frameworks like MITRE ATT&CK.;
Nice to have
- Certifications such as OSCP, OSEP, CRTO, or GXPN.
- Experience on a TIBER-EU, DORA, or CBEST threat-led engagement.
- Vulnerability research, reverse engineering, or exploit adaptation.
- Time spent in a regulated industry, ideally fintech, banking, or payments.
- Social engineering or physical assessment experience.
- A detection engineering background, or previous time on a Blue Team. Knowing how defenders think makes you better at getting past them.
Soft Skills That Make a Difference
- Strategic thinking with a bias for action.
- Strong analytical and problem-solving skills.
- Ownership and accountability.
- Operational rigor and attention to detail.
- Strong communication and leadership across cultures.
- Curiosity, adaptability, and passion for innovation.
What We Offer
- Full remote permanent position with an annual CTC of ₹2,800,000 – ₹4,000,000, based on experience and skills.
- A fair and market-aligned compensation.
- Dynamic, international culture built on trust and collaboration.
- Real impact on global fintech transformation projects.
- Growth and learning opportunities within an innovative group.
Our Selection Process
- HR Introduction: A friendly chat with our HR team.
- Hiring Manager Interview: Discuss your experience and vision.
- Technical Evaluation: Show us your expertise.
- Team Fit Discussion: Ensure mutual alignment with our culture.
Every selection process is an opportunity for mutual discovery and shared growth. Diversity & Inclusion
At BKN301, we believe innovation thrives when different perspectives meet.
We’re proud to be an equal opportunity employer, committed to diversity and inclusion in all forms.
📌 Senior Security Engineer – Red Team (India)
🏢 BKN301
📍 India