29 Aug
|
Nextwebi
|
Bangalore Rural
29 Aug
Nextwebi
Bangalore Rural
Senior SecOps Engineer
Job Type: Full time
Experience Required: 4+ Years
Location: Bangalore
We are looking for an experienced Senior SecOps Engineer to join our Cyber Security team. The ideal candidate will have strong hands-on experience in penetration testing, application security, cloud security, DevSecOps, and emerging AI/LLM security.
This role involves identifying and assessing security risks across web applications, APIs, cloud infrastructure, internal systems, and AI-powered applications. The candidate will work closely with engineering and product teams to strengthen security practices and support a security-first development environment.
Key ResponsibilitiesPenetration Testing
- Lead and execute end-to-end penetration testing for web applications, APIs, internal services, and cloud infrastructure.
- Design and conduct red team exercises based on real-world attack scenarios.
- Perform threat modeling for new product features and system architectures.
- Develop custom scripts, exploits, and tools to improve security testing coverage.
- Prepare clear and actionable penetration testing reports.
- Coordinate with third-party penetration testing vendors and responsible disclosure programs.
AI & LLM Security
- Perform security assessments on AI/LLM-powered systems.
- Test for vulnerabilities including prompt injection, jailbreaks, indirect prompt injection, and data exfiltration through model responses.
- Assess security risks in Model Context Protocol (MCP) deployments.
- Evaluate tool call boundaries, context poisoning vectors, and privilege escalation risks in agentic workflows.
- Develop and maintain AI security threat libraries and red-teaming playbooks.
- Work with ML and product teams to integrate security throughout the AI development lifecycle.
DevSecOps
- Integrate security controls into CI/CD pipelines.
- Work with SAST, DAST, SCA, secret scanning,
and container scanning tools.
- Define and support secure coding standards and security review processes.
- Drive security automation initiatives to reduce vulnerabilities without impacting development efficiency.
Risk Assessment & Governance
- Assess and prioritize security risks using frameworks such as CVSS, DREAD, or FAIR.
- Maintain risk registers and track vulnerability remediation progress.
- Evaluate security risks related to third-party vendors, integrations, and open-source dependencies.
- Support security audits, gap assessments, policies, standards, and compliance processes.
- Communicate security findings and risks to technical and non-technical stakeholders.
Required Skills & Qualifications
- 4+ years of experience in Security Engineering.
- Minimum 2 years of hands-on experience in Penetration Testing.
- Experience with AI/LLM security, including prompt injection, model manipulation, or MCP security assessments.
- Strong knowledge of web application and API penetration testing.
- Good understanding of OWASP Top 10, business logic vulnerabilities, and authentication bypasses.
- Strong scripting skills in Python, Go, or Bash.
- Experience with AWS, GCP, or Azure cloud security.
- Knowledge of cloud security issues including misconfigurations, IAM abuse, and lateral movement.
- Experience integrating SAST, DAST, and SCA tools into CI/CD pipelines.
- Experience conducting security risk assessments.
- Good communication and reporting skills.
Good to Have
- Bug bounty experience or CVE publications.
- Experience with agentic AI frameworks such as LangChain, AutoGPT, or Claude Agents from a security testing perspective.
- Knowledge of SOC 2, ISO 27001, and PCI-DSS compliance frameworks.
Interested candidates can apply through Indeed or submit their updated resume to HR. Pay: ₹567,673.48 - ₹1,933,240.74 per year
Benefits
- Health insurance
- Provident Fund
Work Location: In person
📌 Senior SecOps Engineer (Bangalore Rural)
🏢 Nextwebi
📍 Bangalore Rural