02 Sep
|
Nextwebi IT Solutions
|
Bengaluru
02 Sep
Nextwebi IT Solutions
Bengaluru
We are looking for a Senior Security Engineer to join our Security Team and lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives. This role sits at the intersection of traditional application security and emerging AI security threats.
Location: Bangalore
Key Responsibilities
Penetration Testing Offensive Security
- Lead end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure.
- Design and execute red-team exercises simulating real-world attacks.
- Perform threat modelling for new product features and architectures.
- Develop custom exploits, scripts, and security tools.
- Prepare clear and actionable penetration testing reports.
- Manage third-party penetration testing vendors and responsible disclosure programs.
AI LLM Security
- Research and execute attacks against AI/LLM-powered systems, including prompt injection, jailbreaks, and indirect prompt injection.
- Assess risks related to data exfiltration through model responses.
- Assess security risks in Model Context Protocol (MCP) deployments, including tool-call boundaries, context poisoning, and privilege escalation.
- Build an internal threat library for AI attack patterns.
- Develop and maintain red-teaming playbooks for LLM-based features.
- Work with ML and Product teams to integrate security into the AI development lifecycle.
DevSecOps
- Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secret scanning, and container scanning.
- Define and enforce secure coding standards and security review gates.
- Drive security automation across engineering teams.
Risk Assessment Governance
- Assess and prioritize security risks using frameworks such as CVSS, DREAD, or FAIR.
- Maintain risk registers and track remediation progress.
- Evaluate risks from third-party vendors, integrations, and open-source dependencies.
- Support security audits, gap assessments, policies, standards, and exception processes.
- Communicate security findings and business impact to technical and non-technical stakeholders.
Requirements
- 4+ years of experience in Security Engineering, with at least 2 years of hands-on penetration testing experience.
- Strong experience in web application and API penetration testing.
- Good knowledge of OWASP Top 10, business logic vulnerabilities, and authentication/authorization bypasses.
- Hands-on experience with AI/LLM security, including prompt injection, model manipulation, or MCP security assessments.
- Strong scripting skills in Python, Go, or Bash.
- Experience with cloud security across AWS, GCP, or Azure.
- Knowledge of cloud misconfigurations, IAM abuse, and lateral movement.
- Experience integrating SAST/DAST/SCA tools into CI/CD pipelines.
- Experience conducting risk assessments and communicating findings effectively.
Positive to Have
- Bug bounty experience or CVE publications.
- Experience with agentic AI frameworks such as LangChain, AutoGPT, or Claude Agents.
- Experience with red-team tools and security automation.
- Security certifications such as OSCP, OSWE, OSEP, CEH, or equivalent.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Senior Security Engineer (Bengaluru)
🏢 Nextwebi IT Solutions
📍 Bengaluru