03 Sep
|
Nextwebi IT Solutions
|
Bengaluru
03 Sep
Nextwebi IT Solutions
Bengaluru
We are looking for a Senior Security Engineer to join our Security Team and lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives. This role sits at the intersection of traditional application security and emerging AI security threats.
Key Responsibilities
Penetration Testing & Offensive Security
- Lead end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure..
- Design and execute red-team exercises simulating real-world attacks..
- Perform threat modelling for new product features and architectures..
- Develop custom exploits, scripts, and security tools..
- Prepare clear and actionable penetration testing reports..
- Manage third-party penetration testing vendors and responsible disclosure programs..
AI & LLM Security
- Research and execute attacks against AI/LLM-powered systems, including prompt injection, jailbreaks, and indirect prompt injection..
- Assess risks related to data exfiltration through model responses..
- Assess security risks inModel Context Protocol (MCP)deployments, including tool-call boundaries, context poisoning, and privilege escalation..
- Build an internal threat library for AI attack patterns..
- Develop and maintain red-teaming playbooks for LLM-based features..
- Work with ML and Product teams to integrate security into the AI development lifecycle..
DevSecOps
- Integrate security controls into CI/CD pipelines, includingSAST, DAST, SCA, secret scanning, and container scanning..
- Define and enforce secure coding standards and security review gates..
- Drive security automation across engineering teams..
Risk Assessment & Governance
- Assess and prioritize security risks using frameworks such asCVSS, DREAD, or FAIR..
- Maintain risk registers and track remediation progress..
- Evaluate risks from third-party vendors, integrations, and open-source dependencies..
- Support security audits, gap assessments, policies, standards, and exception processes..
- Communicate security findings and business impact to technical and non-technical stakeholders..
Required Skills & Experience
- 4+ years of experience in Security Engineering, with at least2 years of hands-on penetration testing experience..
- Strong experience inweb application and API penetration testing..
- Good knowledge of OWASP Top 10, business logic vulnerabilities, and authentication/authorization bypasses..
- Hands-on experience withAI/LLM security, including prompt injection, model manipulation, or MCP security assessments..
- Solid scripting skills inPython, Go, or Bash..
- Experience with cloud security acrossAWS, GCP, or Azure..
- Knowledge of cloud misconfigurations, IAM abuse, and lateral movement..
- Experience integratingSAST/DAST/SCAtools into CI/CD pipelines..
- Experience conducting risk assessments and communicating findings effectively..
Positive to Have
- Bug bounty experience or CVE publications..
- Experience with agentic AI frameworks such asLangChain, AutoGPT, or Claude Agents..
- Experience with red-team tools and security automation..
- Security certifications such asOSCP, OSWE, OSEP, CEH, or equivalent..
📌 Senior Security Engineer (Bengaluru)
🏢 Nextwebi IT Solutions
📍 Bengaluru