03 Sep
|
Flexiple
|
India
A global bank is building its India technology centre, and forming the application security team before the teams it will support.
That ordering is deliberate. The intent is that the platform arrives with guardrails already in place rather than acquiring them after the first incident, and it means the standards this group writes will govern several hundred engineers for years. Hiring runs through Flexiple, a managed marketplace that helps global companies build high-performing teams and GCCs in India.
What the first year looks like
Threat modelling new services early enough that the design can still change, which is mostly a matter of being in the room before the architecture is agreed. Reviewing code and infrastructure for the failure classes that actually cause incidents in this environment, rather than working through a generic checklist. Getting scanning and secrets detection into pipelines so a finding arrives with the commit that caused it instead of a fortnight later.
The part that is harder than it sounds
Making the secure path the easy one.
Engineers route around gates. If the paved road is slower than doing it by hand, the standards will be quietly ignored and you will find out during an audit. A positive part of this role is product design aimed at your own colleagues.
Experience that fits
- 4 to 8 years in application or product security, financial services preferred
- Able to write code as well as read it — Java, Python or Go
- Working knowledge of cloud security controls and identity models
- Comfort telling someone a finding is not worth fixing, and defending that
Where and how Mumbai, Pune, Bengaluru, Hyderabad, Chennai or Delhi NCR, hybrid with remote flexibility across India. Screening call, technical round, a threat modelling exercise, then a panel with security leadership.
One application is enough; it stays with us for this and other security openings on the programme.
📌 Security Engineer (India)
🏢 Flexiple
📍 India