05 Sep
|
Nextwebi IT Solutions
|
Bengaluru
05 Sep
Nextwebi IT Solutions
Bengaluru
Job Description
We are looking for a Senior Security Engineer to join our Security Team and lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives. This role sits at the intersection of traditional application security and emerging AI security threats. Key Responsibilities Penetration Testing & Offensive Security • Lead end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure.. • Design and execute red-team exercises simulating real-world attacks.. • Perform threat modelling for current product features and architectures.. • Develop custom exploits, scripts, and security tools.. • Prepare clear and actionable penetration testing reports.. • Manage third-party penetration testing vendors and responsible disclosure programs.. AI & LLM Security • Research and execute attacks against AI/LLM-powered systems, including prompt injection, jailbreaks, and indirect prompt injection.. • Assess risks related to data exfiltration through model responses.. • Assess security risks inModel Context Protocol (MCP)deployments, including tool-call boundaries, context poisoning, and privilege escalation.. • Build an internal threat library for AI attack patterns.. • Develop and maintain red-teaming playbooks for LLM-based features.. • Work with ML and Product teams to integrate security into the AI development lifecycle.. DevSecOps • Integrate security controls into CI/CD pipelines, includingSAST, DAST, SCA, secret scanning, and container scanning.. • Define and enforce secure coding standards and security review gates..
• Drive security automation across engineering teams.. Risk Assessment & Governance • Assess and prioritize security risks using frameworks such asCVSS, DREAD, or FAIR.. • Maintain risk registers and track remediation progress.. • Evaluate risks from third-party vendors, integrations, and open-source dependencies.. • Support security audits, gap assessments, policies, standards, and exception processes.. • Communicate security findings and business impact to technical and non-technical stakeholders.. Required Skills & Experience • 4+ years of experience in Security Engineering, with at least2 years of hands-on penetration testing experience.. • Strong experience inweb application and API penetration testing.. • Good knowledge of OWASP Top 10, business logic vulnerabilities, and authentication/authorization bypasses.. • Hands-on experience withAI/LLM security, including prompt injection, model manipulation, or MCP security assessments.. • Strong scripting skills inPython, Go, or Bash.. • Experience with cloud security acrossAWS, GCP, or Azure.. • Knowledge of cloud misconfigurations, IAM abuse, and lateral movement.. • Experience integratingSAST/DAST/SCAtools into CI/CD pipelines.. • Experience conducting risk assessments and communicating findings effectively.. Good to Have • Bug bounty experience or CVE publications.. • Experience with agentic AI frameworks such asLangChain, AutoGPT, or Claude Agents.. • Experience with red-team tools and security automation.. • Security certifications such asOSCP, OSWE, OSEP, CEH, or equivalent..
📌 Senior Security Engineer (Bengaluru)
🏢 Nextwebi IT Solutions
📍 Bengaluru