11 Sep
|
HuntingCube Recruitment Solution
|
Bengaluru
11 Sep
HuntingCube Recruitment Solution
Bengaluru
Job Title: Founding Security Engineer (Product Security)
Location: Bengaluru
Description
Our first dedicated security hire. You will be an individual contributor building the function.
About the Company
Seekho is built on one straightforward belief: make learning fun and easy for everyone.
We are India's #1 video edutainment platform, helping people learn real-world skills through short, expert-led videos across digital services, business, Spoken English, and much more. Founded in 2020 by IIT Kanpur alumni Rohit Choudhary, Keertay Agarwal and Yash Banwani, we are trusted by 4M+ paid subscribers and were ranked No. 2 in Google Play's Top Trending App 2025 list.
Your Role:
You'll own security across all of our products. With a large engineering team shipping daily, that means building secure defaults and tooling that scale rather than reviewing everything by hand security that's automatic, continuous and owned. It's a high-ownership role with significant independence, and you'll succeed by partnering closely with engineering teams.
1. Enforce server-side authorization; defend against account takeover, promo abuse, payment tampering, and content piracy.
2. Secure our mobile and AI surfaces, and keep children's, health, and payment data least-privilege and audited.
3. Make SAST, DAST, SCA and secret scanning default in CI/CD, and keep results trustworthy so engineers act on them.
4. Own our cloud posture — VPCs, security groups, IAM, secrets management, and threat detection.
5. Run vulnerability management — the VAPT cadence and a channel for outside researchers to report issues and see fixes through.
6. Build security incident management end to end,
detection to postmortem, against India's short breach-reporting clock.
7. Build Seekho's security platform — the internal libraries and guardrails engineers build on.
Requirements
Must Have
1. 4+ years in security, with real depth in application and API security.
2. You think in terms of how systems get exploited, not just vulnerability categories.
3. You can explain an authorization flaw in unfamiliar code, and code in Python or Go to build tooling.
4. Working knowledge of cloud security — IAM, secrets, network controls, and threat detection.
5. You've found real vulnerabilities yourself — a bounty, a VAPT finding, a CVE, or in your own product.
6. Practical incident management, detection through postmortem — you've worked a real incident, not just written the plan.
7. You've owned security in-house for a shipping product, as the first or only security person.
Bonus:
1. India's data-protection landscape (DPDP, SPDI/IT Act) and comfort partnering with legal/DPO
2. Payments and subscription fraud, RBI autopay and tokenization;
3. Children's-data obligations and Play Families / Apple Kids compliance;
4. AI/LLM application security
5. Exposure to ISO 27001 or SOC 2.
Questionnaire Q1. Share an example of custom tooling you've written for testing. Why wasn't an existing tool enough?
Q2. Tell us about a bug that led you into the cloud layer. What did you find?
Q3. Have you tested an AI or LLM-powered feature? What did you find?
Q4. Have you made security as an automated process in CI/CD? How has that increased velocity for developers?Role & responsibilities
Preferred candidate profile
📌 Product Security/Application Security (Bengaluru)
🏢 HuntingCube Recruitment Solution
📍 Bengaluru