Security Engineer (Mumbai)

Security Engineer (Mumbai)

17 Sep
|
Swadesh Mobile
|
Mumbai

17 Sep

Swadesh Mobile

Mumbai

We have grown rapid and we know there is work to do. Our own audits have already found API endpoints without proper authentication and permission checks that do not always block what they should. You will find the rest, fix them with the engineering team, and make sure they stop coming back.

You will also protect the voice side. Toll fraud is real and expensive in telecom.

What you will do

- Audit our APIs for missing authentication and broken permission checks, then fix them with the team
- Make role and permission enforcement real on the server, not just hidden in the interface
- Secure the telephony layer SIP authentication, IP allowlisting, registration abuse
- Build toll fraud detection: unusual call patterns, expensive destinations, sudden volume spikes
- Proper secrets management. No credentials in code or config files
- Audit logging, so we can answer who did what and when
- Encryption in transit and at rest, including call recordings
- Secure the developer platform — API keys, rate limits, webhook signing
- Run internal penetration tests and close what they find
- Write the incident response process and lead it when something happens
- Provide the technical half of SOC 2, ISO 27001 and customer security questionnaires, alongside our compliance manager

What we expect from you




- A finding is not finished until it is closed. Every one comes with a reproduction, the impact in plain English, and a fix or a pull request
- You tell us uncomfortable things, with evidence. This role exists to hear bad news early
- You test production only with written approval and an agreed window
- You rank by real risk, not scanner severity. Five things that matter this month beat a 200-page report
- You fix causes. One missing auth check is a bug. A pattern of them is a process problem
- First 30 days: the authentication state of every API route, ranked
- First 90 days: criticals closed, secrets out of config files, toll fraud detection live

What you must have
- 3+ years in application or infrastructure security. 6+ and we are very interested
- Hands-on penetration testing and secure code review
- Authentication and authorisation design — OAuth, JWT, session handling, RBAC
- Enough code reading to spot a missing auth check in Node.js or Python
- OWASP Top 10, explained plainly
- Secrets management, TLS, certificate handling
- Linux

Preferred VoIP or telecom security, toll fraud and SIP attacks, fraud detection, and hands-on SOC 2 or ISO 27001 work.

📌 Security Engineer (Mumbai)
🏢 Swadesh Mobile
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security engineer (mumbai) / mumbai