Security Engineer Mumbai (India)

Security Engineer Mumbai (India)

18 Sep
|
Swadesh Mobile
|
India

18 Sep

Swadesh Mobile

India

We have grown rapid and we know there is work to do. Our own audits have already found API endpoints without proper authentication and permission checks that do not always block what they should. You will find the rest, fix them with the engineering team, and make sure they stop coming back.

You will also protect the voice side. Toll fraud is real and expensive in telecom.

What you will do
Audit our APIs for missing authentication and broken permission checks, then fix them with the team
Make role and permission enforcement real on the server, not just hidden in the interface
Secure the telephony layer SIP authentication, IP allowlisting, registration abuse
Build toll fraud detection: unusual call patterns, expensive destinations, sudden volume spikes
Proper secrets management. No credentials in code or config files
Audit logging, so we can answer who did what and when
Encryption in transit and at rest, including call recordings
Secure the developer platform — API keys, rate limits, webhook signing
Run internal penetration tests and close what they find
Write the incident response process and lead it when something happens
Provide the technical half of SOC 2, ISO 27001 and customer security questionnaires, alongside our compliance manager

What we expect from you




A finding is not finished until it is closed. Every one comes with a reproduction, the impact in plain English, and a fix or a pull request
You tell us uncomfortable things, with evidence. This role exists to hear bad news early
You test production only with written approval and an agreed window
You rank by real risk, not scanner severity. Five things that matter this month beat a 200-page report
You fix causes. One missing auth check is a bug. A pattern of them is a process problem
First 30 days: the authentication state of every API route, ranked
First 90 days: criticals closed, secrets out of config files, toll fraud detection live

What you must have
3+ years in application or infrastructure security. 6+ and we are very interested
Hands-on penetration testing and secure code review
Authentication and authorisation design — OAuth, JWT, session handling, RBAC
Enough code reading to spot a missing auth check in Node.js or Python
OWASP Top 10, explained plainly
Secrets management, TLS, certificate handling
Linux

Preferred VoIP or telecom security, toll fraud and SIP attacks, fraud detection, and hands-on SOC 2 or ISO 27001 work.

📌 Security Engineer Mumbai (India)
🏢 Swadesh Mobile
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security engineer mumbai (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: security engineer mumbai (india) / india