Security Engineer (Bengaluru)

Security Engineer (Bengaluru)

19 Sep
|
Shortlist Design
|
Bengaluru

19 Sep

Shortlist Design

Bengaluru

We are a hiring company that helps brands hire talents.

Security Engineer @ Product Team, Bangalore, Onsite.

What You’ll Do

Security Posture & Vulnerability Management

Own the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teams

- Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure
- Perform static and dynamic application security testing (SAST/DAST) and track findings to closure
- Manage a responsible disclosure / bug bounty programme and triage external security reports
- Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively

Production System Security

- Harden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcement
- Implement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practices
- Oversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controls
- Conduct threat modelling for new product features and infrastructure changes before they ship
- Define and enforce secure coding standards; embed security reviews into the engineering workflow

AI-Driven Threat Defence

- Identify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud
- Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools,



AI-assisted workflows) and establish guardrails
- Stay current on the evolving AI threat landscape and translate research into practical defensive controls

Compliance & Audits

- Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readiness
- Liaise with external auditors, certification bodies, and enterprise clients during security assessments
- Maintain security policies, procedures, and documentation to audit-ready standards at all times
- Track regulatory changes across applicable frameworks and update internal controls accordingly

Security Training & Culture

- Design and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modules
- Champion a security-first engineering culture — make secure-by-default the path of least resistance for every team
- Build incident response playbooks and lead tabletop exercises to keep the team prepared
- Act as the internal point of contact for security questions, escalations, and policy guidance

What We’re Looking For

Must-Have

- 4–5 years of hands-on experience in application security, infrastructure security,



or a broad security engineering role
- Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments
- Strong working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoring
- Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices
- Deep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence management
- Solid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcement
- Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment
- Strong written communication — able to write transparent policies, audit evidence, and risk reports for both technical and non-technical audiences
- Ownership mindset — you don’t wait for security incidents; you prevent them

Good to Have

- Industry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent
- Experience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similar
- Familiarity with mobile security (Android/iOS) — relevant given product’s SDK footprint
- Experience running a bug bounty or responsible disclosure programme
- Prior work at a fintech, identity, or developer-tools company where security is product-critical
- Experience with SIEM tools, log analysis platforms, or threat detection pipelines

📌 Security Engineer (Bengaluru)
🏢 Shortlist Design
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security engineer (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: security engineer (bengaluru) / bengaluru