20 Sep
|
Shortlist Design
|
Bengaluru
20 Sep
Shortlist Design
Bengaluru
We are a hiring company that helps brands hire talents.
Security Engineer @ Product Team, Bangalore, Onsite.
What You’ll Do
Security Posture & Vulnerability Management
Own the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teams
Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure
Perform static and dynamic application security testing (SAST/DAST) and track findings to closure
Manage a responsible disclosure / bug bounty programme and triage external security reports
Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively
Production System Security
Harden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcement
Implement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practices
Oversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controls
Conduct threat modelling for new product features and infrastructure changes before they ship
Define and enforce secure coding standards; embed security reviews into the engineering workflow
AI-Driven Threat Defence
Identify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud
Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools,
AI-assisted workflows) and establish guardrails
Stay current on the evolving AI threat landscape and translate research into practical defensive controls
Compliance & Audits
Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readiness
Liaise with external auditors, certification bodies, and enterprise clients during security assessments
Maintain security policies, procedures, and documentation to audit-ready standards at all times
Track regulatory changes across applicable frameworks and update internal controls accordingly
Security Training & Culture
Design and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modules
Champion a security-first engineering culture — make secure-by-default the path of least resistance for every team
Build incident response playbooks and lead tabletop exercises to keep the team prepared
Act as the internal point of contact for security questions, escalations, and policy guidance
What We’re Looking For
Must-Have
4–5 years of hands-on experience in application security, infrastructure security,
or a broad security engineering role
Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments
Solid working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoring
Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices
Deep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence management
Solid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcement
Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment
Strong written communication — able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiences
Ownership mindset — you don’t wait for security incidents; you prevent them
Good to Have
Industry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent
Experience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similar
Familiarity with mobile security (Android/iOS) — relevant given product’s SDK footprint
Experience running a bug bounty or responsible disclosure programme
Prior work at a fintech, identity, or developer-tools company where security is product-critical
Experience with SIEM tools, log analysis platforms, or threat detection pipelines
📌 Security Engineer (Bengaluru)
🏢 Shortlist Design
📍 Bengaluru