20 Sep
|
Shortlist Design
|
Maharashtra
20 Sep
Shortlist Design
Maharashtra
We are a hiring company that helps brands hire talents.Security Engineer @ Product Team, Bangalore, Onsite.What You’ll DoSecurity Posture & Vulnerability ManagementOwn the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teamsConduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructurePerform static and dynamic application security testing (SAST/DAST) and track findings to closureManage a responsible disclosure / bug bounty programme and triage external security reportsMonitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactivelyProduction System SecurityHarden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcementImplement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practicesOversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controlsConduct threat modelling for recent product features and infrastructure changes before they shipDefine and enforce secure coding standards; embed security reviews into the engineering workflowAI-Driven Threat DefenceIdentify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraudAssess risks introduced by internal AI tool usage (LLM integrations, copilot tools,
AI-assisted workflows) and establish guardrailsStay current on the evolving AI threat landscape and translate research into practical defensive controlsCompliance & AuditsDrive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readinessLiaise with external auditors, certification bodies, and enterprise clients during security assessmentsMaintain security policies, procedures, and documentation to audit-ready standards at all timesTrack regulatory changes across applicable frameworks and update internal controls accordinglySecurity Training & CultureDesign and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modulesChampion a security-first engineering culture — make secure-by-default the path of least resistance for every teamBuild incident response playbooks and lead tabletop exercises to keep the team preparedAct as the internal point of contact for security questions, escalations, and policy guidanceWhat We’re Looking ForMust-Have4–5 years of hands-on experience in application security, infrastructure security,
or a broad security engineering roleProven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environmentsStrong working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoringHands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practicesDeep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence managementSolid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcementAwareness of AI-powered attack vectors and how to defend against them in a production authentication environmentStrong written communication — able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiencesOwnership mindset — you don’t wait for security incidents; you prevent themGood to HaveIndustry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalentExperience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similarFamiliarity with mobile security (Android/iOS) — relevant given product’s SDK footprintExperience running a bug bounty or responsible disclosure programmePrior work at a fintech, identity, or developer-tools company where security is product-criticalExperience with SIEM tools, log analysis platforms, or threat detection pipelines
📌 Security Engineer (Maharashtra)
🏢 Shortlist Design
📍 Maharashtra