20 Sep
|
Shortlist Design
|
Bengaluru
20 Sep
Shortlist Design
Bengaluru
We are a hiring company that helps brands hire talents.
nSecurity Engineer @ Product Team, Bangalore, Onsite.
n
nWhat You’ll Do
n
nSecurity Posture & Vulnerability Management
n
nOwn the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teams
n
n
n
- Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure
n
- Perform static and dynamic application security testing (SAST/DAST) and track findings to closure
n
- Manage a responsible disclosure / bug bounty programme and triage external security reports
n
- Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively
n
n
nProduction System Security
n
n
n
- Harden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcement
n
- Implement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practices
n
- Oversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controls
n
- Conduct threat modelling for new product features and infrastructure changes before they ship
n
- Define and enforce secure coding standards; embed security reviews into the engineering workflow
n
n
nAI-Driven Threat Defence
n
n
n
- Identify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud
n
- Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools,
AI-assisted workflows) and establish guardrails
n
- Stay current on the evolving AI threat landscape and translate research into practical defensive controls
n
n
nCompliance & Audits
n
n
n
- Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readiness
n
- Liaise with external auditors, certification bodies, and enterprise clients during security assessments
n
- Maintain security policies, procedures, and documentation to audit-ready standards at all times
n
- Track regulatory changes across applicable frameworks and update internal controls accordingly
n
n
nSecurity Training & Culture
n
n
- Design and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modules
n
- Champion a security-first engineering culture — make secure-by-default the path of least resistance for every team
n
- Build incident response playbooks and lead tabletop exercises to keep the team prepared
n
- Act as the internal point of contact for security questions, escalations, and policy guidance
n
n
nWhat We’re Looking For
n
nMust-Have
n
n
n
- 4–5 years of hands-on experience in application security, infrastructure security,
or a broad security engineering role
n
- Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments
n
- Strong working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoring
n
- Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices
n
- Deep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence management
n
- Solid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcement
n
- Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment
n
- Strong written communication — able to write transparent policies, audit evidence, and risk reports for both technical and non-technical audiences
n
- Ownership mindset — you don’t wait for security incidents; you prevent them
n
n
nGood to Have
n
n
n
- Industry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent
n
- Experience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similar
n
- Familiarity with mobile security (Android/iOS) — relevant given product’s SDK footprint
n
- Experience running a bug bounty or responsible disclosure programme
n
- Prior work at a fintech, identity, or developer-tools company where security is product-critical
n
- Experience with SIEM tools, log analysis platforms, or threat detection pipelines
n
📌 Security Engineer (Bengaluru)
🏢 Shortlist Design
📍 Bengaluru