25 Sep
|
Hamly Business Solutions
|
Thanjavur
25 Sep
Hamly Business Solutions
Thanjavur
Security Engineer — Application & Cloud Security
Location: Thanjavur, Tamil Nadu · Experience: 3 - 6 years
About the Role
You will be our first dedicated security engineer, owning the security gate that every product
passes through before it reaches a real user. We build healthcare software for US providers
— an EHR platform and a patient statement platform, both handling PHI — alongside
internal business applications used across the group.
You will take it over and build it properly: testing, tooling, standards, and the judgement calls
about what is safe to ship.
You do need to understand why an exposed patient record is a regulatory breach rather than
a bug — we will teach you the domain.
What You'll Own
Application & API Security
● Web and API penetration testing against our EHR (Java / Spring Boot), statement
platform, and internal apps (Next.js / Node / PostgreSQL)
● Authentication and authorisation flaws, IDOR, injection, session handling, and
business-logic abuse — OWASP Top 10 and OWASP API Security Top 10 in
practice
● Multi-tenant isolation testing: row-level scoping, RBAC, and method-level security
actually enforced on every path
● Findings written with severity, reproduction steps, impact, and a concrete fix —
readable by the engineer who has to act on them
Secure Code Review
● Read Java and JavaScript adversarially — find the missing authorisation check in a
controller, not just run a scanner over it
● Review AI-assisted and low-code applications.
● Own the pre-release gate: you decide what is safe to ship
Cloud & Infrastructure Security
● Review and harden our AWS footprint — IAM, VPC and security groups, S3 policies,
KMS encryption, CloudTrail
● Secrets handling, least-privilege access, and encryption at rest and in transit
● Define what we log and detect, and lead incident response. We use a managed
provider for 24x7 monitoring — this is not a SOC role and there are no rotating shifts
Automation & Tooling
● Wire SAST, SCA and DAST into CI/CD — tuned so the team trusts the output
instead of ignoring it
● Dependency and supply-chain review: lockfile integrity, install-time scripts, known
CVEs that are actually reachable
● Build the tooling that makes security repeatable rather than a person-dependent
bottleneck
Leadership
● Own the security standard for the organisation — you set it, maintain it, and are the
final technical word on it
● Partner with the Product Manager and QA during discovery and sprint planning, so
security is designed in rather than found late
● Maintain the security playbook and evidence pack we show healthcare customers
and auditors
● Report findings and release decisions directly to the Chief Software Engineer
Required
● 3+ years in engineering, including 2+ years of hands-on application security testing
● Web and API penetration testing: OWASP Top 10 and OWASP API Security Top
10
● Burp Suite or OWASP ZAP to a skilled standard
● Secure code review in Java or JavaScript / Node
● AWS security fundamentals in practice — IAM, VPC, S3, KMS, CloudTrail
● Python or Bash scripting — enough to automate a check and glue tools together
● Linux and Git fluency
● Clear written communication — you will write reports that both engineers and non-
engineers act on
Good to Have
● SAST / DAST / SCA in CI/CD
● Threat modelling; PostgreSQL row-level security and audit logging
● OSCP, eJPT, eWPTX, AWS Security Specialty, CEH or equivalent — or a public
portfolio of vulnerability writeups
● Healthcare exposure — PHI, HIPAA, SOC 2, ISO 27001
● API test automation (Postman, REST Assured) and load testing (k6, JMeter) — we
will train you on these
● Azure security, Terraform or CloudFormation
Education
B.E./B.Tech.
How to Apply
Send your CV along with one redacted findings report or vulnerability writeup if you have
written.
Pay: Up to ₹1,842,362.52 per year
Work Location: In person
📌 Security Engineer (Thanjavur)
🏢 Hamly Business Solutions
📍 Thanjavur