Who We Are At BKN301, we build fintech solutions that enable banks, fintechs, and merchants to grow and innovate across emerging markets. We’re a London-based financial technology group, with offices in Milan (Italy), Doha (Qatar), and San Marino, and an international footprint that’s rapidly expanding. We move fast, think globally, and act as one team — transforming ideas into real, scalable fintech solutions every day.
Here, every idea counts: you’ll have a tangible impact on strategic projects, learn continuously, and help build something meaningful from the ground up. As a Senior Security Engineer on our Red Team, you will emulate real adversary tactics, techniques, and procedures to find out where our defenses actually hold and where they only look like they do. You will lead penetration tests, adversarial simulations, and threat-led engagements against the systems that run our core banking, issuing, and acquiring services.
Your insights will help harden the security of our mission-critical financial services.
Adversarial Simulations: Plan and run full-scope attacks against our BaaS platform, from initial access all the way through to objectives that matter in core banking, issuing, and acquiring.
Penetration Testing: Test applications, APIs, cloud infrastructure, and Kubernetes workloads, and report what you find in a way people can act on. Get past EDR and AV, defeat detection logic, and keep your telemetry low, so we learn what our controls genuinely catch rather than what the vendor promised. Sit down with the Blue Team, map coverage against MITRE ATT&CK;, measure how much they actually detected, and help turn your successful TTPs into new detection logic.
Regulatory testing: Support our threat-led testing obligations under DORA and TIBER-EU,
along with the periodic testing and segmentation validation PCI/DSS requires.
Research: Keep up with what is happening in financial services threat activity, and bring it into engagements rather than leaving it in a reading list. Write findings that hold up in front of both an engineering lead and a compliance officer, with real risk assessment and remediation steps that can be picked up and done.
Experience in in offensive security, with real experience owning engagements end to end: scoping, rules of engagement, execution, and debrief. Bypassing EDR and AV, defeating detection logic, and operating quietly.
Experience building and hiding C2 infrastructure and redirectors that stay alive through an engagement. Proficiency in scripting languages (e.g., Go, Python, C/C++, or PowerShell). Solid grasp of attacking Windows domains and Microsoft Entra ID, including modern identity attack paths against tokens, conditional access, and federation.
Hands-on experience attacking cloud and Kubernetes environments: workload identity abuse, container escape, admission control bypass, and attack paths through CI/CD and the supply chain.
Experience on a TIBER-EU, DORA, or CBEST threat-led engagement. Time spent in a regulated industry, ideally fintech, banking, or payments. Social engineering or physical assessment experience. Full remote permanent position with an annual CTC of ₹2,800,000 – ₹4,000,000, based on experience and skills.
Real impact on global fintech transformation projects. Growth and learning opportunities within an innovative group. A friendly chat with our HR team. Discuss your experience and vision. Diversity & Inclusion We’re proud to be an equal opportunity employer, committed to diversity and inclusion in all forms.
📌 SECURITY ENGINEER SENIOR (India)
🏢 BKN301
📍 India