07 Oct
|
Chargebee
|
Bengaluru
07 Oct
Chargebee
Bengaluru
About Chargebee:
Chargebee is a subscription billing and revenue management platform powering some of the fastest-growing brands around the world today, including Calendly, Hopin, Pret-a-Manger, Freshworks, Okta, Study.com, and others. Thousands of SaaS and subscription-first businesses process over billions of dollars in revenue every year through the Chargebee platform.
Headquartered in San Francisco, USA, our 500+ team members work remotely throughout the world, including India, the Netherlands, Paris, Spain, Australia, and the USA.
Chargebee has raised over $480 million in capital and is funded by Accel, Tiger Global, Insight Partners, Steadview Capital, and Sapphire Ventures. And we’re on a mission to push the boundaries of subscription revenue operations. Not just ours, but every customer and prospective business on a recurring revenue model.
Job Summary:
You will be operating at a cross section of cutting edge tech transformation using AWS & Azure stack in a data intensive environment. It entails deep architecture , engineering & automation interventions across Cloud Infrastructure & Product Engineering teams.
We are looking for a Senior Software Engineer with 3+ years of application security experience, with a robust focus on dynamic security testing, vulnerability assessment, and penetration testing (VA/PT).
You will identify, validate, and help remediate vulnerabilities across web applications, APIs, and GenAI-powered product features, including LLM applications, agentic workflows, and Model Context Protocol (MCP) servers and integrations. The role combines hands-on offensive security testing with security automation and close collaboration with Product Engineering and DevOps teams.
Roles and Responsibilities:
Penetration Testing (Primary Role)
- Perform manual penetration testing and automated dynamic application security testing (DAST) across web applications and APIs.
- Understand application architecture, business workflows, authentication, authorization, and data flows to define testing scope and identify attack paths.
- Assess business logic flaws, access control weaknesses, injection vulnerabilities, and other application security risks.
- Develop reproducible proofs of concept and document findings with clear business impact, risk assessments, and actionable remediation guidance.
- Work with engineering teams to drive remediation and retest fixes to confirm closure.
- Retest fixed vulnerabilities to confirm effective remediation and close the finding
- Support external VA/PT engagements and responsible disclosure investigations by reproducing findings, assessing impact, and validating fixes
AI Red Teaming and GenAI Security Testing
- Conduct adversarial testing of GenAI-powered features, including LLM applications, agentic workflows, and MCP servers and integrations.
- Test for prompt injection, sensitive data disclosure, unauthorized tool invocation, and misuse of connected tools or data sources.
- Assess authentication, authorization, trust boundaries, and data access across AI components, backend services, and MCP integrations.
- Develop repeatable attack scenarios and test cases based on relevant OWASP guidance and internal security playbooks.
- Collaborate with engineering teams to validate guardrails and verify remediation of AI security findings.
Code Security
- Analyze and triage findings from SAST and SCA tools to support secure development.
- Collaborate with developers to prioritise and fix vulnerabilities.
- Collaborate with developers, understand the codebase and guide on secure coding practices
Security Automation and Program Support
- Build scripts and reusable tooling to improve testing coverage, repeatability, and efficiency.
- Integrate dynamic security testing into development and release workflows.
- Support application security incident investigations through targeted testing and attack-path analysis.
- Maintain testing methodologies, playbooks, and high-quality technical documentation.
Must Have:
- 3+ years of product security experience, with substantial hands-on experience in manual web application and API penetration testing.
- Strong understanding of application vulnerabilities and remediation, including authentication, authorization, business logic, and OWASP Web and API Top 10 risks.
- Proficiency with tools such as Burp Suite,
OWASP ZAP, and Postman.
- Experience configuring authenticated DAST scans and validating automated findings.
- Ability to independently scope and execute assessments, develop proofs of concept, explain exploitability and business impact, and retest fixes.
- Working knowledge of Python, JavaScript, or a similar language for security testing and automation.
- Ability to read application code to investigate vulnerabilities and provide practical remediation guidance.
- Foundational understanding of LLM and agentic application security, including prompt injection, tool access, and data exposure risks, with a strong interest in developing hands-on AI red teaming expertise.
- Strong written and verbal communication skills, including clear security reports and effective collaboration with developers.
- Ability to journal & create high quality wiki documentation for related work.
- Experience working in Agile environments using Jira and Confluence or equivalent tools.
Nice to have:
- Domain experience in payments / banking / platform based products.
- Hands-on experience in AI red teaming or security testing of LLM applications, agentic systems, or MCP servers and integrations.
- Familiarity with OWASP guidance for GenAI and agentic application security.
- Familiarity with AWS or Azure environments and their application security implications.
- Certifications such as OSCP, OSWE, GPEN, or equivalent.
Benefits:
Want to know what it means to work for a company that genuinely cares about you? Check out just a few of the benefits we give our employees:
We are Globally Local
With a diverse team across four continents, and customers in over 60 countries, you get to work closely with a global perspective right from your own neighborhood.
We value Curiosity
We believe the next great idea might just be around the corner. Perhaps it’s that random thought you had ten minutes ago. We believe in creating an ecosystem that fosters a desire to seek out hard questions, and then figure out answers to them.
Customer! Customer! Customer!
Everything we do is driven towards enabling our customers’ growth. This means no matter what you do, you will always be adding real value to a real business problem. It’s a lot of responsibility, but also a lot of fun.
📌 Senior Security Engineer (Bengaluru)
🏢 Chargebee
📍 Bengaluru