⚡ New
Security Engineer
Shortlist Design
Bangalore BazaarFull-timeMid LevelOn-site
Job Description
We are a hiring company that helps brands hire talents.
Security Engineer @ Product Team, Bangalore, Onsite.
What You’ll Do
Security Posture & Vulnerability Management
Own the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teams
- Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure
- Perform static and dynamic application security testing (SAST/DAST) and track findings to closure
- Manage a responsible disclosure / bug bounty programme and triage external security reports
- Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively
Production System Security
- Harden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcement
- Implement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practices
- Oversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controls
- Conduct threat modelling for new product features and infrastructure changes before they ship
- Define and enforce secure coding standards; embed security reviews into the engineering workflow
AI-Driven Threat Defence
- Identify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud
- Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools, AI-assisted workflows) and establish guardrails
- Stay current on the evolving AI threat landscape and translate research into practical defensive controls
Compliance & Audits
- Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readiness
- Liaise with external auditors, certification bodies, and enterprise clients during security assessments
- Maintain security policies, procedures, and documentation to audit-ready standards at all times
- Track regulatory changes across applicable frameworks and update internal controls accordingly
Security Training & Culture
- Design and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modules
- Champion a security-first engineering culture — make secure-by-default the path of least resistance for every team
- Build incident response playbooks and lead tabletop exercises to keep the team prepared
- Act as the internal point of contact for security questions, escalations, and policy guidance
What We’re Looking For
Must-Have
- 4–5 years of hands-on experience in application security, infrastructure security, or a broad security engineering role
- Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments
- Strong working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoring
- Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices
- Deep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence management
- Solid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcement
- Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment
- Strong written communication — able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiences
- Ownership mindset — you don’t wait for security incidents; you prevent them
Good to Have
- Industry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent
- Experience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similar
- Familiarity with mobile security (Android/iOS) — relevant given product’s SDK footprint
- Experience running a bug bounty or responsible disclosure programme
- Prior work at a fintech, identity, or developer-tools company where security is product-critical
- Experience with SIEM tools, log analysis platforms, or threat detection pipelines
Posted Today