⚡ New

Security Engineer

Shortlist Design

Bangalore BazaarFull-timeMid LevelOn-site

Job Description

We are a hiring company that helps brands hire talents.

Security Engineer @ Product Team, Bangalore, Onsite.


What You’ll Do


Security Posture & Vulnerability Management


Own the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teams


  •  Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure
  • Perform static and dynamic application security testing (SAST/DAST) and track findings to closure
  • Manage a responsible disclosure / bug bounty programme and triage external security reports
  • Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively


Production System Security


  • Harden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcement
  • Implement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practices
  • Oversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controls
  • Conduct threat modelling for new product features and infrastructure changes before they ship
  • Define and enforce secure coding standards; embed security reviews into the engineering workflow


AI-Driven Threat Defence


  • Identify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud
  • Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools, AI-assisted workflows) and establish guardrails
  • Stay current on the evolving AI threat landscape and translate research into practical defensive controls


Compliance & Audits


  • Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readiness
  • Liaise with external auditors, certification bodies, and enterprise clients during security assessments
  • Maintain security policies, procedures, and documentation to audit-ready standards at all times
  • Track regulatory changes across applicable frameworks and update internal controls accordingly


Security Training & Culture

  • Design and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modules
  • Champion a security-first engineering culture — make secure-by-default the path of least resistance for every team
  • Build incident response playbooks and lead tabletop exercises to keep the team prepared
  • Act as the internal point of contact for security questions, escalations, and policy guidance


What We’re Looking For


Must-Have


  • 4–5 years of hands-on experience in application security, infrastructure security, or a broad security engineering role
  • Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments
  • Strong working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoring
  • Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices
  • Deep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence management
  • Solid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcement
  • Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment
  • Strong written communication — able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiences
  • Ownership mindset — you don’t wait for security incidents; you prevent them


Good to Have


  • Industry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent
  • Experience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similar
  • Familiarity with mobile security (Android/iOS) — relevant given product’s SDK footprint
  • Experience running a bug bounty or responsible disclosure programme
  • Prior work at a fintech, identity, or developer-tools company where security is product-critical
  • Experience with SIEM tools, log analysis platforms, or threat detection pipelines

Posted Today

Related Jobs

Related Searches

Apply Now