Experience
6 - 10 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Senior Security Engineer
Job Type
ONSITE
Job Description
Standardized Job Title: Senior Engineer, Security Engineering
Role: Senior Security Engineer (Offensive Security)
Location: Bangalore
About This Role
As a Senior Security Engineer (Offensive Security) you will be given a unique opportunity to solve security challenges in our Cloud environments and work on high impact projects.
As a subject matter expert for Offensive Security, you will be responsible for:
- Conduct deep-dive penetration testing across our Web, API, and Mobile (iOS/Android) platforms.
- Bridge the gap between discovery and remediation by collaborating with developers to provide actionable insights, ensuring every vulnerability found is a lesson learned.
- Collaborate with the engineering teams, ensuring robust security is baked into the SDLC from the initial requirements phase through to deployment.
- Create the feedback loop with the engineering team to ensure the gaps discovered through penetration testing is fixed
- Drive the standardization of security best practices across our Cloud Infrastructure (AWS/GCP/Kubernetes) and fine-tune edge defenses like WAF to neutralize zero-day threats.
- Stay ahead of the curve by leveraging and building AI/ML-driven solutions to automate continuous penetration testing and identify emerging attack vectors in LLM integrations.
- Drive standardization of best practices across all aspects of SDLC and Cloud Security
- Identify potential gaps in existing environments, areas to improve our security posture by comparing against the baseline security standards
What are we looking for
- 6 10 years of experience in Cyber Security with a heavy focus on offensive operations and penetration testing.
- Strong expertise in penetration testing of Web, API and Mobile application platforms
- Deep mastery of API-based architectures and OWASP ASVS frameworks
- Hands-on experience penetration testing modern authentication and authorization mechanisms, including JWT , OAuth2, and Auth0.
- Proven ability to manually exploit and automate tests for XSS, Injection, Hijacking, and complex logic flaws in payment gateways or authentication flows.
- Experience in automating penetration testing test cases to enable continuous testing
- Proficient in at least one language (Python, Java, or JavaScript) with a passion for automation to focus on high-value manual exploitation.
- Specific knowledge of the OWASP Top 10 for LLM Applications and experience using AI to security test the workflows.
- Hands-on experience securing Cloud and Kubernetes environments. You should be comfortable navigating microservices and containerized workloads.
- Prior experience of offensive security testing and navigating the unique security challenges of an ecommerce or digital telco platform will be an advantage
- Passion for security, a practical and balanced approach to security issues
- Knowledge and deep understanding of security engineering best practices.
- Critical thinker, good communicator and problem-solving skills.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
