TymblHub

© 2026 TymblHub

Senior Security Engineer (Offensive Security)

Circles
Posted on
Circles logo

Experience
6 - 10 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Senior Security Engineer
Job Type
ONSITE

Job Description

Standardized Job Title: Senior Engineer, Security Engineering

Role: Senior Security Engineer (Offensive Security)

Location: Bangalore

About This Role

As a Senior Security Engineer (Offensive Security) you will be given a unique opportunity to solve security challenges in our Cloud environments and work on high impact projects.

As a subject matter expert for Offensive Security, you will be responsible for:

  • Conduct deep-dive penetration testing across our Web, API, and Mobile (iOS/Android) platforms.
  • Bridge the gap between discovery and remediation by collaborating with developers to provide actionable insights, ensuring every vulnerability found is a lesson learned.
  • Collaborate with the engineering teams, ensuring robust security is baked into the SDLC from the initial requirements phase through to deployment.
  • Create the feedback loop with the engineering team to ensure the gaps discovered through penetration testing is fixed
  • Drive the standardization of security best practices across our Cloud Infrastructure (AWS/GCP/Kubernetes) and fine-tune edge defenses like WAF to neutralize zero-day threats.
  • Stay ahead of the curve by leveraging and building AI/ML-driven solutions to automate continuous penetration testing and identify emerging attack vectors in LLM integrations.
  • Drive standardization of best practices across all aspects of SDLC and Cloud Security
  • Identify potential gaps in existing environments, areas to improve our security posture by comparing against the baseline security standards

What are we looking for

  • 6 10 years of experience in Cyber Security with a heavy focus on offensive operations and penetration testing.
  • Strong expertise in penetration testing of Web, API and Mobile application platforms
  • Deep mastery of API-based architectures and OWASP ASVS frameworks
  • Hands-on experience penetration testing modern authentication and authorization mechanisms, including JWT , OAuth2, and Auth0.
  • Proven ability to manually exploit and automate tests for XSS, Injection, Hijacking, and complex logic flaws in payment gateways or authentication flows.
  • Experience in automating penetration testing test cases to enable continuous testing
  • Proficient in at least one language (Python, Java, or JavaScript) with a passion for automation to focus on high-value manual exploitation.
  • Specific knowledge of the OWASP Top 10 for LLM Applications and experience using AI to security test the workflows.
  • Hands-on experience securing Cloud and Kubernetes environments. You should be comfortable navigating microservices and containerized workloads.
  • Prior experience of offensive security testing and navigating the unique security challenges of an ecommerce or digital telco platform will be an advantage
  • Passion for security, a practical and balanced approach to security issues
  • Knowledge and deep understanding of security engineering best practices.
  • Critical thinker, good communicator and problem-solving skills.
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.