Experience
3 - 8 yrs
Job Location
Pune, India
Vacancy
1
Designation
Senior Security Engineer
Job Type
ONSITE
Job Description
Job Summary
The Impact of a Sr Security Engineer at Coupa: Coupa's Sr Security Engineer is a key part of the Red Team, responsible for challenging and improving the company's security posture by simulating real-world attacks. This role will involve executing programs and tools to protect the Coupa Cloud for our growing customer base. This is a hands-on role. We need people who are self-motivated, have a strong desire to learn, a can-do attitude, tenacity to solve problems, team players, and results focused.
Responsibilities
- As a Sr Security Engineer, you will execute sophisticated penetration tests and red team exercises. You will also contribute to the development of new attack techniques and testing methodologies.
- Conduct penetration testing on internally and externally hosted applications such as Web apps, Mobile Apps, AI/LLM and APIs, leveraging both traditional and AI-powered tools.
- Perform specialized security assessments and penetration testing on Coupa's AI and LLM integrations, specifically targeting prompt injection, jailbreaking, data poisoning, and model evasion.
- Develop, deploy, and manage AI agents for continuous and autonomous security testing and vulnerability discovery.
- Identify network and system vulnerabilities and provide recommended countermeasures or mitigating controls to reduce risk to an acceptable and manageable level.
- Perform penetration and remediation testing reporting and apply advanced penetration techniques in a fast-paced, highly technical environment.
- Guide and consult development teams on secure coding best practices, including security for AI/ML models.
- Serve as a key escalation point during critical security incidents, leveraging deep technical knowledge to lead root-cause analysis and threat hunting efforts.
- Maintain, support, and extend our application security tooling, standards, and processes, including but not limited to SAST, DAST, WAF, and emerging AI-based security analysis platforms.
What You Will Bring to Coupa
- 3-8 years of experience in an equivalent security-related role, with hands-on experience in AI-driven security testing.
- Bachelors or Masters degree in Computer Science (or equivalent), or equivalent experience.
- Hands-on Experience in developing or utilizing autonomous, agentic systems for security penetration testing.
- Proven track record of building and maintaining cross-functional relationships, effectively navigating organizational friction to implement necessary security improvements.
- Relevant security certifications are a plus, but not required (CEH, OSCP, GPEN, LPT, EWPTX).
- Strong experience in web / API security, with a focus on testing and defending against attacks on AI/ML systems.
- Familiarity with Cloud environments such as AWS, Azure, GCP.
- Hands on experience in handling and managing bug bounty programs.
- Proficiency in one or more scripting languages, with a strong preference for Python for AI/ML development.
- Knowledge of common application security issues (e.g. OWASP Top 10, SANS Top 25) and familiarity with the OWASP Top 10 for Large Language Models.
- Well-versed with pentest standards/frameworks such as PTES, OSSTMM, NIST, OSINT, and OWASP.
- Ability to translate complex, highly technical security findings into actionable business risks for non-technical stakeholders and executive leadership.
- Ability to work in a team environment.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
