Posted on: 19/08/2026
Job Description Information Security Engineer
Position : Information Security Engineer / Application Security Engineer
Experience : 48 years
Role Type : Individual Contributor / Security Engineering
Primary Focus : Application Security, API Security, VAPT, Threat Modeling, Secure Code Review & Compliance
Cloud : AWS
Domain : SaaS / AI-ML Product Environment
About the Role :
We are looking for a hands-on Information Security Engineer to take ownership of application, API, and product security across web, mobile, and API surfaces.
The ideal candidate should have strong practical experience in VAPT, application security, threat modeling, secure code review, security architecture, and security compliance.
This role requires someone who can interpret security findings, assess exploitability and business impact, recommend remediation, and work closely with engineering teams to close vulnerabilities.
This is a security engineering role, not primarily a security tooling or DevSecOps role.
Key Responsibilities :
1. Application & API Security :
- Conduct hands-on security assessments of web applications, APIs, and mobile applications.
- Perform VAPT across web, mobile, and API surfaces.
- Identify vulnerabilities and assess their exploitability, severity, and business impact.
- Validate and prioritize security findings.
- Work with developers to define and track remediation.
- Perform security testing during the SDLC.
2. Threat Modeling :
- Conduct threat modeling for new features, applications, APIs, and system architectures.
- Identify attack vectors, security risks, and potential abuse cases.
- Recommend appropriate security controls and mitigations.
- Collaborate with Product, Engineering, and Architecture teams during design phases.
3. Secure Code Review :
- Perform manual and automated security-focused code reviews.
- Identify vulnerabilities that automated scanners may miss.
- Review application code for common security issues such as : OWASP Top 10, Authentication & authorization vulnerabilities, Injection vulnerabilities, SSRF, XSS, CSRF, Insecure API implementations, Sensitive data exposure, and Business logic vulnerabilities.
4. Security Architecture :
- Provide security inputs during application and infrastructure architecture discussions.
- Review security controls across AWS-based environments.
- Assess authentication, authorization, encryption, secrets management, network security, IAM, logging, etc.
- Provide security recommendations for AI/ML applications and services.
5. AI/ML Security :
- Assess security risks associated with AI/ML applications and APIs.
- Identify potential risks around : Prompt injection, Data leakage, Model/API abuse, Insecure integrations, Sensitive information exposure, and Access control.
- Provide security recommendations for AI-enabled products.
6. Compliance & Audit Readiness :
- The candidate should have practical experience supporting security/compliance programs, particularly : SOC 2, ISO 27001, GDPR, and CCPA.
Responsibilities may include :
- 1. Preparing evidence for audits.
- 2. Supporting security control implementation.
- 3. Identifying compliance gaps.
- 4. Working with internal teams to close gaps.
- 5. Supporting external auditors during certification/audit cycles.
- 6. Maintaining security documentation and policies.
Mandatory Technical Skills :
- VAPT : Hands-on Mandatory
- Web Security : Strong
- API Security : Strong
- Mobile Security : Hands-on experience preferred/required
- Threat Modeling : Hands-on
- Secure Code Review : Hands-on
- OWASP : Strong knowledge
- Application Security : Strong
- Security Architecture : Good understanding
- AWS Security : Good understanding
- SOC 2 / ISO 27001 : Practical audit/compliance experience
- GDPR / CCPA : Working knowledge
- AI/ML Security : Exposure/understanding preferred
Security Tools :
- The candidate may have experience with tools such as : Burp Suite, OWASP ZAP, MobSF, Semgrep, SonarQube, Trivy, Snyk, Checkmarx / Veracode, Nessus / Qualys, Nmap, and Metasploit.
Important :
Tool knowledge alone is not sufficient. The candidate must be able to interpret findings, manually validate vulnerabilities, assess risk/exploitability, and drive remediation.
Did you find something suspicious?
Posted by
Gayatri Gupta
Manager (HR & Admin) at Antino
Last Active: NA as recruiter has posted this job through third party tool.
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1664482