HamburgerMenu
hirist

Antino Labs - Information Security Engineer - Threat Modeling

Antino
4 - 8 Years
rupee15-20 LPA
Gurgaon/Gurugram

Posted on: 19/08/2026

Job Description

Job Description Information Security Engineer

Position : Information Security Engineer / Application Security Engineer

Experience : 48 years

Role Type : Individual Contributor / Security Engineering

Primary Focus : Application Security, API Security, VAPT, Threat Modeling, Secure Code Review & Compliance

Cloud : AWS

Domain : SaaS / AI-ML Product Environment

About the Role :

We are looking for a hands-on Information Security Engineer to take ownership of application, API, and product security across web, mobile, and API surfaces.

The ideal candidate should have strong practical experience in VAPT, application security, threat modeling, secure code review, security architecture, and security compliance.


This role requires someone who can interpret security findings, assess exploitability and business impact, recommend remediation, and work closely with engineering teams to close vulnerabilities.

This is a security engineering role, not primarily a security tooling or DevSecOps role.

Key Responsibilities :

1. Application & API Security :

- Conduct hands-on security assessments of web applications, APIs, and mobile applications.

- Perform VAPT across web, mobile, and API surfaces.

- Identify vulnerabilities and assess their exploitability, severity, and business impact.

- Validate and prioritize security findings.

- Work with developers to define and track remediation.

- Perform security testing during the SDLC.

2. Threat Modeling :

- Conduct threat modeling for new features, applications, APIs, and system architectures.

- Identify attack vectors, security risks, and potential abuse cases.

- Recommend appropriate security controls and mitigations.

- Collaborate with Product, Engineering, and Architecture teams during design phases.

3. Secure Code Review :

- Perform manual and automated security-focused code reviews.

- Identify vulnerabilities that automated scanners may miss.

- Review application code for common security issues such as : OWASP Top 10, Authentication & authorization vulnerabilities, Injection vulnerabilities, SSRF, XSS, CSRF, Insecure API implementations, Sensitive data exposure, and Business logic vulnerabilities.

4. Security Architecture :

- Provide security inputs during application and infrastructure architecture discussions.

- Review security controls across AWS-based environments.

- Assess authentication, authorization, encryption, secrets management, network security, IAM, logging, etc.

- Provide security recommendations for AI/ML applications and services.

5. AI/ML Security :

- Assess security risks associated with AI/ML applications and APIs.

- Identify potential risks around : Prompt injection, Data leakage, Model/API abuse, Insecure integrations, Sensitive information exposure, and Access control.

- Provide security recommendations for AI-enabled products.

6. Compliance & Audit Readiness :

- The candidate should have practical experience supporting security/compliance programs, particularly : SOC 2, ISO 27001, GDPR, and CCPA.

Responsibilities may include :

- 1. Preparing evidence for audits.

- 2. Supporting security control implementation.

- 3. Identifying compliance gaps.

- 4. Working with internal teams to close gaps.

- 5. Supporting external auditors during certification/audit cycles.

- 6. Maintaining security documentation and policies.

Mandatory Technical Skills :

- VAPT : Hands-on Mandatory

- Web Security : Strong

- API Security : Strong

- Mobile Security : Hands-on experience preferred/required

- Threat Modeling : Hands-on

- Secure Code Review : Hands-on

- OWASP : Strong knowledge

- Application Security : Strong

- Security Architecture : Good understanding

- AWS Security : Good understanding

- SOC 2 / ISO 27001 : Practical audit/compliance experience

- GDPR / CCPA : Working knowledge

- AI/ML Security : Exposure/understanding preferred

Security Tools :

- The candidate may have experience with tools such as : Burp Suite, OWASP ZAP, MobSF, Semgrep, SonarQube, Trivy, Snyk, Checkmarx / Veracode, Nessus / Qualys, Nmap, and Metasploit.

Important :

Tool knowledge alone is not sufficient. The candidate must be able to interpret findings, manually validate vulnerabilities, assess risk/exploitability, and drive remediation.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...