Posted on: 15/04/2026
ROLE OVERVIEW :
We are looking for a Security Engineer to join our Security Engineering / SecOps team. This is a hands-on role at the intersection of application security, cloud security, and secure software development not a checkbox compliance job.
You will work closely with engineering and product teams to identify and fix vulnerabilities, build secure-by-default systems, and help company scale securely as a platform. You bring both the depth to dig into a hard security problem and the pragmatism to help teams ship safely without slowing them down.
WHAT YOU'LL DO :
- Conduct VAPT (Vulnerability Assessment & Penetration Testing) across web applications, mobile apps, and APIs end-to-end, with clear findings and actionable recommendations.
- Perform secure code reviews across Go, Python, Java, and Node.js codebases to identify security issues before they reach production not just relying on scanners.
- Integrate and tune SAST, DAST, dependency scanning, and other security tooling into CI/CD pipelines to automate vulnerability detection at scale.
- Identify and remediate cloud security misconfigurations particularly in AWS covering IAM policies, networking, storage, and service configurations.
- Build and improve security automation, signal aggregation pipelines, and internal tooling that reduce manual toil for the security team.
- Respond to security incidents : triage, investigate, contain, and help build resilience to prevent recurrence.
- Partner with engineering teams to embed security into product development workflows be a resource, not a gatekeeper.
- Stay ahead of emerging threats, vulnerability disclosures, and attack techniques relevant to company's stack and operating environment.
WHAT WE'RE LOOKING FOR :
You don't need to tick every box, but this is the kind of profile we're excited about :
Core Skills :
- Hands-on experience with VAPT web, mobile, and API security with the ability to go beyond tooling and think like an attacker.
- Ability to read and review code in one or more of : Golang, Python, Java, Node.js finding security issues through manual review, not just automated scans.
- Solid understanding of cloud security fundamentals, especially AWS : IAM, VPC, S3, security groups, and common misconfigurations.
- Familiarity with application security concepts : OWASP Top 10, authentication/authorization flaws, injection vulnerabilities, insecure deserialization, etc.
- Experience with CI/CD pipelines and integrating security tooling (SAST, DAST, SCA) into developer workflows.
- 3-5 years of experience in a security engineering, AppSec, or product security role at a product-first company.
- B.Tech / M.Tech in Computer Science or equivalent.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1628572