HamburgerMenu
hirist

Job Description

Role : Security Engineer

Infrastructure & Security - Bengaluru - Full-Time - On-Site

About OTPless :

OTPless is India's authentication company - and we're on a mission to make OTPs obsolete.

We help enterprises deliver the fastest, most seamless login experience while improving both conversion and security. Built for high-scale internet companies, OTPless transforms login from a friction point into a measurable growth lever. India's top unicorns trust us. We authenticate 200M+ mobile identities every month - at population scale.

We've raised $8M from tier-1 global investors including General Catalyst, SIDBI, and FJ Labs. We're 10 people with the ambition of 1,000.

Team & Culture :

Our founders are former unicorn builders - people who know what scale, velocity, and disciplined execution actually look like. We operate with the urgency of a startup and the standards of a high-performance institution.

We reward merit, action, ownership, integrity, and ethics. Impact beats titles. Accountability beats activity.

If you want disproportionate responsibility, direct founder access, and the chance to shape a product category from the ground up - you'll love it here.

The Role :

We're hiring a Security Engineer whose primary mandate is to raise and continuously improve the security posture of OTPless - across our product, infrastructure, and people.

Authentication is the most security-sensitive layer of any product stack. Our clients - India's top unicorns and fast-scaling enterprises - trust OTPless to protect 200M+ identities every month. That trust is earned through rigorous, proactive security. This role owns it.

You'll lead vulnerability assessments, harden production systems, drive compliance across SOC 2, ISO 27001, GDPR, and PCI-DSS, own endpoint security, and build a security-first culture through training and awareness. You'll also be our frontline defence against the rapidly growing class of AI-powered threats - prompt injection, automated credential attacks, AI-generated phishing, and adversarial model abuse.

This is a high-trust, high-ownership IC role. You'll work closely with Engineering, Infrastructure, and Leadership - and your work will directly determine how much enterprise clients trust us with their most critical user flows.

Security isn't a checklist here. It's a competitive advantage - and you'll be the one building it.

What You'll Do :

- Own the end-to-end security posture of OTPless - identify gaps, prioritise risks, and drive remediation across teams.

- Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure.

- Perform static and dynamic application security testing (SAST/DAST) and track findings to closure.

- Manage a responsible disclosure / bug bounty programme and triage external security reports.

- Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively.

- Harden cloud infrastructure (AWS/GCP/Azure) - IAM policies, network segmentation, secrets management, and least-privilege enforcement.

- Implement and maintain security controls across CI/CD pipelines - dependency scanning, container security, and secure build practices.

- Oversee endpoint security across all company devices - MDM, EDR tooling, patch management, and access controls.

- Conduct threat modelling for new product features and infrastructure changes before they ship.

- Define and enforce secure coding standards; embed security reviews into the engineering workflow.

- Identify and mitigate emerging AI-powered attack vectors - automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud.

- Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools, AI-assisted workflows) and establish guardrails.

- Stay current on the evolving AI threat landscape and translate research into practical defensive controls.

- Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS - including evidence collection, gap remediation, and audit readiness.

- Liaise with external auditors, certification bodies, and enterprise clients during security assessments.

- Maintain security policies, procedures, and documentation to audit-ready standards at all times.

- Track regulatory changes across applicable frameworks and update internal controls accordingly.

- Design and run security awareness training for all employees - phishing simulations, secure coding workshops, and onboarding modules.

- Champion a security-first engineering culture - make secure-by-default the path of least resistance for every team.

- Build incident response playbooks and lead tabletop exercises to keep the team prepared.

- Act as the internal point of contact for security questions, escalations, and policy guidance.

What We're Looking For :

Must-Have :

- 4 - 5 years of hands-on experience in application security, infrastructure security, or a broad security engineering role.

- Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments.

- Strong working knowledge of cloud security on AWS, GCP, or Azure - IAM, VPCs, secrets management, and security monitoring.

- Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices.

- Deep familiarity with compliance frameworks : SOC 2, ISO 27001, GDPR, and PCI-DSS - including audit preparation and evidence management.

- Solid understanding of endpoint security - MDM, EDR tools, patch management, and device policy enforcement.

- Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment.

- Strong written communication - able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiences.

- Ownership mindset - you don't wait for security incidents; you prevent them.

Good to Have :

- Industry certifications : OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent.

- Experience with authentication protocols and identity security - OAuth 2.0, OpenID Connect, OTP systems, or similar.

- Familiarity with mobile security (Android/iOS) - relevant given OTPless's SDK footprint.

- Experience running a bug bounty or responsible disclosure programme.

- Prior work at a fintech, identity, or developer-tools company where security is product-critical.

- Experience with SIEM tools, log analysis platforms, or threat detection pipelines.

What's in It for You :

- Own the security function at a company protecting 200M+ mobile identities - with full leadership visibility and trust.

- Work on a genuinely security-critical product - authentication is the frontline, and your work directly protects it.

- Direct access to founders and engineering leadership; your recommendations will be heard and acted on.

- Competitive compensation aligned with your experience.

- A fast-evolving threat landscape - especially with AI - that will keep you sharp and learning every week.

- High-trust, outcomes-driven culture without micromanagement.

- Mentorship from senior engineering leadership including ex-BharatPe builders.

Why This Role Matters :

OTPless sits at the intersection of authentication, identity, and mobile - three areas that attract sophisticated, well-resourced attackers. Our enterprise clients trust us with the login layer of their products. Any breach, vulnerability, or compliance failure doesn't just affect us - it affects every user across every client we serve.

At the same time, AI is fundamentally changing the threat surface. Attacks are faster, more convincing, and more automated than ever. We need someone who understands this shift - and builds defences that stay ahead of it.

As our first dedicated Security Engineer, you won't be inheriting a mature, documented security programme. You'll be building one - from policy to tooling to culture. That's a rare opportunity for an engineer who wants to own something that genuinely matters.

If hardening systems, staying ahead of threats, and making security a product advantage sounds like your kind of work - let's talk.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...