Senior Security Engineer – Security Team
- India
نُشرت أمس
عن الوظيفة
We are looking for a Senior Security Engineer to join our Security Team and lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives. This role sits at the intersection of traditional application security and emerging AI security threats.
Key Responsibilities
Penetration Testing & Offensive Security
- Lead end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure.
- Design and execute red-team exercises simulating real-world attacks.
- Perform threat modelling for new product features and architectures.
- Develop custom exploits, scripts, and security tools.
- Prepare clear and actionable penetration testing reports.
- Manage third-party penetration testing vendors and responsible disclosure programs.
AI & LLM Security
- Research and execute attacks against AI/LLM-powered systems, including prompt injection, jailbreaks, and indirect prompt injection.
- Assess risks related to data exfiltration through model responses.
- Assess security risks in Model Context Protocol (MCP) deployments, including tool-call boundaries, context poisoning, and privilege escalation.
- Build an internal threat library for AI attack patterns.
- Develop and maintain red-teaming playbooks for LLM-based features.
- Work with ML and Product teams to integrate security into the AI development lifecycle.
DevSecOps
- Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secret scanning, and container scanning.
- Define and enforce secure coding standards and security review gates.
- Drive security automation across engineering teams.
Risk Assessment & Governance
- Assess and prioritize security risks using frameworks such as CVSS, DREAD, or FAIR.
- Maintain risk registers and track remediation progress.
- Evaluate risks from third-party vendors, integrations, and open-source dependencies.
- Support security audits, gap assessments, policies, standards, and exception processes.
- Communicate security findings and business impact to technical and non-technical stakeholders.
Required Skills & Experience
- 4+ years of experience in Security Engineering, with at least 2 years of hands-on penetration testing experience.
- Strong experience in web application and API penetration testing.
- Good knowledge of OWASP Top 10, business logic vulnerabilities, and authentication/authorization bypasses.
- Hands-on experience with AI/LLM security, including prompt injection, model manipulation, or MCP security assessments.
- Strong scripting skills in Python, Go, or Bash.
- Experience with cloud security across AWS, GCP, or Azure.
- Knowledge of cloud misconfigurations, IAM abuse, and lateral movement.
- Experience integrating SAST/DAST/SCA tools into CI/CD pipelines.
- Experience conducting risk assessments and communicating findings effectively.
Good to Have
- Bug bounty experience or CVE publications.
- Experience with agentic AI frameworks such as LangChain, AutoGPT, or Claude Agents.
- Experience with red-team tools and security automation.
- Security certifications such as OSCP, OSWE, OSEP, CEH, or equivalent.
Pay: From ₹600,000.00 per year
Benefits:
- Health insurance
- Provident Fund
Work Location: In person