Roles & Responsibilities
You'll be responsible for ensuring the security of our platform, protecting customer data, and establishing security practices that scale with our growth. This is a critical early security hire where you'll have significant impact and ownership.
What You'll Do
- Conduct security audits, vulnerability assessments, and penetration testing across our infrastructure and applications
- Implement and maintain security controls for our cloud infrastructure (AWS), databases, and data pipelines
- Build security into our development lifecycle - review code, APIs, and new features for security implications
- Monitor, detect, and respond to security incidents and vulnerabilities
- Manage access controls, secrets management, authentication, and authorization systems
- Drive compliance initiatives to meet enterprise customer requirements
- Establish security best practices and educate the engineering team on secure development
- Secure our API integrations and ensure safe handling of financial data and PII
Ideal Candidate
Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles
Mandatory (Experience 1) – Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience,
Mandatory (Experience 2) – Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.
Mandatory (Experience 3) – Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.
Mandatory (Experience 4) – Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.
Mandatory (Experience 5) – Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.
Mandatory (Experience 6) – Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.
Preferred (Experience 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.
Pay: ₹2,700,000.00 - ₹4,500,000.00 per year
Application Question(s):
- Are you comfortable with a 2-day Work From Office model (Tuesday, Thursday) ?
- What is your notice period in days? (60)
- What is your current CTC in LPA?
- What is your expected CTC in LPA? (45)
Experience:
- overall: 3 years (Required)
- Application/Product Security or Security Engineering: 4 years (Required)
Work Location: Hybrid remote in Bengaluru, Karnataka