Live opening · Posted 11 days ago

Security Engineer

Shortlist Design · Bengaluru, Karnataka, India (On-site)
Linkedin No
You are 11 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 11 days ago
CompanyShortlist Design
LocationBengaluru, Karnataka, India (On-site)
Work modeNo
SourceLinkedin
Listed11 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
8 min from Linkedin publishing this role to us finding it
12 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
70,659 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

We are a hiring company that helps brands hire talents.
Security Engineer @ Product Team, Bangalore, Onsite.
What You’ll Do
Security Posture & Vulnerability Management
Own the end-to-end security posture of the product — identify gaps, prioritise risks, and drive remediation across teams
Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure
Perform static and dynamic application security testing (SAST/DAST) and track findings to closure
Manage a responsible disclosure / bug bounty programme and triage external security reports
Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively
Production System Security
Harden cloud infrastructure (AWS/GCP/Azure) — IAM policies, network segmentation, secrets management, and least-privilege enforcement
Implement and maintain security controls across CI/CD pipelines — dependency scanning, container security, and secure build practices
Oversee endpoint security across all company devices — MDM, EDR tooling, patch management, and access controls
Conduct threat modelling for new product features and infrastructure changes before they ship
Define and enforce secure coding standards; embed security reviews into the engineering workflow
AI-Driven Threat Defence
Identify and mitigate emerging AI-powered attack vectors — automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud
Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools, AI-assisted workflows) and establish guardrails
Stay current on the evolving AI threat landscape and translate research into practical defensive controls
Compliance & Audits
Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS — including evidence collection, gap remediation, and audit readiness
Liaise with external auditors, certification bodies, and enterprise clients during security assessments
Maintain security policies, procedures, and documentation to audit-ready standards at all times
Track regulatory changes across applicable frameworks and update internal controls accordingly
Security Training & Culture
Design and run security awareness training for all employees — phishing simulations, secure coding workshops, and onboarding modules
Champion a security-first engineering culture — make secure-by-default the path of least resistance for every team
Build incident response playbooks and lead tabletop exercises to keep the team prepared
Act as the internal point of contact for security questions, escalations, and policy guidance
What We’re Looking For
Must-Have
4–5 years of hands-on experience in application security, infrastructure security, or a broad security engineering role
Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments
Strong working knowledge of cloud security on AWS, GCP, or Azure — IAM, VPCs, secrets management, and security monitoring
Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices
Deep familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR, and PCI-DSS — including audit preparation and evidence management
Solid understanding of endpoint security — MDM, EDR tools, patch management, and device policy enforcement
Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment
Strong written communication — able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiences
Ownership mindset — you don’t wait for security incidents; you prevent them
Good to Have
Industry certifications: OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent
Experience with authentication protocols and identity security — OAuth 2.0, OpenID Connect, systems, or similar
Familiarity with mobile security (Android/iOS) — relevant given product’s SDK footprint
Experience running a bug bounty or responsible disclosure programme
Prior work at a fintech, identity, or developer-tools company where security is product-critical
Experience with SIEM tools, log analysis platforms, or threat detection pipelines

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App