Live opening · Posted 4 days ago

Application Security Engineer-2

Upstox · Mumbai, Maharashtra, India | Bangalore, Karnataka, India
Darwinbox No Permanent 3 - 5 Years
You are 4 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 4 days ago
CompanyUpstox
LocationMumbai, Maharashtra, India | Bangalore, Karnataka, India
Experience3 - 5 Years
Job typePermanent
Work modeNo
SourceDarwinbox
Listed4 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
731 min from Darwinbox publishing this role to us finding it
13 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
58,880 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Security Engineer 2 — Application
Security
Location: Bangalore/Mumbai
Function: Application
Security
Reports to: Director of
Application Security
Experience: 3-5 years
About the Role
Upstox
is looking for a Security Engineer 2 to join our Application Security team.
This is a senior individual-contributor role for someone who has moved beyond
executing assessments to owning the security posture of our cloud
infrastructure, CI/CD pipelines, and containerized services — and who can write
real production-quality code to build the internal tools that scale our
security program. You'll work closely with engineering, platform, and DevOps
teams to embed security into how we build and ship software, while also
mentoring Security Engineer 1s and raising the technical bar across the team.
What You'll Do
• Own end-to-end security architecture reviews
for new and changing systems — assessing the application layer, AWS
infrastructure, and container/orchestration layer together as one system,
rather than reviewing each in isolation, and driving remediation of what you
find at scale rather than flagging issues one at a time.
• Embed security checks directly into CI/CD
pipelines (SAST, SCA/dependency scanning, container image scanning, secrets
detection, IaC scanning) so vulnerabilities are caught before merge, not after
deployment.
• Own container and orchestration security —
hardening Docker images, reviewing Kubernetes configurations (RBAC, network
policies, pod security standards), and closing gaps in how workloads are built
and run in production.
• Design, build, and maintain in-house security
tools and automation — think internal scanners, policy-as-code checks,
dashboards that aggregate findings across systems, Just in time access tools or
automation that removes manual steps from recurring assessments. This is a
coding role as much as a security one.
• Perform penetration testing across web
applications, mobile applications (Android/iOS), and APIs to identify
vulnerabilities before they reach production.
• Conduct manual and tool-assisted source code
reviews to catch security issues early in the development cycle.
• Partner with engineering teams to embed
security into the Secure SDLC, including security requirements, design reviews,
and release gating.
• Drive and participate in threat modelling
exercises for new features and systems.
• Configure, tune, and manage WAF rules
(Cloudflare/AWS WAF) to protect production applications and APIs.
• Stay current with the evolving threat
landscape, new attack techniques, and security tooling.
• Partner with the platform/DevOps team on
infrastructure-as-code (Terraform, CloudFormation) security reviews before
infrastructure changes ship.
• Track and drive remediation of
vulnerabilities across applications against SLA, working directly with
engineering and platform teams to close gaps.
What We're Looking For
• 3-5 years of hands-on experience in
application, product, or cloud security.
• Strong, hands-on AWS security knowledge — IAM
design and least-privilege policies, VPC/network security, secrets management
(e.g., Secrets Manager/KMS), logging and detection (CloudTrail, Guard Duty), and
common cloud misconfiguration patterns. This needs to be real operational
depth, not just familiarity with the console.
• Solid understanding of CI/CD pipelines and
how to secure them — pipeline-as-code, build system trust boundaries, artifact
integrity, secrets in pipelines, and where to insert automated security gates
(SAST, SCA, container scanning, IaC scanning) without breaking developer
velocity.
• Practical container security experience —
Docker image hardening, and Kubernetes security fundamentals (RBAC, network
policies, secrets handling, pod security standards). Good to have in Security
Engineer 1; required here.
• Strong coding fundamentals in at least one of
Python, Go, or Rust, with the ability to design and ship a real tool, not just
write one-off scripts — this role builds security tooling that other engineers
will depend on.
• Solid foundation in application security
fundamentals: penetration testing across web/mobile/API, manual source code

Experience
3 - 5 Years

Employment type
Permanent

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App