Application Security Engineer-1

Upstox

Mumbai

On-site

INR 1,200,000 - 1,600,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Upstox in India is seeking a Security Engineer 1 — Application Security to secure web, mobile, and API surfaces. You’ll be hands-on across the security lifecycle—from pentesting to threat modelling, cloud security, and embedding security into the software development lifecycle.

This role is for someone with a strong offensive security foundation who enjoys understanding systems, finding weaknesses, and working with engineering teams to fix them and build secure products at scale.

Qualifications

  • 2+ years of hands-on experience in application or product security.
  • Hands-on experience with penetration testing of web, mobile, and APIs.
  • Experience with manual and tool-assisted source code review.
  • Proficiency in Python, Go, or Rust.
  • Working knowledge of AWS or other cloud platforms.
  • Experience with Secure SDLC and threat modelling.
  • Knowledge of authentication protocols such as SAML, OAuth, and OIDC.
  • Understanding of software supply chain security.
  • Experience with Cloudflare and/or AWS WAF.
  • Curiosity to explore new security tools and techniques.

Responsibilities

  • Perform penetration testing across web applications, mobile applications, and APIs to identify vulnerabilities before production.
  • Conduct manual and tool-assisted source code reviews to identify vulnerabilities early in the development lifecycle.
  • Partner with engineering teams to embed security into the Secure SDLC, including security requirements, design reviews, and release gating.
  • Drive and participate in threat modelling exercises for new features and systems.
  • Configure, tune, and manage WAF rules across Cloudflare and AWS WAF to protect production applications and APIs.
  • Write, maintain, and improve scripts and security tools to automate security testing and streamline recurring security assessments.
  • Work with cloud infrastructure, preferably AWS, to review configurations and identify potential security gaps.
  • Track identified vulnerabilities through remediation and work closely with engineering teams to ensure vulnerabilities are addressed within defined SLAs.
  • Stay current with the evolving threat landscape, emerging vulnerabilities, new attack techniques, and application security tooling.

Skills

Penetration testing
Source code review
Python
Go
Rust
AWS
Secure SDLC
OAuth/OIDC
SAML
Cloudflare/WAF
Threat modelling
CI/CD security
Security tooling

Job description

Job Description:
Job Title: Security Engineer 1 — Application Security
Location: Bangalore/Mumbai
Function: Application Security
Experience: 2+ years
About Upstox

At Upstox, we’re building the future of investing — simple, powerful, and for everyone. We're one of India’s fastest-growing fintech platforms, backed by the best in the business, including Mr. Ratan Tata and Tiger Global, and on a mission to make wealth creation accessible to every Indian. From first-time investors to seasoned traders, millions trust us to power their financial journeys. We're not just moving fast — we're moving with purpose. If you thrive in a high-energy, high-impact environment, you're in the right place.

The Role: Security Engineer 1 — Application Security

You’ll join the Application Security team and work hands-on to secure Upstox’s web, mobile, and API surfaces. You’ll be involved across the security lifecycle — from penetration testing and source code reviews to threat modelling, cloud security, and embedding security practices into the software development lifecycle.

This is a role for someone with a strong offensive security foundation who enjoys understanding how products and systems work, finding weaknesses, and working with engineering teams to fix them. You’ll have the opportunity to work closely with engineering teams and contribute to building secure products at scale.

What You’ll Own
  • Perform penetration testing across web applications, mobile applications (Android/iOS), and APIs to identify vulnerabilities before they reach production.
  • Conduct manual and tool-assisted source code reviews to identify security vulnerabilities early in the development lifecycle.
  • Partner with engineering teams to embed security into the Secure SDLC, including security requirements, design reviews, and release gating.
  • Drive and participate in threat modelling exercises for new features and systems.
  • Configure, tune, and manage WAF rules across Cloudflare and AWS WAF to protect production applications and APIs.
  • Write, maintain, and improve scripts and security tools to automate security testing and streamline recurring security assessments.
  • Work with cloud infrastructure, preferably AWS, to review configurations and identify potential security gaps.
  • Track identified vulnerabilities through remediation and work closely with engineering teams to ensure vulnerabilities are addressed within defined SLAs.
  • Stay current with the evolving threat landscape, emerging vulnerabilities, new attack techniques, and application security tooling.
What We’re Looking For:
  • 2+ years of hands-on experience in application or product security.
  • Strong hands-on experience in penetration testing of web applications, mobile applications, and APIs.
  • Strong hands-on experience with manual and/or tool-assisted source code review.
  • Proficiency in at least one programming language: Python, Go, or Rust.
  • Working understanding of at least one cloud platform, preferably AWS.
  • Practical exposure to Secure SDLC and threat modelling practices.
  • Understanding of authentication and authorization protocols such as SAML, OAuth, and OIDC.
  • Understanding of software supply chain security concepts.
  • Experience working with Cloudflare and/or AWS WAF.
  • A strong learning mindset and genuine curiosity to explore new tools, techniques, and areas of application security.
Good to Have:
  • Basic understanding of container security fundamentals, including Docker and Kubernetes.
  • Exposure to DevSecOps practices and integrating security into CI/CD pipelines.
  • Relevant certifications such as OSCP, OSWE, OSCE, or CEH are a plus but not mandatory.
  • Bug bounty experience is a plus but not mandatory.
Why This Role Rocks:

You’ll be part of a high-impact Application Security team working on high-scale, high-stakes financial products used by millions of users. You’ll get direct exposure to modern application, cloud, mobile, and API security challenges while working closely with engineering teams to build security into products from the ground up.

You won't just identify vulnerabilities — you'll help engineering teams fix them, improve security practices, automate recurring security work, and contribute to making the products and systems powering Upstox more secure.

By applying for this position, you acknowledge that you have reviewed our Prospective Employee Privacy Notice, which outlines how Upstox collects, uses, and protects your Personal Information ("PI"). I accept Upstox'sProspective Employee Privacy Notice.

Upstox is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or other characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity -II
Cybersecurity -II

Upstox • Bengaluru Urban

On-site
INR 900,000 - 1,300,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Security Engineer
Security Engineer

Osfin.ai • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Opportunity to build security from the ground up
Work on real-world financial data systems
High ownership and visibility
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Security Engineer (Onsite - Hyderabad)
Security Engineer (Onsite - Hyderabad)

Uplers • Hyderabad

On-site
INR 900,000 - 2,000,000
DevSecOps/ AppSecOps Staff Engineer
DevSecOps/ AppSecOps Staff Engineer

First American (India) • India

On-site
INR 1,200,000 - 1,800,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

Hybrid
INR 2,500,000 - 4,200,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bangalore Rural

On-site
INR 2,500,000 - 4,200,000