Application Security Engineer-2

Darwinbox Digital Solutions Pvt. Ltd.

Bengaluru, Mumbai

On-site

INR 2,500,000 - 4,000,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Upstox is seeking a Security Engineer 2 to join the Application Security team. This senior individual-contributor will own the security posture of our cloud infrastructure, CI/CD pipelines, and containerized services, writing production-ready tools that scale our security program.

You'll embed security into the Secure SDLC, perform penetration testing across web, mobile, and APIs, and mentor Security Engineer 1s while partnering with engineering and DevOps teams to raise the bar across the

Qualifications

  • 3-5 years of hands-on experience in application, product, or cloud security.

Responsibilities

  • Own end-to-end security architecture reviews for new and changing systems, including application, AWS infrastructure and container/orchestration layers.
  • Embed security checks into CI/CD pipelines (SAST, SCA, container scanning, IaC scanning) to catch issues before deployment.
  • Own container and orchestration security—hardening Docker images and reviewing Kubernetes configurations.
  • Design, build, and maintain in-house security tools and automation to centralize findings and reduce manual steps.
  • Perform penetration testing across web, mobile, and APIs to identify vulnerabilities before production.
  • Conduct manual and tool-assisted source code reviews to catch security issues early in development.
  • Partner with engineering teams to embed security into the Secure SDLC and threat modelling for new features.
  • Drive infrastructure-as-code security reviews (Terraform/CloudFormation) before changes ship.
  • Track remediation of vulnerabilities across applications against SLA with platform teams.

Skills

AWS security
CI/CD security
Container security
Python/Go/Rust
Threat modelling
Penetration testing
Auth protocols
IaC security
SBOM awareness
Security tooling

Tools

Terraform
CloudFormation
Kubernetes
Docker
WAF (Cloudflare/AWS)

Job description

Security Engineer 2 — ApplicationSecurity
Function: ApplicationSecurity
Reports to: Director ofApplication Security
Experience: 3-5 years
About the Role

Upstoxis looking for a Security Engineer 2 to join our Application Security team.This is a senior individual-contributor role for someone who has moved beyondexecuting assessments to owning the security posture of our cloudinfrastructure, CI/CD pipelines, and containerized services — and who can writereal production-quality code to build the internal tools that scale oursecurity program. You'll work closely with engineering, platform, and DevOpsteams to embed security into how we build and ship software, while alsomentoring Security Engineer 1s and raising the technical bar across the team.

What You'll Do
  • Own end-to-end security architecture reviewsfor new and changing systems — assessing the application layer, AWSinfrastructure, and container/orchestration layer together as one system,rather than reviewing each in isolation, and driving remediation of what youfind at scale rather than flagging issues one at a time.
  • Embed security checks directly into CI/CDpipelines (SAST, SCA/dependency scanning, container image scanning, secretsdetection, IaC scanning) so vulnerabilities are caught before merge, not afterdeployment.
  • Own container and orchestration security —hardening Docker images, reviewing Kubernetes configurations (RBAC, networkpolicies, pod security standards), and closing gaps in how workloads are builtand run in production.
  • Design, build, and maintain in-house securitytools and automation — think internal scanners, policy-as-code checks,dashboards that aggregate findings across systems, Just in time access tools orautomation that removes manual steps from recurring assessments. This is acoding role as much as a security one.
  • Perform penetration testing across webapplications, mobile applications (Android/iOS), and APIs to identifyvulnerabilities before they reach production.
  • Conduct manual and tool-assisted source codereviews to catch security issues early in the development cycle.
  • Partner with engineering teams to embedsecurity into the Secure SDLC, including security requirements, design reviews,and release gating.
  • Drive and participate in threat modellingexercises for new features and systems.
  • Configure, tune, and manage WAF rules(Cloudflare/AWS WAF) to protect production applications and APIs.
  • Stay current with the evolving threatlandscape, new attack techniques, and security tooling.
  • Partner with the platform/DevOps team oninfrastructure-as-code (Terraform, CloudFormation) security reviews beforeinfrastructure changes ship.
  • Track and drive remediation ofvulnerabilities across applications against SLA, working directly withengineering and platform teams to close gaps.
What We're Looking For
  • 3-5 years of hands-on experience inapplication, product, or cloud security.
  • Strong, hands-on AWS security knowledge — IAMdesign and least-privilege policies, VPC/network security, secrets management(e.g., Secrets Manager/KMS), logging and detection (CloudTrail, Guard Duty), andcommon cloud misconfiguration patterns. This needs to be real operationaldepth, not just familiarity with the console.
  • Solid understanding of CI/CD pipelines andhow to secure them — pipeline-as-code, build system trust boundaries, artifactintegrity, secrets in pipelines, and where to insert automated security gates(SAST, SCA, container scanning, IaC scanning) without breaking developervelocity.
  • Practical container security experience —Docker image hardening, and Kubernetes security fundamentals (RBAC, networkpolicies, secrets handling, pod security standards).
  • Strong coding fundamentals in at least one ofPython, Go, or Rust, with the ability to design and ship a real tool, not justwrite one-off scripts — this role builds security tooling that other engineerswill depend on.
  • Solid foundation in application securityfundamentals: penetration testing across web/mobile/API, manual source codereview, Secure SDLC and threat modeling, and authentication/authorizationprotocols (SAML, OAuth, OIDC).
  • Experience with infrastructure-as-codesecurity review (Terraform, CloudFormation, or similar).
  • Understanding of software supply chainsecurity — dependency risk, SBOMs, and build/artifact integrity.
  • Working understanding of AI/LLM securityrisks — prompt injection, insecure output handling, model/data poisoning, andexcessive agency in AI-integrated systems.
  • <
  • Strong communication skills — this roleinfluences engineering and platform teams directly and will mentor more juniorengineers.
Good to Have
  • Experience with policy-as-code tools(OPA/Rego, Kyverno, or similar) for automated compliance/security checks.
  • Exposure to a service mesh (Istio, Linkerd)and its security implications.
  • Relevant certifications (e.g., OSCP, OSWE,OSCE, AWS Security Specialty, CKS) and bug bounty experience are a plus but notmandatory.
  • Experience operating or building internalsecurity platforms/dashboards at a previous company.
Why Join Us
  • Own security architecture decisions forhigh-scale, high-stakes financial products used by millions of users — not justreview them after the fact.
  • Build real internal tools used daily by thesecurity and engineering teams, with the autonomy to decide how they'redesigned.
  • Work across the full stack of moderncloud-native security — AWS, CI/CD, containers, and application code — ratherthan being siloed into one narrow area.
  • A collaborative team that invests in yourgrowth, including a path toward technical leadership and mentoring the nextgeneration of AppSec engineers.

Upstox is an Equal Opportunity Employer; allqualified applicants will receive consideration for employment without regardto race, color, religion, gender, gender identity or expression, sexualorientation, national origin, genetics, disability, age, veteran status, orother characteristics.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer-2
Application Security Engineer-2

Upstox • Mumbai

Hybrid
INR 2,400,000 - 4,200,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Application Security Architect
Application Security Architect

Orcapod Consulting Services • Hyderabad

Hybrid
INR 4,000,000 - 7,000,000
Comprehensive health insurance
Accidental insurance coverage
Professional development programs
+2
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Senior Application Security Engineer
Senior Application Security Engineer

Tenarai • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

Practice by Numbers • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Security Engineer II
Security Engineer II

Safe Security • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Unlimited vacation policy
High-trust work environment
Commitment to continuous learning
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000