Security Engineer 2 — ApplicationSecurity
Function: ApplicationSecurity
Reports to: Director ofApplication Security
Experience: 3-5 years
About the Role
Upstoxis looking for a Security Engineer 2 to join our Application Security team.This is a senior individual-contributor role for someone who has moved beyondexecuting assessments to owning the security posture of our cloudinfrastructure, CI/CD pipelines, and containerized services — and who can writereal production-quality code to build the internal tools that scale oursecurity program. You'll work closely with engineering, platform, and DevOpsteams to embed security into how we build and ship software, while alsomentoring Security Engineer 1s and raising the technical bar across the team.
What You'll Do
- Own end-to-end security architecture reviewsfor new and changing systems — assessing the application layer, AWSinfrastructure, and container/orchestration layer together as one system,rather than reviewing each in isolation, and driving remediation of what youfind at scale rather than flagging issues one at a time.
- Embed security checks directly into CI/CDpipelines (SAST, SCA/dependency scanning, container image scanning, secretsdetection, IaC scanning) so vulnerabilities are caught before merge, not afterdeployment.
- Own container and orchestration security —hardening Docker images, reviewing Kubernetes configurations (RBAC, networkpolicies, pod security standards), and closing gaps in how workloads are builtand run in production.
- Design, build, and maintain in-house securitytools and automation — think internal scanners, policy-as-code checks,dashboards that aggregate findings across systems, Just in time access tools orautomation that removes manual steps from recurring assessments. This is acoding role as much as a security one.
- Perform penetration testing across webapplications, mobile applications (Android/iOS), and APIs to identifyvulnerabilities before they reach production.
- Conduct manual and tool-assisted source codereviews to catch security issues early in the development cycle.
- Partner with engineering teams to embedsecurity into the Secure SDLC, including security requirements, design reviews,and release gating.
- Drive and participate in threat modellingexercises for new features and systems.
- Configure, tune, and manage WAF rules(Cloudflare/AWS WAF) to protect production applications and APIs.
- Stay current with the evolving threatlandscape, new attack techniques, and security tooling.
- Partner with the platform/DevOps team oninfrastructure-as-code (Terraform, CloudFormation) security reviews beforeinfrastructure changes ship.
- Track and drive remediation ofvulnerabilities across applications against SLA, working directly withengineering and platform teams to close gaps.
What We're Looking For
- 3-5 years of hands-on experience inapplication, product, or cloud security.
- Strong, hands-on AWS security knowledge — IAMdesign and least-privilege policies, VPC/network security, secrets management(e.g., Secrets Manager/KMS), logging and detection (CloudTrail, Guard Duty), andcommon cloud misconfiguration patterns. This needs to be real operationaldepth, not just familiarity with the console.
- Solid understanding of CI/CD pipelines andhow to secure them — pipeline-as-code, build system trust boundaries, artifactintegrity, secrets in pipelines, and where to insert automated security gates(SAST, SCA, container scanning, IaC scanning) without breaking developervelocity.
- Practical container security experience —Docker image hardening, and Kubernetes security fundamentals (RBAC, networkpolicies, secrets handling, pod security standards).
- Strong coding fundamentals in at least one ofPython, Go, or Rust, with the ability to design and ship a real tool, not justwrite one-off scripts — this role builds security tooling that other engineerswill depend on.
- Solid foundation in application securityfundamentals: penetration testing across web/mobile/API, manual source codereview, Secure SDLC and threat modeling, and authentication/authorizationprotocols (SAML, OAuth, OIDC).
- Experience with infrastructure-as-codesecurity review (Terraform, CloudFormation, or similar).
- Understanding of software supply chainsecurity — dependency risk, SBOMs, and build/artifact integrity.
- Working understanding of AI/LLM securityrisks — prompt injection, insecure output handling, model/data poisoning, andexcessive agency in AI-integrated systems.
<- Strong communication skills — this roleinfluences engineering and platform teams directly and will mentor more juniorengineers.
Good to Have
- Experience with policy-as-code tools(OPA/Rego, Kyverno, or similar) for automated compliance/security checks.
- Exposure to a service mesh (Istio, Linkerd)and its security implications.
- Relevant certifications (e.g., OSCP, OSWE,OSCE, AWS Security Specialty, CKS) and bug bounty experience are a plus but notmandatory.
- Experience operating or building internalsecurity platforms/dashboards at a previous company.
Why Join Us
- Own security architecture decisions forhigh-scale, high-stakes financial products used by millions of users — not justreview them after the fact.
- Build real internal tools used daily by thesecurity and engineering teams, with the autonomy to decide how they'redesigned.
- Work across the full stack of moderncloud-native security — AWS, CI/CD, containers, and application code — ratherthan being siloed into one narrow area.
- A collaborative team that invests in yourgrowth, including a path toward technical leadership and mentoring the nextgeneration of AppSec engineers.
Upstox is an Equal Opportunity Employer; allqualified applicants will receive consideration for employment without regardto race, color, religion, gender, gender identity or expression, sexualorientation, national origin, genetics, disability, age, veteran status, orother characteristics.