Application Security Engineer-2

Upstox

Mumbai

Hybrid

INR 2,400,000 - 4,200,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Upstox is seeking a Security Engineer 2 to own the security posture of our cloud infrastructure, CI/CD pipelines, and containerized services. You will write production-grade tooling and mentor junior engineers while embedding security into the software delivery lifecycle.

You will collaborate with engineering, platform, and DevOps teams to scale security across applications, APIs, and cloud resources, driving secure design and rapid remediation at pace.

Qualifications

  • 3–5 years in application, product, or cloud security.
  • Strong AWS security knowledge with IAM, VPC, secrets management, logging/detection.
  • Proficient in Python, Go, or Rust for building tooling.
  • Solid foundation in Secure SDLC, penetration testing, and threat modeling.

Responsibilities

  • Own end-to-end security architecture reviews for new/changed systems, integrating across app, AWS, and container layers.
  • Embed security checks into CI/CD pipelines (SAST, SCA, image scanning, IaC scanning).
  • Own container and orchestration security (Docker/Kubernetes) including RBAC and network policies.
  • Design, build, and maintain in-house security tools and automation for scalable security operations.
  • Perform pen tests across web, mobile, and APIs to identify production risks.
  • Conduct manual and tool-assisted source code reviews to catch issues early.

Skills

AWS security
CI/CD security
Container security
SAST/SCA
IaC scanning
Python/Go/Rust
Penetration testing
Threat modeling
Communication skills

Tools

Docker
Kubernetes
Terraform
CloudFormation
OPA/Rego
WAF (Cloudflare/AWS)

Job description

Security Engineer 2 — Application Security

Location: Bangalore/Mumbai

Function: Application Security

Reports to: Director of Application Security

Experience: 3-5 years

About The Role

Upstox is looking for a Security Engineer 2 to join our Application Security team. This is a senior individual-contributor role for someone who has moved beyond executing assessments to owning the security posture of our cloud infrastructure, CI/CD pipelines, and containerized services — and who can write real production-quality code to build the internal tools that scale our security program. You'll work closely with engineering, platform, and DevOps teams to embed security into how we build and ship software, while also mentoring Security Engineer 1s and raising the technical bar across the team.

What You'll Do
  • Own end-to-end security architecture reviews for new and changing systems — assessing the application layer, AWS infrastructure, and container/orchestration layer together as one system, rather than reviewing each in isolation, and driving remediation of what you find at scale rather than flagging issues one at a time.
  • Embed security checks directly into CI/CD pipelines (SAST, SCA/dependency scanning, container image scanning, secrets detection, IaC scanning) so vulnerabilities are caught before merge, not after deployment.
  • Own container and orchestration security — hardening Docker images, reviewing Kubernetes configurations (RBAC, network policies, pod security standards), and closing gaps in how workloads are built and run in production.
  • Design, build, and maintain in-house security tools and automation — think internal scanners, policy-as-code checks, dashboards that aggregate findings across systems, Just in time access tools or automation that removes manual steps from recurring assessments. This is a coding role as much as a security one.
  • Perform penetration testing across web applications, mobile applications (Android/iOS), and APIs to identify vulnerabilities before they reach production.
  • Conduct manual and tool-assisted source code reviews to catch security issues early in the development cycle.
  • Partner with engineering teams to embed security into the Secure SDLC, including security requirements, design reviews, and release gating.
  • Drive and participate in threat modelling exercises for new features and systems.
  • Configure, tune, and manage WAF rules (Cloudflare/AWS WAF) to protect production applications and APIs.
  • Stay current with the evolving threat landscape, new attack techniques, and security tooling.
  • Partner with the platform/DevOps team on infrastructure-as-code (Terraform, CloudFormation) security reviews before infrastructure changes ship.
  • Track and drive remediation of vulnerabilities across applications against SLA, working directly with engineering and platform teams to close gaps.
What We're Looking For
  • 3-5 years of hands-on experience in application, product, or cloud security.
  • Strong, hands-on AWS security knowledge — IAM design and least-privilege policies, VPC/network security, secrets management (e.g., Secrets Manager/KMS), logging and detection (CloudTrail, Guard Duty), and common cloud misconfiguration patterns. This needs to be real operational depth, not just familiarity with the console.
  • Solid understanding of CI/CD pipelines and how to secure them — pipeline-as-code, build system trust boundaries, artifact integrity, secrets in pipelines, and where to insert automated security gates (SAST, SCA, container scanning, IaC scanning) without breaking developer velocity.
  • Practical container security experience — Docker image hardening, and Kubernetes security fundamentals (RBAC, network policies, secrets handling, pod security standards). Good to have in Security Engineer 1; required here.
  • Strong coding fundamentals in at least one of Python, Go, or Rust, with the ability to design and ship a real tool, not just write one-off scripts — this role builds security tooling that other engineers will depend on.
  • Solid foundation in application security fundamentals: penetration testing across web/mobile/API, manual source code review, Secure SDLC and threat modeling, and authentication/authorization protocols (SAML, OAuth, OIDC).
  • Experience with infrastructure-as-code security review (Terraform, CloudFormation, or similar).
  • Understanding of software supply chain security — dependency risk, SBOMs, and build/artifact integrity.
  • Working understanding of AI/LLM security risks — prompt injection, insecure output handling, model/data poisoning, and excessive agency in AI-integrated systems.
  • Strong communication skills — this role influences engineering and platform teams directly and will mentor more junior engineers.
Good to Have
  • Experience with policy-as-code tools (OPA/Rego, Kyverno, or similar) for automated compliance/security checks.
  • Exposure to a service mesh (Istio, Linkerd) and its security implications.
  • Relevant certifications (e.g., OSCP, OSWE, OSCE, AWS Security Specialty, CKS) and bug bounty experience are a plus but not mandatory.
  • Experience operating or building internal security platforms/dashboards at a previous company.
Why Join Us
  • Own security architecture decisions for high-scale, high-stakes financial products used by millions of users — not just review them after the fact.
  • Build real internal tools used daily by the security and engineering teams, with the autonomy to decide how they're designed.
  • Work across the full stack of modern cloud-native security — AWS, CI/CD, containers, and application code — rather than being siloed into one narrow area.
  • A collaborative team that invests in your growth, including a path toward technical leadership and mentoring the next generation of AppSec engineers.

Upstox is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or other characteristics.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer-2
Application Security Engineer-2

Darwinbox Digital Solutions Pvt. Ltd. • Bengaluru, Mumbai

On-site
INR 2,500,000 - 4,000,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

On-site
INR 9,033,424 - 11,743,451
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

On-site
INR 2,500,000 - 4,200,000
Security Engineer II
Security Engineer II

Safe Security • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Unlimited vacation policy
High-trust work environment
Commitment to continuous learning
Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

Practice by Numbers • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Application Security Analyst – Java / DevSecOps
Application Security Analyst – Java / DevSecOps

Hireflex247 India Private Limited • India

On-site
INR 1,500,000 - 2,700,000
Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000