Cyber Security Engineer

slice

Bengaluru

On-site

INR 1,200,000 - 2,000,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical insurance
Flexible working hours
Learning opportunities
Office culture

Job summary

slice is seeking a Cyber Security Engineer to strengthen our Application and Product Security program across SDLC. You will partner with engineering, product, and infrastructure teams to identify security risks early and help build secure, scalable products that meet industry standards.

This role focuses on offensive security, secure design, mobile and API security, and DevSecOps, with hands-on VAPT across web, API, and mobile apps, plus threat modeling and secure coding guidance.

Qualifications

  • 1–2 years of experience in Application Security, Product Security, or Cyber Security.
  • Strong understanding of web application, API, Android, and iOS security concepts.
  • Hands-on experience performing penetration testing of web applications, APIs, and mobile applications.
  • Hands-on experience in identifying and assessing network security vulnerabilities and security misconfigurations.
  • Familiarity with OWASP Top 10, OWASP API Security Top 10, and OWASP MASVS/MSTG.
  • Knowledge of authentication/authorization mechanisms (OAuth2, JWT, OIDC).
  • Experience with SSDLC and secure coding practices.
  • Proven ability to write technical security reports and remediation recommendations.

Responsibilities

  • Perform end-to-end vulnerability assessment and penetration testing for web applications, APIs, Android and iOS apps.
  • Conduct secure design reviews and threat modeling for new applications and features.
  • Validate security controls and re-test after remediation.
  • Develop security assessment reports with remediation guidance and risk prioritization.
  • Create security automation and scripts to improve testing workflows.
  • Collaborate with engineers, product, and infra teams to drive secure-by-design principles.

Skills

VAPT
Mobile security
OWASP
Pen testing
Python scripting

Tools

Burp Suite
MobSF
Frida
Objection
Postman
Nmap
Subfinder
Amass

Job description

slice’s purpose is to make the world better at using money and time, with a major focus on


building the best consumer experience for your money. We’ve all felt how slow, confusing, and complicated banking can be. So, we’re reimagining it. We’re building every product from scratch to be fast, transparent, and feel good, because we believe that the best products transcend demographics, like how great music touches most of us.


Our cornerstone products and services: slice savings account, slice UPI credit card, slice UPI, and slice business are designed to be simple, rewarding, and completely in your control. At slice, you’ll get to build things you’d use yourself and shape the future of banking in India. We tailor our working experience with the belief that the present moment is the only real thing in life. And we have harmony in the present the most when we feel happy and successful together.


We’re backed by some of the world’s leading investors, including Tiger Global, Insight Partners, Advent International, Blume Ventures, and Gunosy Capital.


About the Role

As a Cyber Security Engineer at slice, you will play a key role in strengthening our Application and Product Security program by embedding security throughout the Software Development Lifecycle (SDLC). You will work closely with engineering, product, and infrastructure teams to identify security risks early, conduct security assessments, and help build secure, scalable products that meet industry standards and compliance requirements.


This role is ideal for someone passionate about offensive security, secure design, mobile and API security, and DevSecOps.


What You’ll Do

Application Security


  • Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, Android, and iOS applications.

  • Conduct Secure Design Reviews and identify potential security risks during the design phase.

  • Perform Threat Modeling sessions for new applications, services, and major feature releases.

  • Validate security controls and perform security re-testing after vulnerabilities are remediated.

  • Prepare detailed security assessment reports with clear remediation guidance and risk prioritization.

  • Perform static and dynamic security analysis of Android and iOS applications.

  • Assess REST APIs and microservices for authentication, authorization, business logic, and data exposure vulnerabilities.

  • Identify vulnerabilities such as:

  • Sensitive Data Exposure

  • Business Logic flaws

  • Security Misconfiguration

  • SSRF, XXE, CSRF, XSS, and related web security issues


.



  • Provide secure coding recommendations and remediation guidance.

  • Contribute to the implementation and improvement of SAST, DAST, SCA, Secret Scanning, and Infrastructure-as-Code (IaC) security practices.

  • Evaluate new technologies and architectures from a security perspective and recommend appropriate security controls.

  • Develop scripts and automation to improve security testing and vulnerability management workflows.

  • Contribute to internal security tools and automation initiatives.

  • Assist in improving security processes, standards, and documentation.

  • Partner with developers, architects, product managers, and infrastructure teams to drive secure‑by‑design principles.

  • Provide technical security guidance during feature development and product releases.

  • Ensure applications and infrastructure comply with internal security requirements and applicable industry standards.


What You’ll Need


  • 1–2 years of experience in Application Security, Product Security, or Cyber Security.

  • Strong understanding of web application, API, Android, and iOS security concepts.

  • Hands‑on experience performing penetration testing of web applications, APIs, and mobile applications.

  • Hands‑on experience in identifying and assessing network security vulnerabilities and security misconfigurations.

  • Good understanding of:

  • OWASP Top 10

  • OWASP API Security Top 10

  • OWASP Mobile Application Security (MASVS/MSTG)

  • Knowledge of authentication and authorization mechanisms including OAuth2, JWT, OIDC, and session management.

  • Good understanding of Secure Software Development Lifecycle (SSDLC) and secure coding practices.

  • Familiarity with common security vulnerabilities and exploitation techniques.

  • Experience writing technical security reports and communicating remediation recommendations.

  • Strong analytical, problem‑solving, and communication skills.

  • Experience with Linux systems and networking fundamentals.

  • Experience with scripting using Python, Bash, or similar languages for automation.


Tools & Technologies

Experience with one or more of the following tools is preferred:



  • Burp Suite

  • MobSF

  • Frida

  • Objection

  • Postman

  • Nmap

  • Subfinder

  • Amass


Good to Have


  • Familiarity with AWS security concepts.

  • Experience with SAST, DAST, SCA, Secret Scanning, and IaC Security.

  • Experience with cloud‑native application security.

  • Participation in Bug Bounty programs or responsible disclosure programs.

  • Contributions to open‑source security projects.

  • Familiarity with AI‑assisted security testing and automation.


Preferred Certifications


  • eJPT

  • eWPT

  • eMAPT

  • PNPT

  • OSCP (Good to Have)


What We Look For


  • Passion for offensive security and continuous learning.

  • Strong ownership and accountability.

  • Curiosity to understand how systems work and how they can be secured.

  • Ability to communicate effectively with engineering and business stakeholders.

  • A collaborative mindset and willingness to improve security processes across the organization.


Life at slice

Life so good, you’d think we’re kidding:



  • An extensive medical insurance that looks out for our employees & their dependents. We’ll love you and take care of you, our promise.

  • Flexible working hours. Just don’t call us at 3AM, we like our sleep schedule.

  • Tailored vacation & leave policies so that you enjoy every important moment in your life.

  • A reward system that celebrates hard work and milestones throughout the year. Expect a gift coming your way anytime you kill it here.

  • Learning and upskilling opportunities. Seriously, not kidding.

  • Good food, games, and a cool office to make you feel like home. An environment so good, you’ll forget the term “colleagues can’t be your friends”

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

slice • Bengaluru

On-site
INR 600,000 - 1,200,000
Medical insurance
Flexible working hours
Vacation policy
+2
Senior Staff Software Engineer (Site Reliability)
Senior Staff Software Engineer (Site Reliability)

slice • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Extensive medical insurance
Flexible working hours
Tailored vacation policies
+3
Staff Engineer (Infrastructure)
Staff Engineer (Infrastructure)

slice • Bengaluru

On-site
INR 4,000,000 - 6,600,000
Medical insurance
Flexible hours
Generous leave
+2
Senior Engineering Manager - Backend
Senior Engineering Manager - Backend

slice • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Competitive salaries
Medical insurance
Flexible working hours
+3
Engineering Manager - Backend
Engineering Manager - Backend

slice • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Competitive salary
Medical insurance
Flexible hours
+4
End User Technology Engineer II
End User Technology Engineer II

slice • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive salary
Medical insurance for employees and 
r
Flexible working hours
+4
Senior Cloud Security Engineer
Senior Cloud Security Engineer

slice • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Extensive medical insurance
Flexible working hours
Tailored vacation & leave policies
+3
Analytics Engineer 2 - Data Platform
Analytics Engineer 2 - Data Platform

slice • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Competitive salaries
Medical insurance for you and depend -
Flexible working hours
+4
Engineer 1 - IS Compliance
Engineer 1 - IS Compliance

slice • Bengaluru

On-site
INR 600,000 - 1,200,000
Competitive salary
Medical insurance
Flexible hours
+3
Technical Program Manager II - GRC Modernization & Governance Process
Technical Program Manager II - GRC Modernization & Governance Process

slice • Bengaluru

On-site
INR 3,500,000 - 7,500,000
Medical insurance
Flexible working hours
Tailored vacation & leave policies
+2