Cyber Security Engineer

Recrew AI

Gurugram District

Hybrid

INR 1,400,000 - 2,100,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Security ownership
Modern stack
Direct influence

Job summary

Recrew AI builds AI-powered SaaS for the U.S. dental market, handling protected health information with security as a core product requirement. Thousands of dental practices rely on the platform daily.

As a Cybersecurity Engineer, you will own the security posture of the AWS cloud and diverse applications (Python/Django, FastAPI, Node.js, React). You will find vulnerabilities, fix them, and build controls to prevent recurrence, working hands-on with engineering and audits.

Qualifications

  • Bachelor’s or Master’s in CS or Info Security.
  • 6+ years in cybersecurity with app/cloud security ownership.
  • Strong AWS security experience: IAM, VPC, encryption.
  • Hands-on web API security testing (OWASP Top 10).
  • Experience with SAST/DAST/SCA and container scanning.
  • Familiarity with HIPAA, SOC 2 compliance.

Responsibilities

  • Perform secure code reviews across Python/Django/FastAPI, Node.js, and React/TypeScript codebases; threat-model new features to identify design-level risks.
  • Own SAST, DAST, dependency, secret, and container scanning; triage and drive fixes to closure.
  • Run white-box, grey-box, and black-box testing against applications and APIs; test authentication and multi-tenant isolation.
  • Harden AWS infrastructure — IAM least privilege, VPC segmentation, encryption, and review IaC for security defects.
  • Secure containerized workloads — image hygiene, secrets handling, rotation; manage secrets (AWS Secrets Manager, SOPS, Vault).
  • Lead incident response and vulnerability management end to end; contribute to audits and CI/CD security checks.

Skills

Secure code reviews
SAST/DAST
Cloud security
OWASP Top10
Docker security
Incident response

Education

Bachelor’s or Master’s in CS or Info Security

Tools

AWS IAM
Terraform
Docker
GitHub Actions

Job description

Function: Cybersecurity / Information Security

Location: Kolkata / Gurugram

Type: Full-time

Industry: AI, Medical SaaS, Dental Technology

About Company

The company builds AI-powered SaaS for the U.S. dental market.

Its platform unifies analytics, scheduling, communications, payments, and marketing automation. Thousands of dental practices rely on it daily.

It handles protected health information at scale, making security a core product requirement — not a compliance checkbox. Founded in 2015, the team is mission-driven, execution-oriented, and moves fast.

Position Overview

As a Cybersecurity Engineer, you will own the security posture of the company's AWS cloud infrastructure and its Python/Django, FastAPI, Node.js, and React applications. You will find real vulnerabilities, fix them or drive them to closure, and build the controls and automation that prevent the same class of issue from recurring. This is a hands-on, technical role. You will read code, review architecture, run tests against live systems, tune detections, respond to incidents, and carry the technical side of HIPAA and SOC 2 obligations — working directly with engineering rather than filing findings over a wall.

Role & Responsibilities

  • Perform secure code reviews across Python/Django/FastAPI, Node.js, and React/TypeScript codebases; threat-model new features and services to identify design-level risks before they ship.
  • Own SAST, DAST, dependency, secret, and container scanning — including triage, false-positive reduction, and driving fixes to closure.
  • Run white-box (source-assisted), grey-box (authenticated, partial-knowledge), and black-box (external, zero-knowledge) security testing against applications and APIs; test authentication, authorization, multi-tenant isolation, and session handling; hunt for IDOR, privilege escalation, and tenant data leakage.
  • Harden AWS infrastructure — IAM least privilege, VPC and network segmentation, security groups, encryption at rest and in transit, S3 and RDS controls; review Terraform and infrastructure-as-code for security defects and add policy-as-code guardrails.
  • Secure containerized workloads (Docker, ECS/Fargate or EKS) — image hygiene, runtime configuration, secrets handling; own secrets management practices (AWS Secrets Manager, SOPS, Vault) and key rotation.
  • Build and tune detection and alerting across cloud, application, and access logs; lead incident response — containment, forensics, root cause, and blameless post-incident review; run vulnerability management end to end: discovery, risk-based prioritization, SLA tracking, and verification.
  • Own the engineering side of HIPAA and SOC 2 — implement controls, produce evidence, support audits, maintain audit logging, access review, data retention, and encryption controls; embed security checks into CI/CD (GitHub Actions) and write Python and shell automation for evidence collection, configuration auditing, and remediation.

Must Have Criteria

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related discipline.
  • 6+ years in cybersecurity, with substantial application security or cloud security ownership.
  • Strong AWS security experience — IAM, VPC networking, encryption, logging, and common misconfiguration patterns.
  • Hands-on web application and API security testing (OWASP Top 10, OWASP API Security Top 10) using black-box, grey-box, and white-box approaches.
  • Practical experience with SAST/DAST/SCA and container scanning tooling, including triage and remediation.
  • Working knowledge of Docker and container orchestration (ECS/Fargate or EKS).
  • Experience with vulnerability management and incident response in production environments.
  • Familiarity with HIPAA, SOC 2, or equivalent compliance frameworks.

Nice to Have

  • Security certifications — OSCP, CISSP, AWS Security Specialty, GIAC (GWAPT, GCIH, GCSA), or CEH.
  • Experience securing multi-tenant SaaS platforms and tenant-isolation models.
  • Prior experience carrying a SOC 2 Type II audit or HIPAA program through to completion.
  • Offensive security background — black-box penetration testing, red teaming, or bug bounty experience.
  • Experience scoping and managing third-party black-box or grey-box penetration tests.
  • Experience with event-driven architectures and message-broker security.
  • Detection-as-code and security automation at scale.
  • Exposure to healthcare technology or other regulated domains.
  • Experience securing AI/LLM-integrated applications.

What We Offer

  • Security ownership of a healthcare platform where the stakes are real.
  • Breadth across application, cloud, and operational security in one role.
  • Modern stack: AWS, Terraform, GitHub Actions, Docker, Python, React, PostgreSQL, Kafka-compatible messaging.
  • Direct influence on architecture and engineering practice — not a downstream audit function.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

Practice by Numbers • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Senior Security Engineer
Senior Security Engineer

INDmoney • Bengaluru

On-site
INR 1,500,000 - 2,600,000
DevSecOps Engineer
DevSecOps Engineer

Sutherland Global • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Senior Security Engineer
Senior Security Engineer

Radius Ois • Khordha

On-site
INR 1,500,000 - 2,500,000
DevOps & Security Engineer - AI-Native Healthcare SaaS
DevOps & Security Engineer - AI-Native Healthcare SaaS

Embedded Shishya • Gopalganj

Hybrid
INR 2,200,000 - 3,500,000
Remote work in India
Equipment allowance
Flexible paid leave
Director, Information Security
Director, Information Security

InvestCloud, Inc. • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Security Engineer
Security Engineer

Pentabay Softwares • Chennai District

On-site
INR 900,000 - 1,400,000
Dedicated learning budget for certifications
Work on cutting-edge Healthcare projects
Security-first engineering culture
Security Apps & Operations Engineer
Security Apps & Operations Engineer

RediMinds, Inc • Gurugram District

On-site
INR 1,200,000 - 2,400,000
Certification support
Learning allowance
Security Apps & Operations Engineer
Security Apps & Operations Engineer

Rediminds, Inc. • Gurugram District

On-site
INR 800,000 - 1,500,000
Competitive salary + bonus
Certifications support
Security-first culture
Lead Security Engineer
Lead Security Engineer

Arcana • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000