InfoSec - Application & Cloud Security Engineer (L2)

OpenFX

Bengaluru

On-site

INR 1,200,000 - 2,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity in a rapidly growing company
Growth path to L3 specialist
Hybrid work model

Job summary

OpenFX in Bengaluru offers a hybrid Application + Cloud Security role for engineers with 2–4 years of hands-on security experience. You will split time between AppSec (code reviews, tooling, threat modeling, triage) and CloudSec (AWS IAM reviews, Kubernetes hardening, WAF tuning).

You will work with L3 engineers and grow into a specialist within 12–18 months. This fintech environment values technical curiosity, real security work, and growth.

Qualifications

  • 2–4 years of hands-on experience in Application Security, Cloud Security, or a closely related role.
  • Solid grounding in security fundamentals: OWASP Top 10, TLS/PKI basics, OAuth/JWT.
  • Hands-on exposure to both AppSec (SAST/DAST/manual review) and CloudSec (AWS/GCP/Azure).
  • Scripting ability in Python, Go, or Bash to build internal tools.
  • Clear communicator — can translate a finding into engineers' fixes.
  • Hunger to grow — take feedback well and drive ramp.

Responsibilities

  • Perform manual and automated code reviews with the AppSec engineer, increasing independence over time.
  • Triage and drive remediation on findings from SAST, DAST, SCA, bug bounty, and internal reports.
  • Support threat-modeling sessions for new services and features.
  • Tune and maintain AppSec tooling in CI/CD to minimize noise and maximize signal.
  • Partner with engineering pods to help developers fix issues correctly the first time.
  • In Cloud Security, review IAM policies, harden Kubernetes clusters, tune WAF rules, run vulnerability scans, and drive remediation with DevOps.

Skills

Security experience
OWASP Top 10
Scripting (Python/Go/Bash)
Communication
Growth mindset
AppSec & CloudSec exposure

Education

Degree in Computer Science or Information Security

Tools

Kubernetes
Terraform IaC
Cloud security tooling

Job description

Role Overview

This is a hybrid Application + Cloud Security role for an engineer who has 2–4 years of hands‑on security experience and is ready to grow into a specialist. You'll spend roughly half your time supporting AppSec (code review, secure SDLC tooling, threat modeling, findings triage) and half on CloudSec (AWS account security, IAM reviews, Kubernetes hardening, WAF tuning).

You'll partner closely with our Sr. Application Security Engineer and Cloud Security Engineer (both L3), picking up increasingly complex work as you ramp. The goal is for you to develop deep expertise in one of the two specializations within 12–18 months while remaining strong across both.

This role is ideal for someone who is technically curious, has shipped real security work (not just evaluated tools), and wants to grow fast in a high‑stakes fintech environment.

Key Responsibilities
Application Security (~50%)
  • Perform manual and automated code reviews alongside the Sr. AppSec engineer, with growing independence over time
  • Triage, reproduce, and drive remediation on findings from SAST, DAST, SCA, bug bounty, and internal reports
  • Support threat‑modeling sessions for new services and features
  • Tune and maintain AppSec tooling in CI/CD to minimize noise and maximize signal
  • Partner with engineering pods to help developers fix issues the right way the first time
Cloud Security (~50%)
  • Support AWS account security: IAM policy reviews, least‑privilege analysis, and guardrail enforcement via Config/SCPs
  • Help harden Kubernetes clusters — admission control (OPA/Gatekeeper, Kyverno), RBAC hygiene, secrets management
  • Tune WAF rules (AWS WAF / Cloudflare) to reduce false positives without creating blind spots
  • Run vulnerability scans against cloud infrastructure and containers; drive remediation with DevOps
  • Contribute to security automation: small tools and scripts that reduce manual work (Python / Go / Bash)
  • Monitor GuardDuty, Security Hub, and Config findings; triage and elevate as needed
Cross‑cutting
  • Contribute to security policies, standards, runbooks, and incident playbooks
  • Participate in InfoSec on‑call rotation
  • Research emerging threats and bring recommendations back to the team
What We're Looking For
Required
  • 2–4 years of hands‑on experience in Application Security, Cloud Security, or a closely related role
  • Solid grounding in security fundamentals: OWASP Top 10, TLS/PKI basics, OAuth/JWT, common cloud attack patterns
  • Hands‑on exposure to both AppSec (at least one of SAST/DAST/manual review) and CloudSec (at least one of AWS/GCP/Azure) — you don't need to be expert in both, but you should have shipped work in both
  • Scripting ability in Python, Go, or Bash — you can write useful internal tools, not just one‑liners
  • Clear communicator — can translate a finding into something an engineer will actually fix
  • Hunger to grow — you take feedback well, go deep on topics, and own your ramp
Preferred
  • Degree or equivalent experience in Computer Science, Information Security, or similar
  • Exposure to Kubernetes in production, even if not as the primary owner
  • Familiarity with IaC (Terraform) and how security gets enforced (or bypassed) in code
  • Bug bounty, CTF, or open‑source security contributions — demonstrated curiosity outside the 9‑to‑5
  • Certifications a plus but not required: AWS Security Specialty, OSCP, CKS, CEH
What We Offer
  • Competitive salary and benefits package
  • Equity in a rapidly growing company
  • Opportunity to work in a fast‑paced startup at the forefront of fintech innovation
  • A real growth path — this role is designed to develop you into an L3 specialist
  • Collaborative work culture with emphasis on personal and professional growth

We are committed to building a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Security & Infrastructure Engineer
Security & Infrastructure Engineer

Taglynk • Bengaluru Urban

On-site
INR 1,200,000 - 1,800,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

Hybrid
INR 2,500,000 - 4,200,000
Senior Security Engineer- 2
Senior Security Engineer- 2

42 Gears Mobility Systems • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Interesting Job Opportunity: Security Engineer - Cloud & Infrastructure Security
Interesting Job Opportunity: Security Engineer - Cloud & Infrastructure Security

SMC • Delhi

On-site
INR 1,500,000 - 2,500,000
Security Engineer III Product
Security Engineer III Product

Framework Ventures • New Delhi

On-site
INR 2,500,000 - 4,500,000
Security Architect
Security Architect

ValueLabs • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Senior Cloud Developer (Data)
Senior Cloud Developer (Data)

BXB Digital, A Brambles Company • Bengaluru

On-site
INR 1,200,000 - 2,000,000