Offensive Security Engineer

UST

Ernakulam

On-site

INR 2,400,000 - 3,600,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

UST in Kerala, India is seeking an Offensive Security Engineer to protect our technology and data by identifying exploitable weaknesses and validating security controls across applications, APIs, cloud environments and infrastructure.

The role is hands-on, focusing on security testing, threat emulation, vulnerability lifecycle management and embedding secure practices within the software development lifecycle, working closely with engineering and security teams.

Qualifications

  • Experience in cybersecurity, application security, penetration testing, security engineering or DevSecOps.
  • Strong knowledge of web application, API and cloud security.
  • Hands-on experience with security testing tools such as SAST, DAST and CSPM platforms.
  • Understanding of secure software development and CI/CD environments.
  • Experience identifying, validating and remediating security vulnerabilities.
  • Knowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST and PCI DSS.
  • Ability to automate tasks using scripting languages such as Python or PowerShell.
  • Strong analytical and problem-solving capabilities.
  • Excellent stakeholder engagement and communication skills.
  • Ability to provide practical, risk-based security advice to technical and business teams.
  • Relevant cybersecurity qualifications, certifications or equivalent industry experience.
  • A passion for emerging security technologies, automation and continuous improvement.

Responsibilities

  • Plan and perform authorised, risk-based security testing across web apps, APIs, infrastructure, networks and cloud workloads.
  • Operate, administer and optimise security testing platforms (SAST, DAST, CSPM).
  • Embed security testing early in the SDLC and support secure development practices.
  • Integrate security testing into code repos, IDEs and CI/CD pipelines.
  • Conduct authorised penetration testing, threat modelling and design reviews.
  • Document findings with severity, impact and remediation timelines.
  • Track remediation progress and retest vulnerabilities.
  • Use cloud posture tooling to assess vulnerabilities and misconfigurations.
  • Conduct MITRE ATT&CK-aligned control validation and adversary emulation.
  • Provide remediation guidance aligned to OWASP Top 10 and PCI DSS.
  • Automate discovery, testing, ticketing, evidence collection and reporting.
  • Produce evidence-based reports and control-effectiveness insights.

Skills

Cybersecurity
Application security
Penetration testing
Security engineering
DevSecOps
Web security
API security
Cloud security
SAST/DAST/CSPM
CI/CD security
OWASP Top 10
MITRE ATT&CK
ISO 27001/NIST/PCI DSS
Automation with Python/PowerShell

Tools

SAST tooling
DAST tooling
CSPM tooling

Job description

Job Description We have an exciting opportunity for an Offensive Security Engineer to join our Technology team. This role plays an important part in protecting the confidentiality, integrity, availability and resilience of technology and data by identifying exploitable weaknesses before they cause harm, validating the effectiveness of security controls, and supporting safer delivery across our technology environment. Reporting to the Senior Manager, Security Compliance & Governance, you ll work closely with engineering, cloud, platform, infrastructure, architecture and security teams to embed security early in the software development lifecycle, reduce vulnerabilities reaching production, and provide evidence-based assurance across applications, APIs, cloud environments and security controls. This is a hands‑on role for someone who enjoys practical security testing, automation, threat emulation, vulnerability lifecycle management and working with technical teams to improve security outcomes in a complex enterprise environment.

What You ll Do
  • Plan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services and cloud-hosted workloads.
  • Operate, administer and optimise security testing platforms, including SAST, DAST, CSPM and attack simulation tooling.
  • Embed security testing early in the software development lifecycle and support secure development practices across engineering teams.
  • Integrate application security, dependency, open-source risk, DAST and API security testing controls into code repositories, IDEs and CI/CD pipelines.
  • Conduct authorised penetration testing, technical security assessments, security design reviews and threat modelling for material changes.
  • Validate, triage and document security findings, including severity, business impact, accountable owners, target remediation dates and closure evidence.
  • Track remediation progress, retest resolved vulnerabilities and escalation overdue or material findings where required.
  • Use cloud security posture management tooling to assess cloud vulnerabilities, misconfigurations, attack paths and compliance posture.
  • Conduct MITRE ATT&CK-aligned control validation, adversary emulation and purple team activities across key security controls.
  • Provide practical remediation advice to engineering and technology teams, including guidance aligned to OWASP Top 10, PCI DSS secure coding requirements and secure AI development practices.
  • Automate repeatable discovery, testing, ticketing, evidence collection, reporting, remediation tracking and validation activities where practical.
  • Produce evidence-based reports, service metrics and control-effectiveness insights to support operational, executive, audit and governance reporting.
What You ll Bring
  • Experience in cybersecurity, application security, penetration testing, security engineering or DevSecOps.
  • Strong knowledge of web application, API and cloud security.
  • Hands‑on experience with security testing tools such as SAST, DAST and CSPM platforms.
  • Understanding of secure software development and CI/CD environments.
  • Experience identifying, validating and remediating security vulnerabilities.
  • Knowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST and PCI DSS.
  • Ability to automate tasks using scripting languages such as Python or PowerShell.
  • Strong analytical and problem-solving capabilities.
  • Excellent stakeholder engagement and communication skills.
  • Ability to provide practical, risk-based security advice to technical and business teams.
  • Relevant cybersecurity qualifications, certifications or equivalent industry experience.
  • A passion for emerging security technologies, automation and continuous improvement.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Executive - QA
Executive - QA

INTECH Creative Services Pvt. Ltd. • Mumbai, Navi Mumbai

On-site
INR 1,500,000 - 2,600,000
Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Security Engineer
Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Penetration Testing Senior Consultant
Penetration Testing Senior Consultant

Alignity Solutions • Hyderabad

Hybrid
INR 1,800,000 - 3,000,000
Hybrid work
Security Engineer
Security Engineer

Ingenium Digital • Bengaluru

Hybrid
INR 3,250,000 - 6,500,000
Security Engineer - OSCP
Security Engineer - OSCP

TAC Security • Delhi

On-site
INR 1,200,000 - 1,800,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Security & Compliance Engineer Intern
Security & Compliance Engineer Intern

AI Prof • Hyderabad

On-site
INR 1,500,000 - 2,100,000