Platform Security Engineer

Phinite.ai

India

On-site

INR 900,000 - 1,800,000

Full time

23 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Phinite.ai, an early-stage company building a platform for running AI agents in production, seeks a Security Engineer to own security end-to-end across the product and infrastructure.

You’ll work across backend, cloud, identity systems, data and developer platform, designing practical defenses, leading incident response, and guiding engineers to bake security into the stack from day one.

Qualifications

  • 3+ years securing production apps and infrastructure.
  • Strong fundamentals in application and cloud security.
  • Experience with authentication, authorization, identity and access control.
  • Familiarity with OWASP Top 10 and web/API security.

Responsibilities

  • Own security initiatives from threat identification through implementation and monitoring.
  • Conduct threat modeling for new products and major changes.
  • Identify and remediate vulnerabilities across apps, infra, cloud, and CI/CD.
  • Collaborate with backend and infra engineers to bake security in from the start.
  • Design authentication, authorization, and secrets management patterns.
  • Review APIs and services for access control and data exposure risks.
  • Secure cloud infrastructure, containers, databases, and messaging systems.
  • Lead incident response, root-cause analysis and remediation.
  • Automate security checks and provide practical remediation guidance.

Skills

Security engineering
Threat modeling
Vulnerability remediation
Identity & access control
Authentication & authorization
Security monitoring

Tools

AWS
GCP
Azure
Kubernetes
Docker
Terraform
CI/CD pipelines
OpenID Connect
JWT
SIEM

Job description

Phinite.ai is an early-stage company building a platform for running AI agents in production, with evaluation, guardrails, governance and observability built in. We work with enterprise customers, so security is central to what we ship.

About the role

We're looking for a Security Engineer who enjoys owning security problems end to end and building security into the product and infrastructure instead of treating it as a checklist.

You’ll work across our backend, cloud infrastructure, applications, identity systems, data and developer platform. This role goes beyond running scanners and writing reports. You’ll identify real risks, design practical defenses, investigate incidents and work directly with engineers to make the whole system more secure, with meaningful ownership over security across the product and engineering stack.

What you’ll do
  • Own security initiatives from threat identification and design through implementation, monitoring and continuous improvement
  • Run threat modeling for new products, services, APIs, infrastructure and major architectural changes
  • Find and fix vulnerabilities across applications, infrastructure, cloud environments, dependencies, containers and CI/CD pipelines
  • Work with backend and infrastructure engineers to build security in from the start
  • Design and improve authentication, authorization, identity, session management, secrets management and access control
  • Review APIs and distributed services for access control, data exposure, injection, abuse and other risks
  • Secure cloud infrastructure, networking, containers, Kubernetes, databases, queues, storage and internal services
  • Build controls that hold up in real conditions: compromised credentials, privilege escalation, exposed secrets, compromised dependencies and misconfiguration
  • Run vulnerability management: prioritization, remediation, verification and tracking
  • Improve security monitoring, detection, alerting and incident response
  • Lead security incidents from detection through containment, root-cause analysis, remediation and prevention
  • Automate security checks such as secrets detection, dependency scanning and access reviews
  • Give engineers practical remediation guidance, not just a list of findings
  • Establish secure engineering patterns and tooling that make the secure path the easy path
  • Join architecture discussions and challenge designs when security matters
What we’re looking for
  • 3+ years of experience securing production applications and infrastructure
  • Strong fundamentals in application, infrastructure and cloud security
  • Strong understanding of authentication, authorization, identity, access control, sessions, secrets and cryptography
  • Strong knowledge of common web and API vulnerabilities, including the OWASP Top 10
  • Strong understanding of network security: TLS, DNS, firewalls, proxies, load balancers and service-to-service communication
  • Ability to read an architecture, identify realistic attack paths and propose practical mitigations
  • Experience determining the real impact and exploitability of vulnerabilities
  • Strong grasp of least privilege, defense in depth and secure defaults
  • Good understanding of distributed systems and the security problems they introduce
  • Ability to tell meaningful risks from theoretical issues, and to explain risk clearly without security theater
  • Comfort with ambiguity and making decisions on incomplete information
  • Strong ownership mindset, following difficult problems through to resolution
Nice to have
  • Cloud security on AWS, GCP, Azure or similar
  • Kubernetes and container security
  • IAM systems and identity platforms
  • OAuth 2.0, OpenID Connect, JWT, API keys, service accounts and workload identity
  • Application security testing, penetration testing or red-team experience
  • SAST, DAST, SCA, container scanning, secrets detection and vulnerability-management platforms
  • SIEM, security monitoring or detection engineering
  • Incident response and digital forensics
  • CI/CD and software supply-chain security
  • Key management and cryptographic systems
  • Securing PostgreSQL, MongoDB, Redis and Kafka
  • Building security tooling in Go, TypeScript, Python or similar
  • Experience at an early-stage or high-growth startup

We believe most technologies can be learned when needed, but familiarity with these is a big plus: Go / TypeScript / Python, Linux, Docker / Kubernetes, AWS / GCP / Azure, PostgreSQL / Redis, Kafka, Terraform, GitHub Actions / GitLab CI / ArgoCD, OAuth 2.0 / OpenID Connect / JWT, Prometheus / Grafana / OpenTelemetry / SIEM tooling, and secrets management and KMS systems.

What we value
  • Ownership over handoffs: you don't just report a vulnerability, you help drive it to resolution
  • Real security over compliance theater: we care about actual attack paths and whether our controls work
  • Secure by design: security belongs in the design, not just after deployment
  • Practical security over unnecessary friction: not every theoretical issue deserves a six-week project
  • Defense in depth and least privilege
  • Detection and response: we don't assume prevention is perfect
  • Engineering judgment over blindly following frameworks: standards are tools, not substitutes for understanding our architecture and threat model
This may not be the role for you if
  • You want a narrow role that ends once vulnerability tickets are filed
  • You see security mainly as a compliance or documentation exercise
  • You rely on automated scanners without understanding what they detect
  • You report vulnerabilities without understanding their exploitability, impact or fix
  • You're uncomfortable reading backend code, infrastructure configuration or system architecture
  • You're uncomfortable with Linux, networking, APIs, databases, containers or cloud infrastructure
  • You believe adding a WAF or a security product makes an application secure
  • You rely on AI-generated security configurations without understanding their implications
  • You'd leave a known security issue open because it belongs to another team
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

Practice by Numbers • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Software Engineering PMTS - Cloud Infra & Security - Hyderabad
Software Engineering PMTS - Cloud Infra & Security - Hyderabad

Leadout Capital • Hyderabad

On-site
INR 4,200,000 - 7,000,000
Senior Security Engineer
Senior Security Engineer

Oolka • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Product Security Engineer
Senior Product Security Engineer

Whatfix • Bengaluru

On-site
INR 4,200,000 - 7,000,000
Head of Security Engineering
Head of Security Engineering

Brevan Howard • Bengaluru Urban

On-site
INR 1,800,000 - 2,500,000
. Security Engineer — Security Operations
. Security Engineer — Security Operations

Aistra • Pune District

On-site
INR 3,000,000 - 4,200,000
Senior Product Security Engineer
Senior Product Security Engineer

Whatfix Inc. • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Product Security Engineer
Senior Product Security Engineer

Pocket FM Corp. • Bengaluru

On-site
INR 2,000,000 - 3,200,000
Director, Information Security
Director, Information Security

InvestCloud, Inc. • Bengaluru

On-site
INR 3,500,000 - 7,000,000
MTS - Engineering (Security)
MTS - Engineering (Security)

Collinear AI, Inc. • Bengaluru

On-site
INR 3,500,000 - 5,000,000