Security Engineer

KGEN

Bengaluru

On-site

INR 1,200,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KGeN is seeking a security professional to run recurring security audits across applications, cloud, and infrastructure. This hands‑on role requires finding real risk, explaining it clearly to engineers, and ensuring fixes are implemented.

You will shape how reviews are performed as we scale. In your first months, establish a repeatable review cadence and build a prioritized view of vulnerabilities to drive remediation.

Qualifications

  • 3–7 years in security engineering or application security.
  • Strong web and application security fundamentals (OWASP Top 10 in practice).
  • Real cloud security depth in AWS and Cloudflare; comfortable across both.
  • Hands‑on experience with SAST/DAST/VAPT tooling and manual testing.
  • Ability to threat model and reason about attacker behavior.
  • Scripting ability (Python or similar) to automate tooling.
  • Clear communication of risk to engineers and drive fixes.

Responsibilities

  • Run application and architecture security reviews across products.
  • Perform code and configuration reviews, penetration tests, and provide actionable feedback.
  • Review cloud security posture across AWS and Cloudflare — IAM, network, data controls.
  • Coordinate VAPT activities and triage findings with external testers.
  • Promote secure‑SDLC practices and embed security into development.
  • Own vulnerability management and drive remediation to closure.
  • Threat‑model new and existing systems to identify weaknesses.
  • Support incident response when needed.

Skills

Security engineering
Application security
Cloud security
Threat modeling
VAPT testing
SAST/DAST tooling
Python scripting
Risk communication
Incident response support

Tools

SAST tooling
DAST tooling
VAPT tooling
Penetration testing
Cloud security tools

Job description

About KGeN

KGeN is building the Verified Distribution Protocol (VeriFi) for AI, DeFi, and Gaming - built on real users and real commerce to accelerate growth for projects across these industries.

Since its founding by global leaders in the consumer and gaming sectors, KGeN has grown to become the dominant growth engine in the Global South. With 45.7 million users, 6.7 million monthly active users, and $64 million in annualized revenue, KGeN delivers verified user acquisition, on-chain loyalty programs, and decentralized storefronts via its POGE, the identity and reputation framework and a global clan network spanning more than 60 countries.

The role

You’ll partner with the Head of Security to run our recurring security audits and reviews — across applications, cloud, and infrastructure. This is a hands‑on technical role: you find real risk, explain it clearly to the engineers who can fix it, and make sure it actually gets fixed. You’ll have the room to shape how security reviews work here as we scale.

In your first few months
  • Get up to speed on our application and cloud architecture and run your first end‑to‑end security review, from findings to tracked remediation.
  • Establish a repeatable cadence for security and architecture reviews rather than one‑off checks.
  • Build a clear, prioritized view of our current vulnerabilities and drive down the ones that matter most.
What you’ll do
  • Run application and architecture security reviews across our products.
  • Perform code and configuration reviews, penetration tests, and give engineering teams concrete, actionable feedback.
  • Review our cloud security posture across AWS and Cloudflare — configuration, identity, network, and data controls.
  • Run and coordinate VAPT — hands‑on testing where it counts, managing external pentests where it makes sense, and triaging findings.
  • Guide secure‑SDLC practices — help teams build security in, not bolt it on.
  • Own vulnerability management: track, prioritize, and drive remediation to closure.
  • Threat‑model new and existing systems to find weaknesses before attackers do.
  • Support incident response when something needs investigating.
What you bring
  • 3–7 years in security engineering or application security. (We’re open on level — strong mid‑career and senior candidates are both welcome.)
  • Strong web and application security fundamentals (you know the OWASP Top 10 in practice, not just by name).
  • Real cloud security depth in AWS and Cloudflare — deep in at least one, comfortable across both.
  • Hands‑on experience with SAST/DAST/VAPT tooling and manual testing — you don’t rely on scanners alone.
  • Comfort with threat modeling and reasoning about attacker behavior.
  • Scripting ability (Python or similar) to automate and build your own tooling.
  • The ability to explain risk clearly to engineers and get fixes shipped — influence without authority.
Bonus points
  • Relevant certifications (OSCP, GWAPT, CCSP, or similar).
  • Bug bounty, CTF, or independent security research experience.
  • DevSecOps / secure‑SDLC automation experience.
  • Container and Kubernetes security.
Why join

You’ll work directly with the Head of Security on real, high‑impact security work with the autonomy to shape how we do reviews as we grow. If you like finding the risk that matters and actually seeing it fixed — not writing reports that gather dust — this is that role.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Security Architect
Security Architect

ValueLabs • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Lead DevSecOps Engineer
Lead DevSecOps Engineer

GoKwik Commerce Solutions Pvt Ltd • Bengaluru

On-site
INR 7,575,000 - 11,364,000
Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Cyber Security Engineer
Cyber Security Engineer

Kapture CX • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Security Engineer II
Security Engineer II

Safe Security • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Unlimited vacation policy
High-trust work environment
Commitment to continuous learning
InfoSec - Application & Cloud Security Engineer (L2)
InfoSec - Application & Cloud Security Engineer (L2)

OpenFX • Bengaluru

On-site
INR 1,200,000 - 2,100,000
Equity in a rapidly growing company
Growth path to L3 specialist
Hybrid work model
DevSecOps Engineer
DevSecOps Engineer

SourcingXPress • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Head of Security Engineering
Head of Security Engineering

Brevan Howard • Bengaluru Urban

On-site
INR 1,800,000 - 2,500,000