Security Engineer

Recro

Bengaluru

On-site

INR 1,800,000 - 2,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading security firm in India is looking for a skilled professional with 3 to 6 years of experience in Vulnerability Assessment and Penetration Testing (VAPT). The candidate will be responsible for security reviews, threat modeling, and integrating security practices into DevSecOps pipelines. Strong knowledge of cloud security models and familiarity with tools like Burp Suite and OWASP ZAP are essential. This role offers a challenging yet rewarding career path in cybersecurity.

Qualifications

  • 3 to 6 years of solid hands-on experience in the VAPT domain.
  • Strong knowledge of cloud platforms and their security models.
  • Familiarity with bug bounty programs and responsible disclosure practices.
  • Strong knowledge of cloud platforms (AWS/GCP/Azure) and their security models.
  • Familiarity with bug bounty programs and responsible disclosure practices.
  • Familiarity with tools like Burp Suite, MobSF, OWASP ZAP, Terraform, Checkov.
  • Good knowledge of API security.
  • Scripting experience (Python, Bash, or similar) for automation tasks.

Responsibilities

  • Perform Security reviews and Vulnerability Assessments for applications.
  • Integrate security tools into CI/CD pipelines.
  • Conduct secure code reviews and identify OWASP Top 10 vulnerabilities.
  • Conduct secure code reviews and red team assessments.
  • Integrate SAST, DAST, SCA, and secret scanning tools into CI/CD pipelines.
  • Automate security checks using tools like SonarQube, Snyk, Trivy, etc.
  • Maintain and manage vulnerability scanning infrastructure.
  • Perform security assessments of AWS, Azure, and GCP environments, with an emphasis on container security, particularly for Docker and Kubernetes.
  • Implement guardrails for IAM, network segmentation, encryption, and cloud monitoring.
  • Contribute to infrastructure hardening for containers, Kubernetes, and virtual machines.
  • Triage bug bounty reports and coordinate remediation with engineering teams.
  • Act as the primary responder for external security disclosures.
  • Maintain documentation and metrics related to bug bounty and penetration testing activities.
  • Collaborate with developers and architects to ensure secure design decisions.
  • Lead security design reviews for new features and products.
  • Provide actionable risk assessments and mitigation plans to stakeholders.

Skills

Vulnerability Assessment
Web Application Security
DevSecOps
Cloud Security (AWS/GCP/Azure)
API Security
Scripting (Python, Bash)
MobSF
OWASP ZAP
Terraform
Checkov
API security
Scripting (Python/Bash)

Education

OSCP, CEH, AWS Security Specialty

Tools

Burp Suite
OWASP ZAP
SonarQube
Snyk
Terraform
Checkov

Job description

  • 3 to 6 years of solid hands‑on experience in the VAPT domain
  • Solid understanding of Web, Android, and iOS application security
  • Experience with DevSecOps tools and integrating security into CI/CD
  • Strong knowledge of cloud platforms (AWS/GCP/Azure) and their security models
  • Familiarity with bug bounty programs and responsible disclosure practices
  • Familiarity with tools like Burp Suite, MobSF, OWASP ZAP, Terraform, Checkov..etc
  • Good knowledge of API security
  • Scripting experience (Python, Bash, or similar) for automation tasks
Preferred Qualifications
  • OSCP, CEH, AWS Security Specialty, or similar certifications
  • Experience working in a regulated environment (e.g., FinTech, InsurTech)
Responsibilities
  • Perform Security reviews, Vulnerability Assessments & Penetration Testing for Web, Android, iOS, and API endpoints
  • Perform Threat Modelling & anticipate potential attack vectors and improve security architecture on complex or cross‑functional components
  • Identify and remediate OWASP Top 10 and mobile‑specific vulnerabilities
  • Conduct secure code reviews and red team assessments
  • Integrate SAST, DAST, SCA, and secret scanning tools into CI/CD pipelines
  • Automate security checks using tools like SonarQube, Snyk, Trivy, etc.
  • Maintain and manage vulnerability scanning infrastructure
  • Perform security assessments of AWS, Azure, and GCP environments, with an emphasis on container security, particularly for Docker and Kubernetes.
  • Implement guardrails for IAM, network segmentation, encryption, and cloud monitoring
  • Contribute to infrastructure hardening for containers, Kubernetes, and virtual machines
  • Triage bug bounty reports and coordinate remediation with engineering teams
  • Act as the primary responder for external security disclosures
  • Maintain documentation and metrics related to bug bounty and penetration testing activities
  • Collaborate with developers and architects to ensure secure design decisions
  • Lead security design reviews for new features and products
  • Provide actionable risk assessments and mitigation plans to stakeholders
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000
Cyber Security Specialist
Cyber Security Specialist

SuperOps • Chennai District

On-site
INR 800,000 - 1,200,000
Senior Security Engineer
Senior Security Engineer

Crossbow Cybersecurity • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Competitive salary and benefits
Medical Insurance – Self & family
Parental Support – Maternity Leave
+3
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

Hybrid
INR 900,000 - 1,500,000
Application Security Engineer - Red Team
Application Security Engineer - Red Team

Air India • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture