Get more replies from employers
Send a job-specific resume in minutes.
Angel One is seeking an experienced Senior Security Engineer – Security Assurance to strengthen its offensive security capabilities across cloud, applications, infrastructure, APIs, Kubernetes, and enterprise environments.
This hands-on role focuses on VAPT, cloud exploitation, adversary emulation, and security validation, with emphasis on AWS/GCP/Azure and modern cloud-native architectures. You will drive real-world risk reduction through remediation guidance.
Angel One is one of India’s fastest growing fin-techs, on a bold mission to make investing simple, smart, and inclusive for every Indian. With over 3+ crore clients, we’re building at scale – and building for impact.
Our Super App helps clients manage their investments, trade seamlessly, and access financial tools tailored to their goals. We are working to build personalized financial journeys for our clients, powered by new-age tech, AI, Machine Learning and Data Science.
We’re a builder's company at heart. You’ll have the space to experiment, the freedom to move with velocity, and the mandate to make bold, user-first decisions – every single day.
The vibe? Think less hierarchy, more momentum. Everyone has a seat at the table and a shot to build something that lasts.
Be part of a team that’s scaling sustainably, thinking big, and building for the next billion.
Why You'll Love Working at Angel One!
Lead Security Engineer – Security Assurance (Cloud & Offensive Security)
Department: Information Security – Security Assurance
Reports To: Security Manager / Senior Director – Security Assurance
About the Role
Angel One is looking for an experienced Senior Security Engineer – Security Assurance to strengthen its offensive security capabilities across cloud, applications, infrastructure, APIs, Kubernetes, and enterprise environments.
This is a highly technical, hands-on role focused on Vulnerability Assessment and Penetration Testing (VAPT), cloud exploitation, adversary emulation, and security validation. The successful candidate will go beyond identifying vulnerabilities—they will demonstrate exploitability, assess business impact, and provide actionable remediation guidance to engineering teams.
The ideal candidate should have deep expertise in offensive security techniques across AWS, GCP, or Azure, with a strong understanding of modern cloud-native architectures, containerized workloads, identity systems, and CI/CD pipelines. They should be capable of conducting manual penetration testing, chaining vulnerabilities, and simulating realistic attack scenarios.
Key Responsibilities
1. Vulnerability Assessment & Penetration Testing (Primary Responsibility)
Plan and execute end-to-end VAPT engagements across Angel One's technology landscape, including:
2. Cloud Offensive Security (Primary Responsibility)
Conduct offensive security assessments across AWS, Azure, and GCP environments.
Identify and exploit cloud-specific weaknesses, including:
Perform advanced manual testing to identify vulnerabilities not detected by automated tools, including:
4. Adversary Simulation & Exploitation
Conduct controlled adversary simulations to evaluate the effectiveness of preventive and detective controls.
Execute:
5. Container & Kubernetes Security Testing
Assess the security of containerized environments by evaluating:
6. Application Security Assessments
Perform in-depth security assessments of applications throughout the SDLC, including:
7. Vulnerability Validation
Review findings from SAST, DAST, SCA, cloud security tools, and infrastructure scanners.
Validate:
Required Technical Skills
Mandatory
Experience
Qualifications
Bachelor's degree in Computer Science, Engineering, Information Security, or a related discipline.
Preferred certifications:
What Makes an Ideal Candidate
The ideal candidate is a technically accomplished offensive security professional who enjoys understanding how complex systems can be compromised—and using that knowledge to make them more secure. They are comfortable exploiting vulnerabilities in cloud-native environments, validating business impact, and partnering with engineering teams to eliminate risk. Beyond running tools, they understand modern architectures, think like an attacker, and can adapt to evolving technologies while maintaining the rigor expected in a regulated financial services environment.