Senior Application Security Engineer

Angel One

Mumbai

On-site

INR 2,800,000 - 5,200,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Angel One is seeking an experienced Senior Security Engineer – Security Assurance to strengthen its offensive security capabilities across cloud, applications, infrastructure, APIs, Kubernetes, and enterprise environments.

This hands-on role focuses on VAPT, cloud exploitation, adversary emulation, and security validation, with emphasis on AWS/GCP/Azure and modern cloud-native architectures. You will drive real-world risk reduction through remediation guidance.

Qualifications

  • Bachelor's degree in Computer Science, Engineering, Information Security, or a related discipline.
  • OSCP/OSWE/OSEP/CRTO/PNPT/CARTP/CARTE or cloud security certifications are preferred.
  • Minimum 4 years focused on penetration testing and offensive security.
  • Experience with cloud-native applications and infrastructure.
  • Strong understanding of modern cloud-native architectures, containers, and CI/CD pipelines.
  • Ability to demonstrate exploitability beyond automated scanners.
  • Experience in financial services, fintech, or regulated environments is preferred.

Responsibilities

  • Plan and execute end-to-end VAPT engagements across Angel One's tech stack.
  • Test web apps, APIs, internal/external infrastructure, cloud, containers, and Kubernetes.
  • Perform both automated and manual testing to identify vulnerabilities and exploitability.
  • Conduct offensive security assessments across AWS, Azure, and GCP environments.
  • Identify cloud weaknesses: misconfigurations, over-permissive roles, serverless risks, metadata abuse.
  • Validate business impact of findings and provide remediation guidance to engineers.
  • Conduct adversary simulations and map findings to MITRE ATT&CK to strengthen detections.

Skills

Manual Penetration Testing
Cloud Exploitation
Web & API Security
Container & Kubernetes Security
Exploitability Validation
Authentication & Authorization
Attack-path Analysis
OWASP Top 10
Scripting (Python/Bash/PowerShell)

Education

Bachelor's degree in Computer Science/Engineering/Info Security

Tools

Python
Bash
PowerShell

Job description

Angel One is one of India’s fastest growing fin-techs, on a bold mission to make investing simple, smart, and inclusive for every Indian. With over 3+ crore clients, we’re building at scale – and building for impact.

Our Super App helps clients manage their investments, trade seamlessly, and access financial tools tailored to their goals. We are working to build personalized financial journeys for our clients, powered by new-age tech, AI, Machine Learning and Data Science.

We’re a builder's company at heart. You’ll have the space to experiment, the freedom to move with velocity, and the mandate to make bold, user-first decisions – every single day.

The vibe? Think less hierarchy, more momentum. Everyone has a seat at the table and a shot to build something that lasts.

Be part of a team that’s scaling sustainably, thinking big, and building for the next billion.

Why You'll Love Working at Angel One!

  • Tech Systems that run at Scale: From AI to real-time data infra, you’ll work on tech that’s ahead of the curve and solve problems that truly matter.
  • Build one of India’s Leading Fintech Platform: We’re not just disrupting finance – we’re shaping how billion Indians access wealth.
  • Own It. Drive It. Scale It: You’ll have the freedom to lead, the resources to build, and the opportunity to leave your mark.
  • Empowered Growth: We invest in your growth and empower you to explore your full potential.
  • Exceptional Benefits: Our comprehensive benefits package includes health insurance, wellness programs, learning & development opportunities, and more.

Lead Security Engineer – Security Assurance (Cloud & Offensive Security)

Department: Information Security – Security Assurance

Reports To: Security Manager / Senior Director – Security Assurance

About the Role

Angel One is looking for an experienced Senior Security Engineer – Security Assurance to strengthen its offensive security capabilities across cloud, applications, infrastructure, APIs, Kubernetes, and enterprise environments.

This is a highly technical, hands-on role focused on Vulnerability Assessment and Penetration Testing (VAPT), cloud exploitation, adversary emulation, and security validation. The successful candidate will go beyond identifying vulnerabilities—they will demonstrate exploitability, assess business impact, and provide actionable remediation guidance to engineering teams.

The ideal candidate should have deep expertise in offensive security techniques across AWS, GCP, or Azure, with a strong understanding of modern cloud-native architectures, containerized workloads, identity systems, and CI/CD pipelines. They should be capable of conducting manual penetration testing, chaining vulnerabilities, and simulating realistic attack scenarios.

Key Responsibilities

1. Vulnerability Assessment & Penetration Testing (Primary Responsibility)

Plan and execute end-to-end VAPT engagements across Angel One's technology landscape, including:

  • Web applications
  • APIs (REST, GraphQL, gRPC)
  • Internal and external infrastructure
  • Cloud environments
  • Containers and Kubernetes
  • Perform both automated and manual testing to identify vulnerabilities, validate findings, and assess real-world exploitability.

2. Cloud Offensive Security (Primary Responsibility)

Conduct offensive security assessments across AWS, Azure, and GCP environments.

Identify and exploit cloud-specific weaknesses, including:

  • Misconfigured storage services
  • Over-permissive roles and policies
  • Serverless function vulnerabilities
  • Metadata service abuse
  • Cross-account trust issues
  • Publicly exposed cloud services
  • Identity federation weaknesses
  • Validate the business impact of cloud misconfigurations through controlled exploitation.

Perform advanced manual testing to identify vulnerabilities not detected by automated tools, including:

  • Authentication and authorization flaws
  • Business logic vulnerabilities
  • Chained attack paths
  • Insecure object references
  • API abuse
  • SSRF
  • RCE
  • XXE
  • Deserialization attacks
  • OAuth/OIDC implementation issues
  • JWT weaknesses
  • Demonstrate proof-of-concept exploits while adhering to established safety and change-management procedures.

4. Adversary Simulation & Exploitation

Conduct controlled adversary simulations to evaluate the effectiveness of preventive and detective controls.

Execute:

  • Lateral movement
  • Cloud identity attacks
  • Attack chain simulations
  • Map findings to the MITRE ATT&CK framework and provide recommendations to strengthen detection and response capabilities.

5. Container & Kubernetes Security Testing

Assess the security of containerized environments by evaluating:

  • RBAC configurations
  • Secrets management
  • Image security
  • Pod Security Standards
  • Container runtime configurations
  • Service account permissions
  • Validate container escape and privilege escalation scenarios in authorized environments

6. Application Security Assessments

Perform in-depth security assessments of applications throughout the SDLC, including:

  • Source-assisted testing (when applicable)
  • API testing
  • Authorization controls
  • Session management
  • Encryption implementations
  • Secure coding practices
  • Collaborate with developers to explain findings and recommend secure remediation strategies.

7. Vulnerability Validation

Review findings from SAST, DAST, SCA, cloud security tools, and infrastructure scanners.

Validate:

  • Business impact
  • SeverityReduce false positives and ensure consistent risk ratings

Required Technical Skills

Mandatory

  • Strong expertise in manual penetration testing
  • Hands-on experience with cloud exploitation (AWS, Azure, and/or GCP)
  • Deep understanding of web application and API security
  • Experience with container and Kubernetes security testing
  • Ability to validate exploitability beyond automated scanner findings
  • Strong knowledge of authentication and authorization mechanisms
  • Familiarity with attack-path analysis and offensive security methodologies
  • Experience testing for: OWASP Top 10, OWASP API Security Top 10
  • Experience with scripting in Python, Bash, or PowerShell to automate assessments is highly desirable.

Experience

  • 7–10 years of experience in Information Security
  • Minimum 4 years focused on penetration testing and offensive security
  • Experience testing cloud-native applications and infrastructure
  • Experience conducting manual exploitation beyond automated scanning
  • Experience working with cloud engineering and DevSecOps teams
  • Experience in financial services, fintech, or regulated environments is preferred

Qualifications

Bachelor's degree in Computer Science, Engineering, Information Security, or a related discipline.

Preferred certifications:

  • OSCP (Highly Preferred)
  • OSWE
  • OSEP
  • CRTO
  • PNPT
  • CARTP / CARTE
  • AWS Certified Security – Specialty
  • Google Professional Cloud Security Engineer
  • Microsoft Certified: Azure Security Engineer Associate
  • eCPPT

What Makes an Ideal Candidate

The ideal candidate is a technically accomplished offensive security professional who enjoys understanding how complex systems can be compromised—and using that knowledge to make them more secure. They are comfortable exploiting vulnerabilities in cloud-native environments, validating business impact, and partnering with engineering teams to eliminate risk. Beyond running tools, they understand modern architectures, think like an attacker, and can adapt to evolving technologies while maintaining the rigor expected in a regulated financial services environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000
Senior Security Analyst (Offensive)
Senior Security Analyst (Offensive)

CloudSEK • Bengaluru

On-site
INR 600,000 - 1,000,000
Unlimited snacks and drinks
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Security Engineer (Onsite - Hyderabad)
Security Engineer (Onsite - Hyderabad)

Uplers • Hyderabad

On-site
INR 900,000 - 2,000,000
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Staff Engineer, Security Architecture
Staff Engineer, Security Architecture

Automation Anywhere • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Security Architect
Security Architect

ValueLabs • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000