Senior Cybersecurity Engineer

Aspire

Bengaluru

On-site

INR 3,800,000 - 6,600,000

Full time

43 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Aspire is seeking an experienced security leader to own and drive application, cloud, and DevSecOps security across our Bengaluru platform. You will build end-to-end security testing, manage disclosure processes, and integrate SAST/SCA into CI/CD with automation to prevent data leaks.

You will secure AWS environments, orchestrate CSPM and WAF usage, and perform internal tests while coordinating external pen tests. Strong collaboration with product and engineering is essential.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
  • 6+ years of hands-on experience in Application Security, Product Security, or Cloud Security.
  • Strong knowledge of web application vulnerabilities (OWASP Top 10, SANS 25) and remediation techniques.

Responsibilities

  • Build and maintain end-to-end security testing processes and manage Responsible Disclosure Policy.
  • Integrate SAST, SCA, and Secret Detection into CI/CD pipelines (GitHub) and develop automation to prevent data leaks.
  • Manage CSPM tools (Orca) and WAF (Cloudflare); conduct AWS security reviews and internal network testing.
  • Identify and remediate vulnerabilities (including LLM-specific risks) and patch dependencies.
  • Create security dashboards to track KPIs, automate PII detection in logs, and support ISO/SOC2 audits with evidence.
  • Coordinate external penetration testing engagements with third-party vendors and track remediation.

Skills

Application Security
Cloud Security
DevSecOps
Container Security
Scripting
Cross-functional collaboration
Threat modelling

Education

Bachelor's degree in CS/InfoSec

Tools

GitHub Advanced Security
SAST
SCA
AWS IAM
Orca CSPM
Cloudflare WAF
Docker
Kubernetes

Job description

About The Company

Founders today are building global companies from day one — but the systems that manage their money were built for a different era. Aspire exists to change that! We’re building the financial operating system for global founders, bringing banking, software, and automation into a single platform so businesses can move faster across borders and stay focused on building. Aspire is built by people who think from first principles, care deeply about solving hard problems, and take real ownership of their work. Our team brings global experience from leading fintech and technology companies, and many of us are former founders and operators who understand what it takes to build thoughtfully, make trade‑offs, and deliver at scale in a global environment. Backed by leading global investors including Y Combinator, Peak XV, and Lightspeed, Aspire has been trusted by more than 50,000 startups and growing businesses worldwide to manage their finances since 2018. Together with partners like J.P. Morgan, Visa, and Wise, we’re building for the next generation of global companies.

About The Team

At Aspire, we recognize that data and infrastructure security are paramount to the success and trust of our customers. Our Security Team is at the forefront of protecting and securing our systems, ensuring compliance with industry best practices, and continuously learning and evolving to stay ahead of emerging threats. Our emphasis extends to data privacy, seamlessly integrating it into our security initiatives.

About The Role

Key Responsibilities:

  • AppSec Program Management: Build and maintain end-to-end security testing processes, managing the Responsible Disclosure Policy and coordinating remediation with engineering teams.
  • DevSecOps Implementation: Integrate SAST, SCA, and Secret Detection into the CI/CD pipeline (GitHub) and develop custom automation to prevent data leaks.
  • Cloud & Infrastructure Security: Manage CSPM tools (Orca) and WAF (Cloudflare), conduct AWS infrastructure reviews, and perform internal network penetration tests.
  • Vulnerability Management: Identify and resolve critical vulnerabilities (including LLM-specific risks) and patch Docker/application dependencies.
  • Monitoring & Compliance: Build security dashboards to track KPIs, automate PII detection in logs, and support ISO/SOC2 audits with technical evidence.
  • External Penetration Testing: Scope, manage, and coordinate external penetration testing engagements with third‑party vendors, communicating findings and tracking remediation to closure.
Minimum Qualifications
  • Education & Experience: Bachelor’s degree in Computer Science, Information Security, or equivalent practical experience. 6+ years of hands‑on experience in Application Security, Product Security, or Cloud Security.
  • Web Application Security: Deep understanding of web application vulnerabilities (OWASP Top 10, SANS 25) with the ability to identify, exploit, and remediate issues like SQL Injection, XSS, IDOR, and Access Control flaws.
  • Cloud Security (AWS): Strong experience securing AWS environments. Proficiency with IAM, Security Groups, NACLs, and conducting infrastructure security reviews.
  • DevSecOps & Automation: Experience implementing security in the CI/CD pipeline (e.g., GitHub Advanced Security, SAST, SCA). Proficiency in scripting (Python, Bash, or Go) to build custom security tools, log monitoring automations, or pre‑commit hooks.
  • Container Security: Hands‑on experience with Docker/Kubernetes security, including identifying and patching vulnerabilities in container images and dependencies.
  • Tooling: Experience managing security tools such as CSPM (e.g., Wiz), WAF (e.g., Cloudflare), and vulnerability scanners.
  • Collaboration: Proven ability to work cross‑functionally with Product Managers, DevOps, and Engineering teams to prioritize and drive security remediation without blocking releases.
Preferred Qualifications
  • LLM & GenAI Security: Experience threat modeling for Generative AI workflows (LLM Injection, Prompt Engineering attacks) and securing AI/ML integrations.
  • Advanced Cloud Networking: Experience configuring WAF rules, rate limiting, and bot protection (specifically Cloudflare) to mitigate DDoS and abuse.
  • Compliance & GRC: Familiarity with compliance frameworks such as ISO 27001, SOC2, or PCI-DSS, and experience collecting technical evidence for audits.
  • Program Management: Experience running a Bug Bounty or Responsible Disclosure program and coordinating with external researchers.
  • Certifications: Industry‑recognized certifications such as OSCP, OSWE, CISSP, or AWS Certified Security – Specialty.
  • Threat Modeling: Experience conducting threat modeling sessions for complex features and architectural reviews.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security
Information Security

Aspora • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Manager — Information Security and Compliance
Manager — Information Security and Compliance

APEX Analytix • India

On-site
USD 120,000 - 150,000
Security Engineering Manager
Security Engineering Manager

Smartstream • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Security Engineering Manager
Security Engineering Manager

SmartStream • India

On-site
INR 4,000,000 - 6,000,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Security Engineering Manager
Security Engineering Manager

Smartstream Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Security & Compliance Engineer Intern
Security & Compliance Engineer Intern

AI Prof • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Senior Information Security Engineer
Senior Information Security Engineer

Aspora • Bengaluru

On-site
INR 3,500,000 - 7,500,000
InfoSec - Application & Cloud Security Engineer (L2)
InfoSec - Application & Cloud Security Engineer (L2)

OpenFX • Bengaluru

On-site
INR 1,200,000 - 2,100,000
Equity in a rapidly growing company
Growth path to L3 specialist
Hybrid work model
FinCrime Manager
FinCrime Manager

Aspire • Gurugram District

On-site
INR 2,500,000 - 4,500,000