Senior Security Engineer

Nextwebi

Bengaluru

On-site

INR 1,500,000 - 2,100,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nextwebi is seeking a Senior Security Engineer to lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives in Bengaluru. You will drive end-to-end pentesting across web apps, APIs, and cloud, and develop red-team playbooks for AI features.

Role requires 4+ years in Security Engineering with hands-on pentesting, strong knowledge of OWASP Top 10, Python/Go/Bash scripting, and cloud security across AWS/GCP/Azure.

Qualifications

  • 4+ years in Security Engineering
  • 2+ years hands-on pentesting
  • Experience with web/app and API pentesting
  • Proficient in Python, Go, or Bash
  • Familiar with AWS, GCP, or Azure
  • Knowledge of OWASP Top 10
  • Experience with AI/LLM security

Responsibilities

  • Lead end-to-end penetration testing across apps, APIs, and cloud
  • Design red-team exercises simulating real attacks
  • Perform threat modelling for new features
  • Develop custom exploits and tools
  • Prepare actionable pentest reports
  • Manage third-party pentesting vendors
  • Research attacks against AI/LLM systems
  • Assess MCP deployments and tool-call boundaries
  • Build red-teaming playbooks for LLM features
  • Integrate security into AI development lifecycle
  • Audit CI/CD with SAST/DAST/SCA and secret scanning

Skills

Security testing
Penetration testing
Python/Go/Bash
Cloud security
AI/LLM security
Threat modelling

Job description

We are looking for a Senior Security Engineer to join our Security Team and lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives. This role sits at the intersection of traditional application security and emerging AI security threats.

Key Responsibilities
Penetration Testing & Offensive Security
  • Lead end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure.
  • Design and execute red-team exercises simulating real-world attacks.
  • Perform threat modelling for new product features and architectures.
  • Develop custom exploits, scripts, and security tools.
  • Prepare clear and actionable penetration testing reports.
  • Manage third-party penetration testing vendors and responsible disclosure programs.
AI & LLM Security
  • Research and execute attacks against AI/LLM-powered systems, including prompt injection, jailbreaks, and indirect prompt injection.
  • Assess risks related to data exfiltration through model responses.
  • Assess security risks in Model Context Protocol (MCP) deployments, including tool-call boundaries, context poisoning, and privilege escalation.
  • Build an internal threat library for AI attack patterns.
  • Develop and maintain red-teaming playbooks for LLM-based features.
  • Work with ML and Product teams to integrate security into the AI development lifecycle.
DevSecOps
  • Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secret scanning, and container scanning.
  • Define and enforce secure coding standards and security review gates.
  • Drive security automation across engineering teams.
Risk Assessment & Governance
  • Assess and prioritize security risks using frameworks such as CVSS, DREAD, or FAIR.
  • Maintain risk registers and track remediation progress.
  • Evaluate risks from third-party vendors, integrations, and open-source dependencies.
  • Support security audits, gap assessments, policies, standards, and exception processes.
  • Communicate security findings and business impact to technical and non-technical stakeholders.
Required Skills & Experience
  • 4+ years of experience in Security Engineering, with at least 2 years of hands-on penetration testing experience.
  • Strong experience in web application and API penetration testing.
  • Good knowledge of OWASP Top 10, business logic vulnerabilities, and authentication/authorization bypasses.
  • Hands-on experience with AI/LLM security, including prompt injection, model manipulation, or MCP security assessments.
  • Strong scripting skills in Python, Go, or Bash.
  • Experience with cloud security across AWS, GCP, or Azure.
  • Knowledge of cloud misconfigurations, IAM abuse, and lateral movement.
  • Experience integrating SAST/DAST/SCA tools into CI/CD pipelines.
  • Experience conducting risk assessments and communicating findings effectively.
Good to Have
  • Bug bounty experience or CVE publications.
  • Experience with agentic AI frameworks such as LangChain, AutoGPT, or Claude Agents.
  • Experience with red-team tools and security automation.
  • Security certifications such as OSCP, OSWE, OSEP, CEH, or equivalent.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Senior Security Engineer
Senior Security Engineer

Nextwebi IT solutions Pvt ltd • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Cornerstone • Mumbai, Pune District

On-site
INR 2,000,000 - 4,000,000
AI Security Engineer
AI Security Engineer

QualiZeal • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Security & Compliance Engineer Intern
Security & Compliance Engineer Intern

AI Prof • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Lead Security Specialist
Lead Security Specialist

Skillmine Technology • Mumbai

On-site
INR 4,000,000 - 7,000,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
CyberSecurity
CyberSecurity

Cloudxtreme • Hyderabad, Bengaluru

On-site
INR 170,000 - 210,000
Application Security Specialist (AppSec + AI Security)
Application Security Specialist (AppSec + AI Security)

Qualizeal India • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Sr Security Engineer I, Application Security
Sr Security Engineer I, Application Security

Flywire • Bengaluru

On-site
INR 3,500,000 - 5,500,000