Senior Security Engineer

Nextwebi IT solutions Pvt ltd

Bengaluru

On-site

INR 2,500,000 - 4,500,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nextwebi IT solutions Pvt ltd is seeking a Senior Security Engineer to lead offensive security, AI/LLM security, and DevSecOps. You will drive pen tests across web apps, APIs, cloud, and internal services, design red-team exercises, and develop security tooling.

The role requires 4+ years in security engineering, strong Python/Go/Bash skills, and experience with SAST/DAST/SCA tools. You will collaborate with ML teams to secure AI deployments and report findings to leadership.

Qualifications

  • 4+ years of security engineering with hands-on pentesting.
  • Strong knowledge of web apps, APIs and cloud security.
  • Proficient in Python, Go or Bash scripting.
  • Experience with SAST/DAST/SCA tools and secure DevOps.
  • Ability to communicate risks and remediation clearly.

Responsibilities

  • Lead end-to-end penetration testing across apps, APIs, internal services, and cloud.
  • Design and execute red-team exercises simulating real-world attacks.
  • Perform threat modelling for new features and architectures.
  • Develop exploits, scripts, and security tools; create reports.
  • Manage third-party pen tests and disclosure programs.
  • Research AI/LLM security and integrate secure lifecycle practices.
  • Integrate security controls into CI/CD with SAST/DAST/SCA.
  • Maintain risk registers and communicate findings to stakeholders.

Skills

Penetration testing
Web application security
Cloud security
Scripting (Python/Go/Bash)
Threat modelling
Security reporting

Tools

SAST/DAST/SCA tools
Red-team tools

Job description

We are looking for a Senior Security Engineer to join our Security Team and lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives. This role sits at the intersection of traditional application security and emerging AI security threats.

Location: Bangalore

Key Responsibilities
Penetration Testing Offensive Security
  • Lead end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure.
  • Design and execute red-team exercises simulating real-world attacks.
  • Perform threat modelling for new product features and architectures.
  • Develop custom exploits, scripts, and security tools.
  • Prepare clear and actionable penetration testing reports.
  • Manage third-party penetration testing vendors and responsible disclosure programs.
AI LLM Security
  • Research and execute attacks against AI/LLM-powered systems, including prompt injection, jailbreaks, and indirect prompt injection.
  • Assess risks related to data exfiltration through model responses.
  • Assess security risks in Model Context Protocol (MCP) deployments, including tool-call boundaries, context poisoning, and privilege escalation.
  • Build an internal threat library for AI attack patterns.
  • Develop and maintain red-teaming playbooks for LLM-based features.
  • Work with ML and Product teams to integrate security into the AI development lifecycle.
DevSecOps
  • Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secret scanning, and container scanning.
  • Define and enforce secure coding standards and security review gates.
  • Drive security automation across engineering teams.
Risk Assessment Governance
  • Assess and prioritize security risks using frameworks such as CVSS, DREAD, or FAIR.
  • Maintain risk registers and track remediation progress.
  • Evaluate risks from third-party vendors, integrations, and open-source dependencies.
  • Support security audits, gap assessments, policies, standards, and exception processes.
  • Communicate security findings and business impact to technical and non-technical stakeholders.
Requirements
  • 4+ years of experience in Security Engineering, with at least 2 years of hands-on penetration testing experience.
  • Strong experience in web application and API penetration testing.
  • Good knowledge of OWASP Top 10, business logic vulnerabilities, and authentication/authorization bypasses.
  • Hands-on experience with AI/LLM security, including prompt injection, model manipulation, or MCP security assessments.
  • Strong scripting skills in Python, Go, or Bash.
  • Experience with cloud security across AWS, GCP, or Azure.
  • Knowledge of cloud misconfigurations, IAM abuse, and lateral movement.
  • Experience integrating SAST/DAST/SCA tools into CI/CD pipelines.
  • Experience conducting risk assessments and communicating findings effectively.
Good to Have
  • Bug bounty experience or CVE publications.
  • Experience with agentic AI frameworks such as LangChain, AutoGPT, or Claude Agents.
  • Experience with red-team tools and security automation.
  • Security certifications such as OSCP, OSWE, OSEP, CEH, or equivalent.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Cornerstone • Mumbai, Pune District

On-site
INR 2,000,000 - 4,000,000
AI Security Engineer
AI Security Engineer

QualiZeal • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

Hybrid
INR 2,500,000 - 4,200,000
Penetration Tester ( F2F Interviews - Mumbai )
Penetration Tester ( F2F Interviews - Mumbai )

KPMG Assurance and Consulting Services LLP • Mumbai, Navi Mumbai

On-site
INR 1,200,000 - 1,800,000
VAPT consultant
VAPT consultant

Cyraac Services • Pune District

On-site
INR 700,000 - 1,100,000
SISA Information Security - Network Security Engineer
SISA Information Security - Network Security Engineer

SISA • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Director, Information Security
Director, Information Security

InvestCloud India • Bengaluru

On-site
INR 7,000,000 - 12,000,000
Cyber Security Engineer
Cyber Security Engineer

Worktual Innovations • Chennai District

On-site
INR 4,000,000 - 7,000,000