Key member of the Security team, this role focuses on securing applications, platform and AI systems. The role includes hands-on security testing, secure development practices, and security architecture and ownership of security outcomes.
Essential Duties and Responsibilities
- Perform VAPT across web, mobile, and API’s.
- Identify, assess, and help remediate vulnerabilities across the SDLC
- Partner with engineering teams to embed secure-by-design and secure-by-default practices
- Support responsible disclosure and/or bug bounty programs
- Contribute to vulnerability management, risk tracking, and remediation validation
- Use automation and tooling to improve the efficiency and scale of security controls
- Integrate security into CI/CD pipelines (SAST, SCA, secrets scanning, container/image scanning)
- Evaluate, onboard, and operate security tooling, including emerging AI-powered solutions
- Partner with product and engineering teams to design mitigations and guardrails
- Provide security architecture guidance for new platforms and features
- Execute or guide Breach & Attack Simulations (BAS) to validate detection and response
- Build automation and AI assisted workflows that measurably improve security outcomes
Qualifications Expected for Position
- Strong experience in Application Security and vulnerability assessment
- Hands-on expertise with web, mobile and API security testing, including OWASP Top 10
- Proven experience supporting vulnerability remediation with engineering teams
- Solid understanding of:
- Secure SDLC
- Secure coding and design patterns
- Hands-on experience with SAST, SCA, secrets management, and container scanning tools
- Familiarity with common security tools such as Burp Suite, Wiz, Nuclei, or equivalent
- Familiarity with deploying and managing RASP tools or eBPF kernel controls
- Practical experience using LLMs in security workflows, including:
- AI-assisted testing or analysis
- Coding agents
- Exposure to AI/ML security concepts
- Experience with BAS tools or attack simulation frameworks
- Scripting experience in Python, Go, or similar languages
- Familiarity with Infrastructure as Code (Terraform or equivalent)