Staff Security Engineer

Ethos

Bengaluru

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading insurance technology company in Bengaluru is seeking a Staff Security Engineer. The role involves leading application security, penetration testing, and offensive security practices. Candidates should have over 8 years of experience in the field and strong proficiency in security tools and coding principles. This full-time position offers significant influence over the company’s security posture and collaboration across teams to build robust defenses.

Qualifications

  • 8+ years of experience in security engineering, penetration testing, or offensive security.
  • Strong understanding of secure coding principles and web security vulnerabilities.
  • Proficiency in threat modeling, design reviews, and security testing.

Responsibilities

  • Perform code reviews, threat modeling, and architecture assessments.
  • Conduct manual and automated penetration tests.
  • Plan and execute red team operations, simulating APT scenarios.

Skills

Application security
Penetration testing
Offensive security practices
Secure coding principles
AWS cloud platform
Burp Suite

Tools

Burp Suite
Metasploit
Nmap
Cobalt Strike

Job description

We're looking for a Staff Security Engineer with deep technical expertise in application security, penetration testing, and offensive security practices. You will lead efforts to proactively identify and exploit vulnerabilities across our products and infrastructure, working alongside engineering and security teams to design robust defences and build security into everything we deploy.

This is a hands-on technical role with significant influence over the security posture of the company, from code to cloud.

Duties and Responsibilities:

Application Security

  • Perform code reviews, threat modelling, and architecture assessments across internal and customer-facing applications.
  • Guide engineering teams on secure design patterns, libraries, and development practices.
  • Integrate and maintain security tooling (SAST, DAST, SCA) into CI/CD pipelines.
  • Collaborate with product and engineering teams to remediate identified vulnerabilities and design secure solutions.

Penetration Testing

  • Conduct manual and automated penetration tests against Ethos Web Application, APIs, infrastructure, and cloud environments.
  • Simulate attacker behaviors to assess technical weaknesses and business risks.
  • Create detailed, developer-friendly reports with risk ratings and actionable remediation guidance.
  • Re-test findings and validate security fixes in collaboration with product owners.

Offensive Security

  • Plan and execute red team operations, simulating advanced persistent threat (APT) scenarios.
  • Develop custom tools, scripts, and exploits to test detection and response capabilities.
  • Collaborate to improve detection, logging, and incident response based on attack insights.
  • Contribute to the development of offensive security playbooks and adversary emulation plans.

Other Responsibilities

  • Mentor junior team members and evangelize security best practices across the company.
  • Participate in investigations, threat hunting, and incident response activities; build playbooks for specific incident response scenarios
  • Communicate risks to engineering staff through training and technical demonstration of vulnerabilities and secure design patterns
  • Support security audits, compliance efforts, and executive briefings with technical depth.

Qualifications and Skills:

Required:

  • 8+ years of experience in security engineering, penetration testing, or offensive security.
  • Strong understanding of secure coding principles, web security vulnerabilities (e.g., OWASP Top 10), and remediation techniques.
  • Proficiency in threat modeling, design reviews and security testing of various types of applications, technologies and platforms
  • Skilled in using tools such as Burp Suite, Metasploit, Nmap, Cobalt Strike, or custom tooling.
  • Experience with AWS cloud platform and containerized environments (Docker, Kubernetes).
  • Strong written and verbal communication skills for technical and non-technical audiences.

Preferred:

  • Certifications like OSCP, OSWE, OSEP, GXPN, or equivalent.
  • Experience with threat modeling methodologies (e.g., STRIDE, PASTA).
  • Familiarity with MITRE ATT&CK, adversary emulation, and purple teaming.
  • Contributions to security research, open-source tools, or bug bounty platforms.
Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Industries
    Insurance

Referrals increase your chances of interviewing at Ethos by 2x

Sign in to set job alerts for “Security Engineer” roles.
Senior Security Analyst, Cloud Threat Detection
Walkin Drive Security Engineer (AI) at Bangalore on 12th August 25
IT Security Operations – Firewall (Senior engineer)
Senior Engineer , IT Security Operations – Firewall
Distinguished Engineer, Security Operations

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Monitoring Security Engineer
Threat Monitoring Security Engineer

HireFlex • India

On-site
INR 1,200,000 - 2,000,000
AWS Cloud Security Engineer
AWS Cloud Security Engineer

Globex Digital • India

On-site
INR 800,000 - 1,200,000
Senior Application Security Specialist
Senior Application Security Specialist

[24]7.ai • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Senior Network Security Engineer
Senior Network Security Engineer

Objectways • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Senior Security Analyst (Offensive)
Senior Security Analyst (Offensive)

CloudSEK • Bengaluru

On-site
INR 600,000 - 1,000,000
Unlimited snacks and drinks
Senior Security Engineer
Senior Security Engineer

Cynosure Corporate Solutions • Chennai

On-site
INR 1,500,000 - 2,000,000
Senior Security Engineer- 2
Senior Security Engineer- 2

AstroFarm by 42Gears • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Penetration Tester
Penetration Tester

ISA • Pune City

On-site
INR 1,200,000 - 2,000,000
Security Operations Engineer
Security Operations Engineer

NextGenEnergyJobs • Bengaluru

On-site
INR 2,500,000 - 5,200,000
Flexible time off
Wellness resources
Team events
Endpoint Security Analyst
Endpoint Security Analyst

Cubical Operations • Gurugram District

On-site
INR 800,000 - 1,200,000