
Security Engineer 2
Jupiter Money4 months ago
Bengaluru, IndiaMid Level
Responsibilities
- Design and implement security automation frameworks for threat detection, remediation, and compliance validation across cloud and application layers.
- Develop tools and scripts to improve security visibility across AI model pipelines, APIs, and data integrations.
- Integrate SAST, DAST, SCA, and IaC scanning controls into CI/CD workflows.
- Lead periodic vulnerability assessment and penetration testing for web applications, mobile applications, agentic AI platforms, and connected services.
- Secure AWS and OCI multi-cloud environments using native and third-party tooling.
- Build and maintain IaC security baselines with automated configuration drift detection.
- Configure and manage WAF rules for DDoS mitigation and bot protection.
- Enforce secrets management, IAM policies, and container security practices across production workloads.
- Collaborate with engineering teams to remediate vulnerabilities and enforce secure SDLC practices.
- Conduct internal security training and phishing simulations.
- Apply AI model security and data privacy principles to protect sensitive data flows.
- Contribute to ISO 27001, SOC 2, DPDPA, and PCI DSS control implementation and maintenance.
Requirements
- At least 3 years of experience in product security or a related field.
- Hands-on experience with security assessments, threat modeling, code reviews, and penetration testing.
- Strong understanding of secure coding practices and secure SDLC principles.
- Proficiency in scripting languages such as Python, Bash, or similar.
- Working knowledge of OWASP, static and dynamic analysis tools, and security frameworks including CWE and CVSS.
- Strong communication, collaboration, analytical, problem-solving, project management, and prioritization skills.
- Experience with AWS or OCI infrastructure security is preferred.
- Hands-on experience securing personally identifiable information and sensitive content is preferred.
- Understanding of RBI, NPCI, SOC 2, DPDPA, and ISO 27001 compliance frameworks is preferred.
- Fintech or startup experience and knowledge of red teaming methodologies are nice to have.
- Certifications such as OSCP, AWS Security Specialty, GCP Security Specialty, CEH, CISSP, or CKS are nice to have.
- Exposure to multi-cloud environments including GCP and OCI is nice to have.
Benefits
- Ownership-oriented culture with responsibility for seeing projects through to completion.
- Meaningful customer-focused security and financial technology problems.
- Healthy debate and a culture that values consent, ownership, and commitment.
- Continuous learning and professional growth opportunities.