1 month ago
Bengaluru, IndiaMid Level
Responsibilities
- Perform manual and automated application code reviews and support secure SDLC tooling.
- Triage, reproduce, and drive remediation for findings from SAST, DAST, SCA, bug bounty, and internal reports.
- Support threat modeling for new services and features and partner with engineering teams on remediation.
- Review AWS IAM policies, enforce cloud guardrails, and help secure AWS accounts.
- Harden Kubernetes clusters, including admission control, RBAC, and secrets management.
- Tune AWS WAF and Cloudflare WAF rules, scan cloud infrastructure and containers, and drive remediation.
- Build security automation with Python, Go, or Bash and monitor GuardDuty, Security Hub, and Config findings.
- Contribute to security policies, standards, runbooks, incident playbooks, threat research, and the InfoSec on-call rotation.
Requirements
- 2–4 years of hands-on experience in Application Security, Cloud Security, or a closely related role.
- Hands-on experience in both AppSec and CloudSec, including at least one of SAST, DAST, or manual review and at least one major cloud platform.
- Knowledge of OWASP Top 10, TLS/PKI, OAuth/JWT, and common cloud attack patterns.
- Ability to write useful internal tools and scripts in Python, Go, or Bash.
- Clear communication skills for translating security findings into actionable engineering fixes.
- A degree or equivalent experience in Computer Science, Information Security, or a similar field.
- Preferred: production Kubernetes exposure, Terraform familiarity, bug bounty, CTF, open-source security contributions, or certifications such as AWS Security Specialty, OSCP, CKS, or CEH.
Benefits
- Competitive salary and benefits package.
- Equity in a rapidly growing company.
- Hybrid Application Security and Cloud Security responsibilities with a defined path toward L3 specialization.
- Collaborative, fast-paced fintech startup environment focused on professional growth.
