Leads enterprise security engineering across cloud, infrastructure, applications, APIs, and CI/CD environments. Designs security architecture, automation, DevSecOps controls, WAF protections, vulnerability management, and application security testing. Conducts penetration testing and red team exercises, supports incident response, partners with engineering teams, and mentors security practitioners.
Key Responsibilities
Security Engineering & Architecture
- Design, implement, and maintain enterprise security controls across cloud, infrastructure, and application environments.
- Evaluate emerging threats and technologies and recommend improvements to the organization's security architecture.
- Develop security standards, engineering patterns, and technical guidance to improve the overall security posture.
Security Automation & DevSecOps
- Design and develop security automation solutions that improve operational efficiency and reduce manual effort.
- Integrate security controls and validation activities into CI/CD pipelines and software delivery workflows.
- Build and maintain GitHub Actions and related automation to support secure development practices.
- Automate vulnerability management, policy enforcement, reporting, and remediation tracking activities.
Application Security
- Lead security engineering efforts focused on protecting internally developed applications and APIs.
- Perform and coordinate:
- Threat modeling
- Secure design and architecture reviews
- Secure code reviews
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Open-source dependency and supply chain security reviews
- Secret and credential exposure detection
- API security testing and assessments
- CI/CD pipeline security reviews
- Security validation of application deployments
- Partner with development teams to identify, prioritize, and remediate security risks.
Web Application Firewall (WAF) & Edge Security
- Design, implement, and maintain Web Application Firewall (WAF) capabilities.
- Develop and tune security rules, attack detection logic, bot mitigation, rate limiting, and application-layer protections.
- Continuously monitor and improve protections against OWASP Top 10 and emerging web application threats.
Offensive Security & Penetration Testing
- Conduct application red team exercises and adversarial security assessments.
- Perform manual and automated penetration testing of web applications, APIs, and supporting services.
- Simulate real-world attack techniques to identify weaknesses in application design, authentication, authorization, and deployment architectures.
- Document findings, provide remediation guidance, and validate corrective actions.
Collaboration & Security Operations Support
- Partner with engineering, infrastructure, and cloud teams to implement secure solutions.
- Support incident response investigations involving applications, cloud services, and development platforms.
- Provide technical leadership and mentorship on security engineering practices and security tool adoption.
Success Measures
- Increased automation and efficiency of security processes.
- Successful integration of security controls into engineering and CI/CD workflows.
- Reduction of application and cloud security risks.
- Effective implementation and management of WAF protections.
- Timely identification and remediation of vulnerabilities.
- Successful execution of penetration testing and red team activities.
- Improved security posture across applications, APIs, and software delivery platforms.
Similar Jobs
Financial Services
Owns delivery and continuous improvement of credit monitoring products within wholesale lending services. Partners with business and technology stakeholders to gather requirements, design solutions, manage the product backlog, coordinate user acceptance testing, support production incidents, and oversee change readiness, risk controls, and regulatory adherence. Develops automated regression testing, resolves operational issues, and drives process and product transformations across cross-functional teams.
Top Skills:
Agile MethodologyAlteryxJIRAExcelMicrosoft PowerpointMicrosoft VisioMicrosoft WordTableau
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Business Analyst supporting retail banking and digital transformation initiatives. Responsibilities include mapping customer onboarding and digital account servicing journeys, documenting business requirements, supporting end-to-end delivery, and collaborating with Product Owners, Technology, Operations, and global stakeholders. The role also involves Agile delivery, including creation of epics and user stories and backlog management using Jira and Confluence.
Top Skills:
ConfluenceJIRA
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Business Analyst supporting private banking and wealth management transformation programs. Responsibilities include gathering and prioritizing requirements, defining MVP scope, documenting use cases, communicating requirements to stakeholders, and supporting Agile delivery. The role requires expertise in capital markets and trade lifecycle, Avaloq or core banking, advisory, financial planning, insurance, digital customer journeys, stakeholder management, Jira, and Confluence.
Top Skills:
AvaloqConfluenceFigmaJIRA
What you need to know about the Mumbai Tech Scene
From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

