Description :
We are looking for a highly skilled Senior Security Engineer with strong expertise in Application Security, Product Security, Cloud Security (AWS), DevSecOps, and secure architecture reviews. The ideal candidate must have strong communication skills to collaborate effectively with Engineering, DevOps, Cloud, and Product teams to strengthen our security posture, run end-to-end security assessments, design scalable security controls, and drive automation across the SDLC.
This role demands hands-on technical depth, strong problem-solving skills, and the ability to independently lead security initiatives in a high-growth environment.
The ideal candidate must have strong communication skills
Key Responsibilities :
Application & Product Security :
- Conduct security assessments for web, mobile, and API applications including Penetration Testing, manual testing, and business logic reviews.
- Perform secure code reviews (manual + automated) and identify root causes of vulnerabilities.
- Lead secure design & architecture reviews across new and existing systems.
- Drive product-level security controls, security guardrails, and policy implementation.
Cloud & Infrastructure Security :
Perform deep-dive AWS infrastructure security assessments including IAM, VPC, EC2, ECS, security groups, and network segmentation.Conduct periodic cloud configuration reviews and ensure compliance with best practices.Manage WAF configurations, bot-abuse protection, API security, and attack-surface monitoring.Support incident response planning, playbook development, and threat modelling.DevSecOps & Security Automation :
Build, enhance, and maintain SAST / DAST pipelines, dependency checks, container security scans, and secret scanning automation.Integrate security checks early in the SDLC and ensure shift-left adoption.Develop custom automation scripts using Python / Shell to scale security operations.Vulnerability Management :
Lead end-to-end vulnerability management : discovery, triage, prioritisation, tracking and closure with engineering teams.Manage external audits, bug-bounty triage, and coordinate fixes with App / Infra teams.Collaboration & Leadership :
Work closely with Product, Engineering, DevOps, Cloud, and IT teams to implement security best practices.Deliver internal security awareness and developer training programs if needed.Mentor junior analysts and foster a strong security culture.Certifications & Street Cred :
Preferred : ePTX / OSCP / eWPT / eCPPT / AWS Security Specialty(ref : hirist.tech)