# Senior Security Engineer

**Company:** [Greenlight](https://hotfix.jobs/companies/greenlight)
**Location:** Bengaluru, India
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** AWS, Kubernetes, Node.js, Kotlin, Java, Go, React, GraphQL, MySQL, Redis, CI/CD, Threat Modeling, SAST, DAST, Penetration Testing
**Posted:** 2026-09-09

> Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.

## Job Description

## Responsibilities
- Execute a product security strategy aligned with company goals and risk appetite.
- Build and operate security automation across code, infrastructure, and CI/CD, including agents, services, and pipelines for detecting, preventing, and remediating risks.
- Design SDLC security automation for code scanning, dependency risk management, secrets detection, and policy-as-code.
- Perform manual security design and implementation reviews of products and services.
- Establish secure development standards covering API security, security patterns, and infrastructure as code.
- Serve as a subject-matter expert for AI and LLM security; lead threat modeling for novel AI systems.
- Continuously test, fuzz, and validate products and platform components for security issues.
- Perform penetration testing and retesting to validate fixes.
- Triage security researcher findings and lead PSIRT incident response and product security events.
- Partner with engineering, product, and platform teams on secure-by-design patterns, threat modeling, vulnerability remediation, and developer guardrails.
- Develop software supply-chain protections, including SBOM generation and verification, artifact signing and attestation, and provenance enforcement.
- Build static and dynamic analysis automation and reusable security frameworks.
- Use telemetry to measure control effectiveness and build dashboards and alerts.
- Document runbooks and APIs, mentor engineers, and promote secure engineering practices.
- Stay current on security threats, vulnerabilities, and industry practices.

## Requirements
- 5+ years of experience finding security vulnerabilities, conducting security code reviews, and applying secure coding practices.
- 2–4 years of experience with threat modeling and identifying design flaws from technical architectures and data-flow diagrams.
- Experience exploiting common security vulnerabilities.
- Deep knowledge of web and mobile application security, common vulnerabilities, exploit mitigations, and secure architecture patterns.
- Experience integrating or building AI-powered tools for vulnerability detection, code review, or threat modeling.
- Experience creating software and automation that enables security processes, including AI/ML-enabled automation.
- Experience implementing and managing product security tools such as API security, mobile protection, SAST, and runtime scanning.
- Strong understanding of CI/CD pipelines and security tooling for web and mobile applications.
- Hands-on experience with SAST, DAST, IAST, and penetration-testing tools.
- Scripting, automation, and exploit-writing skills.
- Strong understanding of AWS cloud security principles.
- Strong communication and collaboration skills.

## Nice to Have
- Fuzzing expertise.
- Ability to turn bespoke security engagements into reusable patterns and reference implementations.
- Security assessment experience for IoT hardware and firmware.
- Contributions to the security community through research, bug bounties, presentations, or blogs.
- Experience in fintech or other regulated industries.
- Startup experience and a curious, adaptable mindset.

## Similar jobs

- [Lead Security Engineer - Penetration Testing & AI Security](https://hotfix.jobs/jobs/ac8bc34d-2a43-4c67-870e-a1e01edee0cb) - GoHighLevel - Remote
- [Senior Security Engineer - DART](https://hotfix.jobs/jobs/8f733ffe-5874-43b6-9dcb-4a76ac35e099) - Rippling - Bengaluru, India
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Detection and Response Engineer](https://hotfix.jobs/jobs/ebb8ac3d-4282-4505-bdb8-4699d594df80) - Anyscale - $200k – $240k/yr
- [Senior Product Security Engineer](https://hotfix.jobs/jobs/ee4b6e89-8ca0-45e7-9cbf-da0994206d99) - Anyscale - $180k – $210k/yr

**Apply:** https://hotfix.jobs/jobs/2a1ede09-d608-462e-bb14-223603034206
**Canonical:** https://hotfix.jobs/jobs/2a1ede09-d608-462e-bb14-223603034206