Skip to content

Lead Security Engineer

Leads cloud security architecture, penetration testing, threat modeling, and secure-by-default practices for large-scale cloud-native applications. Requires 8+ years of application, product, or cloud security experience and strong expertise across cloud platforms, containers, and security tooling.

About the job

Responsibilities

  • Design secure, scalable cloud environments across AWS, GCP, and Azure, focusing on identity, network security, encryption, and compliance.
  • Conduct security architecture reviews for distributed systems and cloud-native applications; identify design risks and recommend secure architectural patterns.
  • Lead manual and automated penetration testing across applications, APIs, and cloud services.
  • Drive threat modeling and secure architecture reviews across application and infrastructure layers.
  • Collaborate with Infrastructure and DevOps teams on VPC design, security groups, routing, and network segmentation.
  • Design and advise on cloud-native security controls, including IAM hardening, role boundaries, secrets management, and least privilege.
  • Evaluate and improve Kubernetes and container security across runtime, image, and network layers.
  • Implement secure-by-default patterns across the SDLC, CI/CD, and infrastructure as code.
  • Monitor emerging threats, CVEs, and vulnerabilities relevant to web, cloud, and infrastructure environments.
  • Influence security tooling, automation pipelines, and security review processes.
  • Advise engineering, SRE, and product teams on security for key projects.

Requirements

  • 8+ years of experience in application security, product security, or cloud security, focused on large-scale cloud-native applications.
  • Strong hands-on experience with threat modeling, secure architecture reviews, and penetration testing.
  • Familiarity with OWASP Top 10, STRIDE, and modern security frameworks.
  • Experience with Burp Suite, ZAP, Snyk, Metasploit, and Semgrep.
  • Ability to read and analyze code, such as JavaScript, Go, PHP, or Node.js.
  • Working knowledge of cloud security principles, preferably AWS.

Nice-to-Haves

  • Experience with multi-tenant SaaS platforms or white-labeled architectures.
  • Familiarity with VPC design, IAM, and zero-trust networks.
  • Exposure to Docker and Kubernetes security.
  • Background in B2B SaaS serving regulated industries such as health, legal, or finance.
  • Hands-on experience with infrastructure-as-code security and CI/CD pipelines, including GitHub Actions and Terraform.

Skills

AWS, GCP, Microsoft Azure, Cloud Security, Threat Modeling, Penetration Testing, Owasp Top 10, Stride, Burp Suite, Zap, Snyk, Metasploit, Semgrep, Kubernetes, Terraform

Greenlight

Greenlight

Bengaluru, India

Senior Security Engineer
No salary listedHybrid5+ YOESecurity Engineering

Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.

GoHighLevel

GoHighLevel

India

Lead Security Engineer - Penetration Testing & AI Security
No salary listedRemote8+ YOESecurity Engineering

Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.

Rippling

Rippling

Bengaluru, India

Senior Security Engineer - DART
No salary listedOn-site7+ YOESecurity Engineering

The Senior Security Engineer will build and operate detection and incident-response capabilities across cloud production and corporate environments. The role requires 7+ years of security engineering experience, AWS expertise, threat hunting, investigations, automation, and SIEM/SOAR proficiency.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Anyscale

Anyscale

India
Senior Detection and Response Engineer
$200k+/yrOn-site6+ YOESecurity Engineering

Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.