Skip to content

Lead Security Engineer - Penetration Testing & AI Security

Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.

About the job

Responsibilities

  • Lead application security initiatives across web, mobile, API, microservices, and cloud-native products.
  • Conduct architecture reviews, threat modeling, secure design and code reviews, penetration tests, and hands-on security assessments.
  • Identify weaknesses in authentication, authorization, tenant isolation, business logic, data protection, and API security.
  • Define security standards, requirements, guardrails, and reusable secure engineering patterns.
  • Improve CI/CD security testing with SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.
  • Drive risk-based vulnerability triage and remediation with engineering teams.
  • Develop security automation and promote secure coding through guidance, documentation, and training.
  • Lead security reviews and adversarial testing of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.
  • Assess model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent toolchains.
  • Test for prompt injection, jailbreaking, sensitive-data disclosure, system-prompt leakage, output manipulation, insecure tool use, excessive agency, model abuse, data poisoning, model inversion, training-data extraction, adversarial evasion, and model exfiltration.
  • Evaluate guardrails, input/output filtering, access controls, human approvals, logging, monitoring, and abuse detection.
  • Develop AI security testing methodologies, playbooks, automation, and test cases using Garak, PyRIT, or similar frameworks.
  • Assess security and supply-chain risks involving third-party models, AI platforms, and AI-enabled SaaS products.
  • Produce security reports with evidence, risk ratings, business impact, and remediation guidance.
  • Communicate risks to developers, architects, product leaders, and executive stakeholders.
  • Mentor engineers and help establish a security-conscious engineering culture.

Requirements

  • 8+ years of cybersecurity experience with hands-on expertise in application security, product security, penetration testing, or security engineering.
  • 1–3 years of AI security experience, including AI/ML security, adversarial testing of AI systems, or security-focused applied AI research.
  • Experience with threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.
  • Strong knowledge of web, mobile, API, and cloud-native security, OWASP guidance, and business-logic risks.
  • Understanding of OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.
  • DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.
  • Knowledge of Docker, Kubernetes, microservices, and cloud security.
  • Experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.
  • Understanding of prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks.
  • Familiarity with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices.
  • Programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language.
  • Strong written and verbal communication skills.

Nice to Have

  • Experience building or scaling application security practices in a SaaS or product-led technology organization.
  • Hands-on experience red teaming LLM applications, RAG systems, AI agents, or AI-enabled products.
  • Experience developing security automation, internal testing tools, or reusable security guardrails.
  • Contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure.
  • Certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI security credential.

Skills

Application Security, Penetration Testing, Threat Modeling, Ai Security, Llm Security, RAG, Python, Go, JavaScript, Kubernetes, Docker, DevSecOps, SAST, DAST, Owasp

Greenlight

Greenlight

Bengaluru, India

Senior Security Engineer
No salary listedHybrid5+ YOESecurity Engineering

Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.

Rippling

Rippling

Bengaluru, India

Senior Security Engineer - DART
No salary listedOn-site7+ YOESecurity Engineering

The Senior Security Engineer will build and operate detection and incident-response capabilities across cloud production and corporate environments. The role requires 7+ years of security engineering experience, AWS expertise, threat hunting, investigations, automation, and SIEM/SOAR proficiency.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Anyscale

Anyscale

India
Senior Detection and Response Engineer
$200k+/yrOn-site6+ YOESecurity Engineering

Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.

Anyscale

Anyscale

India
Senior Product Security Engineer
$180k+/yrOn-site8+ YOESecurity Engineering

Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.