
Security Engineer
3 days ago
Signzy is a digital trust system. We provide identification, background checks, forgery detection
and contract management systems which enable contracting in a trustable, safe, legal, and
convenient manner. Our biometric user authentication system and blockchain-based digital trail
ensure non-repudiation. This increases compliance and enforceability in the court of law. We
consist of a tech-savvy team and are backed by investors who are enthusiastic about creating
solutions with technology.
Working at Signzy
● At Signzy we breathe software and exploit the latest technologies to create the most
amazing products. We comprise a tech-savvy team and are backed by investors who are
enthusiastic about creating solutions using technology.
● Signzy is looking for an Security Engineer . If you think you have what it
takes to get the job done, this is an invitation to be a part of the future
JD for Security Engineer-1 Role
Responsibilities:
Application Security
- Perform secure code reviews, threat modeling, and static/dynamic application security testing (SAST/DAST).
- Integrate and maintain automated scanning tools (e.g., Semgrep, Snyk, Trivy, Gitleaks) in CI/CD pipelines.
- Collaborate with developers to remediate vulnerabilities and embed security in SDLC.
- Guide on secure architecture patterns (authentication, authorization, data encryption, API security, mobile app protections like SSL pinning and mTLS).
Infrastructure & Cloud Security
- Harden cloud infrastructure (AWS/GCP/Azure), including IAM, VPC design, encryption, and network segmentation.
- Implement infrastructure-as-code security checks for Terraform, Helm, and Kubernetes deployments.
- Conduct internal and external penetration tests, configuration reviews, and vulnerability management for servers, containers, and endpoints.
- Support continuous monitoring (WAF, SIEM, EDR/MDM) and incident response
Security Assessments & Compliance
- Lead periodic security assessments: vulnerability assessments, penetration testing, firewall rule reviews, user-access audits, and network segmentation reviews.
- Document findings, track remediation, and provide risk-based recommendations.
- Assist with evidence gathering for ISO 27001, SOC 2, PCI-DSS, GDPR, and internal security audits.
Continuous Improvement
- Research emerging threats (e.g., supply-chain attacks, npm/package ecosystem risks) and recommend mitigations.
- Contribute to security runbooks, policies, and developer awareness sessions.
Qualification
Must Have
- 2–4 years of experience in application or infrastructure security engineering.
- Strong understanding of web/mobile security, OWASP Top 10, cloud security fundamentals, and Linux/Unix systems.
- Hands-on experience with CI/CD pipelines and common security tools (SAST, DAST, container scanners, SIEM/EDR).
- Hands-on with SAST/DAST tools (e.g., Burp Suite, OWASP ZAP, Semgrep, Fortify)
- Knowledge of network & OS hardening (Linux, cloud workloads).
- Experience with internal and external penetration testing methodologies.
- Familiarity with common tools: Nmap, Metasploit etc.,
- Hands on experience with Mobile application security testing [Android and iOS]
- Familiarity with threat modeling frameworks (STRIDE, MITRE ATT&CK) and SBOM management.
- Scripting or programming skills (Python, Go, Bash) for automation and custom tooling.
- Should have fundamental knowledge of cloud environments
- Security-first mindset with curiosity and analytical thinking.
- Ability to review firewall rules, ACLs, and security groups for least-privilege.
- Understanding of network segmentation and zero-trust principles.
- Ability to translate complex vulnerabilities into actionable, developer-friendly guidance.
- Collaborative approach to working with engineering, DevOps, and compliance teams.
- Strong reporting & documentation skills (writing assessment reports).
- Knowledge of security standards (ISO 27001, NIST 800-53, CIS Benchmarks).
Good to Have
- Container & K8s Security: Familiarity with Trivy, Falco, Kubescape, Kyverno.
- IaC Security: Experience with Terraform/CloudFormation scanning (Checkov, Tfsec).
- DevSecOps Integration: Embedding security tests into CI/CD (GitLab, GitHub Actions, Jenkins).
- Advanced API Security: Hands-on with API gateways (Kong, Apigee, AWS API Gateway) and WAF tuning.
- Cloud-Native Security: Experience with GuardDuty, Security Hub, AWS Config, GCP SCC.
- Emerging Areas: AI/ML model security.
- Certifications (good-to-have, not must): OSCP or Cloud Security certs (AWS Security Specialty).
-
Senior Security Engineer
2 weeks ago
Bengaluru, Karnataka, India Skyhigh Security Full time US$ 1,25,000 - US$ 1,75,000 per yearJob Title:Senior Security EngineerAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.Since 2011, organizations have...
-
Engineering Manager
3 days ago
Bengaluru, Karnataka, India, Karnataka Skyhigh Security Full timeAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world’s data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency. Since 2011, organizations have trusted us to provide them with a...
-
Product Security Engineer
3 days ago
Bengaluru, Karnataka, India, Karnataka Traveloka Full timeJob DescriptionProduct Security Engineer at Traveloka will be required to ensure that our products and services are shipped with high security standards through application security testing, hardening, and secure framework. A Product Security Engineer will be smart and self starter. The person needs to find unique ways to understand complex software...
-
Cyber Security Engineer
3 days ago
Bengaluru, Karnataka, India, Karnataka Anumana Full timePosition: Cyber Security EngineerExperience Range: 3 to 5 yrsJob Location: BangaloreWork Mode: Hybrid (3 days in the office, 2 days remote)Job SummaryAnumana is seeking a skilled and motivated Cybersecurity Engineer to ensure the security, integrity, and compliance of our Software as a Medical Device (SaaMD) products. This position is critical in maintaining...
-
Technical Product Manager
3 days ago
Bengaluru, Karnataka, India, Karnataka Astra Security Full timeAbout Astra: Astra is a cyber security SaaS company that makes otherwise chaotic pentests a breeze with its one of a kind Pentest Platform. Astra's continuous vulnerability scanner emulates hacker behavior to scan applications for 9300+ security tests. CTOs & CISOs love Astra because it helps them fix vulnerabilities in record time and move from DevOps to...
-
GCP Cloud Security Engineer
3 days ago
Bengaluru, Karnataka, India, Karnataka Objectways Full timeJob Description: GCP Cloud Security EngineerLocation: Bangalore (Hybrid – 3 days in-office)Experience Required: 5+ years in cloud security, specifically with GCPRole OverviewWe are looking for a passionate GCP Cloud Security Engineer to enhance our Network Security and Technology Risk team in Bangalore. You will be central to securing our Google Cloud...
-
AWS Cloud Security Engineer
3 days ago
Bengaluru, Karnataka, India, Karnataka Objectways Full timeJob Title: AWS Cloud Security EngineerLocation: Bangalore (Hybrid – 3 days in office)Experience Required: 5+ yearsRole OverviewWe are seeking a dedicated AWS Cloud Security Engineer to bolster our Network Security and Technology Risk team in Bangalore. In this position, you will be pivotal in securing our AWS cloud infrastructure, ensuring compliance,...
-
Senior Product Security Engineer
3 days ago
Bengaluru, Karnataka, India, Karnataka Pocket FM Full timeAbout Pocket FMPocket FM is the world’s largest audio entertainment platform, revolutionizing the way stories are told and consumed. We bring together storytelling, technology, and creativity to deliver an immersive and engaging experience through audio series, audiobooks, and podcasts. With over 150 million+ users, and billions of minutes streamed...
-
Senior Application Security Engineer
3 days ago
Bengaluru, Karnataka, India, Karnataka Atomicwork Full timeAbout AtomicworkAtomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions.Role OverviewWe are looking for a Senior...
-
Technical Account Manager
3 days ago
Bengaluru, Karnataka, India, Karnataka Astra Security Full timeAbout Astra: Astra is a cybersecurity SaaS company that makes pentests simple with its AI-led Offensive Pentest Platform. Our continuous vulnerability scanner emulates hacker behavior with over 15,000 security tests, enabling CTOs and CISOs to achieve continuous security at scale, remediate vulnerabilities faster, and seamlessly embed security into DevOps...