Security Engineer

4 days ago


Yelahanka, India OnArrival Full time

About OnArrival OnArrival is the world’s most advanced full-stack travel platform. We power the infrastructure behind flights, hotels, insurance, visas, and more - all through modular APIs and embeddable frontends. We're building the AWS of travel tech - and doing it from India. Role Overview We’re looking for a hands-on Security Engineer who can design, implement, and operate security across our cloud infrastructure, backend services, and internal systems. You’ll work closely with platform, DevOps, and backend teams to ensure security is built-in from day one, not bolted on later. This role is ideal for someone who enjoys owning security end-to-end, from architecture to audits to real incident handling. Key Responsibilities Cloud & Infrastructure Security - Design and enforce security best practices across AWS infrastructure (IAM, VPCs, security groups, networking). - Own secure authentication mechanisms (IAM roles, SSH key management, restricted RDP access). - Implement and monitor WAFs, VPC flow logs, GuardDuty, CloudTrail, and related controls. - Ensure secure secrets management (AWS Secrets Manager, KMS). Application & Platform Security - Work with backend teams (Kotlin / Spring Boot, Node.Js) to enforce secure coding practices. - Review APIs, authentication flows, token-based systems, and multi-tenant data isolation. - Ensure encryption at rest and in transit across databases (MongoDB, Redis, Elastic). - Participate in threat modeling and security design reviews for new features. Compliance & Audits - Own and respond to security questionnaires, audits, and assessments (SOC 2, ISO 27001, partner security reviews). - Prepare and maintain security evidence, policies, and documentation. - Coordinate access reviews, user lifecycle management, and audit trails. - Support enterprise customers with security and compliance requirements. Monitoring, Detection & Incident Response - Set up centralized logging and security monitoring (SIEM integrations, alerts). - Define and run incident response playbooks. - Investigate and respond to security incidents and vulnerabilities. - Coordinate vulnerability scanning and penetration testing. Internal Security & Processes - Define access control policies for employees, vendors, and partners. - Work with HR and IT on joiner-mover-leaver processes. - Help establish security awareness and best practices internally. Required Skills & Experience - 3–7 years of experience in security engineering, cloud security, or DevSecOps. - Strong experience with AWS security (IAM, KMS, CloudTrail, GuardDuty, WAF). - Good understanding of web security fundamentals (OAuth, JWT, TLS, OWASP Top 10). - Experience securing backend systems and APIs. - Familiarity with logging, monitoring, and SIEM concepts. - Hands-on mindset. You should be comfortable configuring systems, not just writing docs. Good To Have - Experience with SOC 2, ISO 27001, or similar compliance frameworks. - Experience with container security (Docker, ECS/EKS). - Knowledge of EDR, DLP, or endpoint security tools. - Prior experience in fintech, travel-tech, or regulated environments. - Ability to communicate clearly with engineering, product, and external auditors. What You'll Get - Ownership of security for a real, production-scale platform. - Direct influence on architecture and engineering decisions. - Exposure to enterprise customers, audits, and complex integrations. - A team that treats security as a first-class engineering problem. - Opportunity to build security foundations that scale for years.



  • Yelahanka, India Persistent Systems Full time

    About Position: A Level 3 Network/Security Engineer (Senior Engineer) is responsible for designing, implementing, and managing complex network and security infrastructures. This role involves advanced troubleshooting, strategic planning, and ensuring compliance with security standards. It typically includes leadership responsibilities such as mentoring...


  • Yelahanka, India Mindsprint Full time

    Profile Summary: The Factory (ICS/ OT) Security Lead Engineer will be responsible for the Security Risk assessment and implementation of Factory Security Program and Practices for Mindsprint Customers. This position requires a strong understanding of both IT and OT systems, as well as expertise in cybersecurity practices specific to Factory Systems. Job...


  • Yelahanka, India Themesoft Inc. Full time

    Greetings from Themesoft! We are urgently looking for highly experienced Senior Data Security Specialists with strong expertise in Enterprise Encryption, CaaS, Tokenization, Cryptography, and Key Management Solutions. Job Title: Cyber & System Security Engineer Experience: 12+ Years of experienced candidates Notice Period: Immediate Joiners Preferred...


  • Yelahanka, India Best NanoTech Full time

    About the Company Develop, integrate, and maintain security solutions focused on TPM (Trusted Platform Module), firmware attestation, and Root of Trust (RoT). About the Role Implement and optimize TPM firmware and protocols to ensure robust device security. Responsibilities - Conduct threat modeling, risk assessments, and vulnerability analysis on firmware...


  • Yelahanka, India Andromeda Security Full time

    Experience: 4+ years Location: Bengaluru/On Site Employment Type: Full-time About the Role We are seeking an experienced Site Reliability Engineer (SRE) with a strong background in DevOps technologies and cloud infrastructure. The ideal candidate will have hands-on experience with Kubernetes, Helm charts, and AWS, along with a solid understanding of CI/CD...


  • Yelahanka, India ADM Full time

    About ADM: We are one of the world’s largest nutrition companies and a global leader in human and animal nutrition. We unlock the power of nature to provide nourishing quality of life by transforming crops into ingredients and solutions for foods, beverages, supplements, livestock, aquaculture, and pets. About ADM India Hub: At ADM, we have long recognized...


  • Yelahanka, India Palo Alto Networks Full time

    Our Mission At Palo Alto Networks® everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking...


  • Yelahanka, India Resillion Full time

    Job Title: Cyber Security Manager / Architect Experience range: 12-15 Years Location: Bangalore (Hybrid Mode) Company Description Resillion is the only Total Quality solutions company combining quality engineering, cyber security, conformance and interoperability, and content quality control. We are a strategic partner, ensuring digital resilience and...


  • Yelahanka, India Smarsh Full time

    Company Description Smarsh is the leader in Communications Compliance, Archiving, and Analytics. We provide compliance across the broadest set of communications channels with insights on what’s being captured. Smarsh customers manage over 500 million daily conversations across 80 channels - and it’s still growing. Our customers include the top 10 U.S.,...


  • Yelahanka, India Raytheon Technologies Full time

    Unspecified Role Overview We are seeking a highly experienced and strategic Information System Security Officerto lead our cyber and regulatory compliance programsacross RTX business unitsfor siteslocatedin (India/Singapore/Poland).This role is critical for ensuring the cyber posture of the sites and for establishing the guidelines and actions needed to...