Staff Security Engineer

5 days ago


Delhi, India Ethos Full time

About the Role:We're looking for aStaff Security Engineerwith deep technical expertise inapplication security ,penetration testing , andoffensive security practices . You will lead efforts to proactively identify and exploit vulnerabilities across our products and infrastructure, working alongside engineering and security teams to design robust defences and build security into everything we deploy.This is a hands-on technical role with significant influence over the security posture of the company, from code to cloud.Duties and Responsibilities:Application SecurityPerform code reviews, threat modelling, and architecture assessments across internal and customer-facing applications.Guide engineering teams on secure design patterns, libraries, and development practices.Integrate and maintain security tooling (SAST, DAST, SCA) into CI/CD pipelines.Collaborate with product and engineering teams to remediate identified vulnerabilities and design secure solutions.Penetration TestingConduct manual and automated penetration tests against Ethos Web Application, APIs, infrastructure, and cloud environments.Simulate attacker behaviors to assess technical weaknesses and business risks.Create detailed, developer-friendly reports with risk ratings and actionable remediation guidance.Re-test findings and validate security fixes in collaboration with product owners.Offensive SecurityPlan and execute red team operations, simulating advanced persistent threat (APT) scenarios.Develop custom tools, scripts, and exploits to test detection and response capabilities.Collaborate to improve detection, logging, and incident response based on attack insights.Contribute to the development of offensive security playbooks and adversary emulation plans.Other ResponsibilitiesMentor junior team members and evangelize security best practices across the company.Participate in investigations, threat hunting, and incident response activities; build playbooks for specific incident response scenariosCommunicate risks to engineering staff through training and technical demonstration of vulnerabilities and secure design patternsSupport security audits, compliance efforts, and executive briefings with technical depth.Qualifications and Skills:Required:8+ years of experience in security engineering, penetration testing, or offensive security.Strong understanding of secure coding principles, web security vulnerabilities (e.g., OWASP Top 10), and remediation techniques.Proficiency in threat modeling, design reviews and security testing of various types of applications, technologies and platformsProficient in scripting and development (e.g., Python, Bash, Go, JavaScript).Skilled in using tools such as Burp Suite, Metasploit, Nmap, Cobalt Strike, or custom tooling.Experience with AWS cloud platform and containerized environments (Docker, Kubernetes).Strong written and verbal communication skills for technical and non-technical audiences.Preferred:Certifications like OSCP, OSWE, OSEP, GXPN, or equivalent.Experience with threat modeling methodologies (e.g., STRIDE, PASTA).Familiarity with MITRE ATT&CK, adversary emulation, and purple teaming.Contributions to security research, open-source tools, or bug bounty platforms.


  • Security Engineer

    5 days ago


    Delhi, India TAC Security Full time

    Job descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...

  • Security Engineer

    4 days ago


    Delhi, India TAC Security Full time

    Job description As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...

  • Security Engineer

    1 week ago


    Delhi, Delhi, India TAC Security Full time ₹ 5,00,000 - ₹ 8,00,000 per year

    Job descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...

  • Security Engineer

    5 days ago


    Delhi, India TAC Security Full time

    Job description As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients'...

  • Security Engineer

    1 week ago


    Delhi, Delhi, India TAC Security Full time

    Job description As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems...

  • Security Engineer

    4 days ago


    Delhi, India TAC Security Full time

    Job descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...

  • Security Engineer

    4 days ago


    delhi, India TAC Security Full time

    Job descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...

  • Security Engineer

    3 days ago


    Delhi, India TAC Security Full time

    Job description As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients'...

  • Security Engineer

    1 week ago


    Delhi, Delhi, India TAC Security Full time

    Job Description :As a Security Engineer VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...

  • TAC Security

    4 days ago


    Delhi Division, India TAC Security Full time

    Job Description :As a Security Engineer VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems...