Senior Security Engineer, Product Security New

2 days ago


Remote, India Ocrolus Full time ₹ 7,00,000 - ₹ 12,00,000 per year

Come build at the intersection of AI and fintech. At Ocrolus, we're on a mission to help lenders automate workflows with confidence—streamlining how financial institutions evaluate borrowers and enabling faster, more accurate lending decisions.

Our AI-powered data and analytics platform is trusted at scale, processing nearly one million credit applications every month across small business, mortgage, and consumer lending. By integrating state-of-the-art open- and closed-source AI models with our human-in-the-loop verification engine, Ocrolus captures data from financial documents with over 99% accuracy. Thanks to our advanced fraud detection and comprehensive cash flow and income analytics, our customers achieve greater efficiency in risk management, and provide expanded access to credit—ultimately creating a more inclusive financial system.

Trusted by more than 400 customers—including industry leaders like Better Mortgage, Brex, Enova, Nova Credit, PayPal, Plaid, SoFi, and Square—Ocrolus stands at the forefront of AI innovation in fintech. Join us, and help redefine how the world's most innovative lenders do business.

Summary:

Ocrolus is a fast-growing financial technology SaaS (Software-as-a-Service) organization. We are building a world-class security program to secure Ocrolus and our customers' data. We are looking for diverse security practitioners to help us design, build, and scale product security at Ocrolus. We value critical thinking, creativity, data-driven and intelligence-driven approaches, and offensive experience. Security is a collaborative process, where security is a partner to help achieve business goals securely. We believe in saying "yes and;" instead of "no" when recommending security objectives. We don't believe in using fear or penalty for the enforcement of security policies and processes, and we will always provide evidence and justification for security controls.

What you'll do:

  • Work closely with the CISO to build the product security strategy, roadmap, and metrics to measure and monitor product security posture.
  • Conduct design and architecture reviews for Ocrolus products and infrastructure.
  • Perform code reviews and application security assessments, including AI/LLMs.
  • Engage with the development teams to conduct secure design reviews/threat modeling exercises.
  • Identify vulnerabilities/threats that could affect Ocrolus products through independent research and work with the developers on workarounds/mitigation plans.
  • Be the go-to person for developers in solving critical issues relating to secure product development.
  • Run penetration testing targeting critical data, services, and environments. Report underlying security issues and propose enhanced security protections.
  • Write and disseminate security guidelines for common security issues, remediation, and security technology baselines.
  • Collaborate with stakeholders to ensure secure deployment of AI systems by staying updated on AI security best practices and executing adversarial testing strategies.
  • Guide engineering teams on secure coding and testing principles/practices.
  • Be a role model for the team and provide a healthy platform for learning and growth. Build relationships with stakeholders throughout the engineering and product organizations.
  • Spread security culture throughout the organization.

What you'll bring:

  • A passion for identifying vulnerabilities and remediations.
  • Ability to interpret and explain multiple classes of vulnerabilities, such as cross-site scripting, SQL Injection, CSRF, cryptographic-related weakness, and code injection, to various audiences, such as development and management teams.
  • Experience in designing and building a wide variety of technical security controls.
  • Experience in performing threat modeling, design reviews, code reviews, web application security, and enterprise cloud penetration testing.
  • Stellar understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into development processes.
  • Ability to automate product security processes and optimize productivity with SAST & DAST tools.
  • Good proficiency with a programming language (e.g., Java, Python, Go, Bash).
  • Good Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols
  • Experience in cloud security architecture and infrastructure.
  • Self-driven with excellent communication and prioritization skills.
  • A total of 5+ years of experience in product security (code, web application, API)

Good to have:

  • Published CVEs / articles on application security
  • Contributions to open-source security software
  • Certified in application security, pen testing (e.g., OSCP)

Life at Ocrolus

We're a team of builders, thinkers, and problem solvers who care deeply about our mission — and each other. As a fast-growing, remote-first company, we offer an environment where you can grow your skills, take ownership of your work, and make a meaningful impact.

Our culture is grounded in four core values:

Empathy – Understand and serve with compassion

Curiosity – Explore new ideas and question the status quo

Humility – Listen, be grounded, and remain open-minded

Ownership – Love what you do, work hard, and deliver excellence

We believe diverse perspectives drive better outcomes. That's why we're committed to fostering an inclusive workplace where everyone has a seat at the table, regardless of race, gender, gender identity, age, disability, national origin, or any other protected characteristic.

We look forward to building the future of lending together.

Create a Job Alert

Interested in building your career at Ocrolus Inc.? Get future opportunities sent straight to your email.

Create alert


  • L1 Security Analyst

    4 days ago


    Remote, India Kobalt Security Inc. Full time ₹ 8,00,000 - ₹ 12,00,000 per year

    About Us: At , our mission is to solve cybersecurity for SMBs at scale. We believe small businesses are the engine behind innovation and growth. Understanding the challenges that our customers have enables us to design and refine scalable cybersecurity services that support a secure path to growth. This is reflected in everything we do from the programs we...


  • Remote, India Sun King Full time US$ 70,000 - US$ 1,20,000 per year

    DescriptionJob location: Remote in India About the role:In this role, your principal mission will be to drive security-related engineering engagement and technical remediation across Sun King's product lines. You will work across application security, architecture reviews, and cloud security to scale security engagement across Engineering. As a Product...


  • Remote - India Twilio Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    See yourself at TwilioJoin the team as Twilio's next Senior Cloud Security Engineer (L3). About the job The Cloud and Application Security team enables delivery of secure by default products to reduce our attack surface against an evolving threat landscape. This position is needed to enhance Twilio's Cloud Security capabilities to improve visibility,...


  • Remote - India Twilio Full time ₹ 15,00,000 - ₹ 20,00,000 per year

    See yourself at Twilio Join the team as Twilio's next Senior Application Security Engineer(L3). About the job The Cloud and Application Security team enables delivery of secure by default products to reduce our attack surface against an evolving threat landscape. This position is needed to enhance Twilio's Application Security capabilities to improve...


  • Remote, India Nexsofture Private Limited Full time ₹ 15,00,000 - ₹ 28,00,000 per year

    Role OverviewWe are seeking a highly skilled Senior Application Security Engineer with deep expertise in application security, threat modeling, and secure design, particularly within the ServiceNow ecosystem. The ideal candidate will combine strong technical security knowledge with practical experience in enterprise application development and cloud...

  • Security Engineer

    4 days ago


    Remote, India NotDisclosed Full time ₹ 10,00,000 per year

    Key Responsibilities:Design, implement, and maintain security architecture across applications, infrastructure, and networks.Ensure data security (TLS 1.3, AES-256) and strong identity/access management (SAML, OAuth, RBAC).Lead threat modeling, risk assessments, and vulnerability management.Oversee secure SDLC practices: code reviews, SAST/DAST, CI/CD...


  • Remote, India Rackspace Technology Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Rackspace Security (Public Cloud)Security Engineer L3 (Endpoint Security)About Rackspace Cyber DefenceRackspace Cyber Defence is our next generation cyber defence and security operations capability that builds on 20+ years of securing customer environments to deliver proactive, risk-based, threat-informed and intelligence driven security services.Our purpose...


  • Remote, India beBeeSeniorSecurityEngineer Full time ₹ 15,00,000 - ₹ 20,00,000

    About This RoleThis position involves working as a senior security engineer on the Tide platform.Our team's mission is to protect our products, covering all aspects from secure design reviews to threat modelling and penetration testing.We're proactive in our defence, constantly improving our security posture and staying ahead of emerging threats.Your Key...

  • Network Security

    1 week ago


    Remote, India Fast Track Jobs Full time

    We Required **Network Security** For an **IT Company** at **Lower Parel (Work From Home)** **Position : Network Security** **Location : Work From Home** Sal **:Nego (Depends on Exp & Skills)** **Exp : 1 to 5 years** **Job Description-** - Continuously updating the company’s incident response via. Cato or SOTIC alerts. - security tickets monitoring,...


  • Remote, India cyberu Full time US$ 1,25,000 - US$ 1,75,000 per year

    We're looking for a Principal Security Engineer This role is Office BasedPrincipal Security Engineer – India – Cybersecurity Engineering:As a Principal Security Engineer, yourleadership will encompass safeguarding infrastructure, network, cloud, andAI-driven systems across Cornerstone's enterprise environments. This role demandsnot only vision and...