Cutshort logo
For Employers
Confidential logo
Security Engineer
Confidential
Security Engineer

Security Engineer at Confidential · Remote only · 2 - 4 years · ₹10L - ₹25L / yr · Remote only · Posted 30 Jan 2023

Petals Careers's logo

Security Engineer

at Confidential

Agency job
2 - 4 yrs
₹10L - ₹25L / yr
Remote only
Skills
Penetration testing
skill iconAmazon Web Services (AWS)
Google Cloud Platform (GCP)
skill iconKubernetes
Backtrack
Metasploit
Job Description
  • You have 2+ years of experience with production GCP/AWS; Experience with Kubernetes is a plus
  • You have conducted penetration testing using different tools like Backtrack and Metaspoilt
  • You have experience in developing security training and guiding the internal development teams
  • You design and implement best practices concerning information security
  • You can create programs to implement Identity and Access Management
  • You have to develop automated security testing.
  • You have to triage security issues and provide recommended fixes.
  • You have conducted vulnerability assessments using various open-source and commercial tools.
  • You are an excellent collaborator & communicator. You know that start-ups are a team sport.
  • You listen to others, aren’t afraid to speak your mind and always try to ask the right questions.
  • You are excited by the prospect of working in a distributed team and company.

Role: Security Engineer

Title: Security Engineer SDE1

Location: We are open to candidates working from anywhere in India/across the globe. We are fully remote.

About Us
Requirements / Responsibilities

The ability for you to make an impact and lay a foundation for the upcoming fin-tech
innovations.
A multicultural and diverse team of colleagues from all over the globe
Mission-driven and fast-paced, entrepreneurial environment
Competitive salary and flexible leave policy
A collaborative and flat company culture
What do we offer? 
What’s in it for you?
Do you truly want to make a difference and revolutionize the lives of millions of business
owners? Do you thrive in an environment where moving at light speed and embracing new
challenges every day is essential? If yes, our client is the perfect place for you!

Regards,
TA
Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

Similar jobs (10)

company logo
Zeeshan Sheikh
Posted by Zeeshan Sheikh
Kolkata
6 - 10 yrs
₹4L - ₹5L / yr
Cyber Security
Security Information and Event Management (SIEM)
Network Security
Information security management system
Information security

A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.

Key Responsibilities

  • Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
  • Conduct vulnerability assessments, penetration testing, and risk analysis.
  • Monitor and respond to security incidents, ensuring timely resolution and documentation.
  • Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
  • Collaborate with IT and business teams to integrate security into system architecture and processes.
  • Lead incident response drills and disaster recovery planning.
  • Provide guidance and mentorship to junior cybersecurity staff.
  • Stay updated on emerging threats, tools, and technologies.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
  • 5–10 years of proven experience in cybersecurity engineering or related roles.
  • Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
  • Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
  • Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.

Skills

  • Advanced problem-solving and analytical skills.
  • Strong communication and leadership abilities.
  • Ability to manage complex projects and handle escalations effectively.
  • Proactive mindset with adaptability to evolving cyber threats.


Read more
company logo
Agency job
via by Akash Bhatt
Bengaluru (Bangalore), Hyderabad, Pune, Kolkata, Chennai, Mumbai
1 - 10 yrs
₹4L - ₹30L / yr
Security Information and Event Management (SIEM)
Cyber Security
Burp suite
Metasploit
Network Security

We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.


Responsibilities

  • Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
  • Monitor and respond to security events using SIEM tools as part of SOC operations
  • Test application security using Burp Suite and similar tools
  • Support ISO 27001 compliance, audits and security policies
  • Harden network infrastructure, firewalls and access controls
  • Document findings and track fixes with engineering teams


Requirements

  • 1+ years of experience in VAPT, SOC or security engineering
  • Hands-on experience with Burp Suite and SIEM tools
  • Knowledge of the OWASP Top 10 and network security fundamentals
  • Exposure to ISO 27001 or similar frameworks
  • Certifications such as CEH, OSCP or CompTIA Security+ are a plus
Read more
company logo
Sandhiya M
Posted by Sandhiya M
Chennai
1 - 5 yrs
₹2L - ₹8L / yr
ISO9001
ISO27001
Security Information and Event Management (SIEM)
Cyber Security
skill iconAmazon Web Services (AWS)
+4 more

Hi Folks, we are currently Hiring for Security Engineer.

Gemini said


Hiring: Security Engineer

Company : Pentabay Softwares

Location : Anna salai, Mount Road

Mode: Fulltime


Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.


The Mission

You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.


Key Responsibilities


Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.

Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.

DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.

Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.

Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.


What You Bring


Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).

Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).

Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.

Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).

Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.

Auditing space like ISO27001 , ISO9001 prefered


Why Pentabay?

At Pentabay, we offer more than just a job; we offer a security-first engineering culture.

Growth: A dedicated learning budget for certifications and conferences.

Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.


Send resumes to : sandhiya.m at pentabay.com

Read more
company logo
Ananya  Arenavaru
Posted by Ananya Arenavaru
Bengaluru (Bangalore)
5 - 10 yrs
₹15L - ₹18L / yr
Jump Cloud
Sophos
google workspace
SSO
Sophos Central administration
+10 more

IT Systems Engineer

Location: Bengaluru, India · On-site | Experience: 5+ years in IT systems / infrastructure

Department: IT & Information Security | Employment Type: Full-time | Reports To: Engineering Leadership

Focus: Own the identity, endpoints, network, and compliance backbone that powers immersive technology at

scale.

The Mission

About Metadome.ai

Metadome.ai is an immersive 3D & XR technology company that enables cloud-based, photorealistic, and captivating customer experiences for brands. Our technology offers a complete stack for creating immersive 3D & XR applications with omni-channe deployment across both in-store and digital touchpoints, and over a multitude of devices. These experiences span a spectrum of use cases across the automotive, home décor, fashion, and cosmetics & accessories sectors. Our flagship automotive platform — Autodome — enables unprecedented photorealistic, cloud-based immersive 3D & XR applications that cover the entire pre-retail funnel, empowering brands to launch products virtually and drive awareness, engagement, and bookings among modern automotive consumers. Today, we are trusted partners to leading brands across the globe — including Unilever, MG Motor, Lexus, Asian Paints, Tata Motors, and Royal Enfield, among others. We have also partnered with the likes of TCS, SAP , and PwC, and are an active voice in the XR community, including the

Metaverse Standards Forum and the VR/AR Association.


About the Role

We are looking for a hands-on IT Systems Engineer to own and run the technology backbone that keeps our teams productive and our data secure. You will be the single point of accountability for IT operations and information security across a multi-location business where 24x7 systems availability is core to how we operate — managing identity, endpoints, network, and our cloud workspace, while operating and continuously hardening our GDPR, SOC 2, and ISO 27001 compliance posture.

This is a builder-operator role, not a supervisory one. We run a tight ship on security and compliance, and we expect you to have personally implemented and operated the systems and controls described below — you should know them inside out, down to the configuration, the evidence, and the edge cases.


Core Responsibilities

● Identity & Access Management — JumpCloud:

○ Own the JumpCloud directory end-to-end: user lifecycle (joiner / mover / leaver), groups, and organizational structure.

○ Administer SSO, enforce MFA, and configure conditional and device-based access policies across all SaaS applications.

○ Manage cross-platform device policies (macOS, Windows, Linux) via JumpCloud device management, including disk encryption and compliance baselines.

○ Integrate RADIUS / LDAP for Wi-Fi and application authentication.

○ Automate onboarding and offboarding to guarantee least-privilege access and clean, auditable deprovisioning.

● Google Workspace Administration — GWS:

○ Administer the Google Workspace tenant: users, groups, organizational units, and email routing.

○ Configure and enforce security controls — 2-Step Verification, context-aware access, DLP rules,

and sharing / visibility policies.○

○ Manage retention, eDiscovery, and legal holds through Google Vault. Optimize licensing and SaaS spend across Workspace and other portals.


Endpoint & Threat Protection — Sophos:

○ Deploy, configure, and manage Sophos Central (Intercept X / XDR) across all endpoints and

servers.

○ Monitor alerts, triage threats, and lead incident detection, response, and remediation.

○ Maintain endpoint encryption, web / application control, and device-hardening standards.

○ Where Sophos Firewall is in use, manage firewall policies, IPS, and secure remote access.


Network, Firewall & Wi-Fi:

○ Design, configure, and maintain firewalls, VLAN segmentation, VPN, and secure remote access.

○ Administer enterprise Wi-Fi and wired networks (switches, access points), including

RADIUS-backed authentication.

○ Manage LAN / WAN connectivity, ISP relationships, and network performance and uptime.

○ Implement network monitoring, intrusion detection, and centralized logging.

Hardware, Software & Asset Management:

○ Own the full hardware lifecycle — procurement, provisioning / imaging, maintenance, repair, and

decommissioning.

○ Support a mixed fleet of macOS, Windows, and Android devices, including high-performance workstations and XR / VR hardware used by our creative and engineering teams.

○ Maintain an accurate hardware and software inventory and asset register.

○ Manage software deployment, patch management, and license compliance.


Security, Risk & Compliance — GDPR · SOC 2 · ISO 27001:

○ Operate and continuously improve the company's Information Security Management System

(ISMS).

○ Own day-to-day compliance for GDPR, SOC 2 (Type II), and ISO/IEC 27001 — including control

implementation, evidence collection, and continuous monitoring.

○ Conduct risk assessments, internal audits, periodic access reviews, and vendor security / DPA

assessments.

○ Serve as a primary point of contact during external audits and customer security reviews.

○ Maintain security policies, records of processing (RoPA), DPIAs, and incident / breach-response

runbooks.

○ Drive security-awareness and phishing-simulation programs across the organization.


IT Operations & Support:

○ Ensure 24x7 high availability of core systems and meet defined uptime and SLA metrics.

○ Provide escalation-level troubleshooting and support across macOS, Windows, and Android.

○ Manage backups, disaster recovery, and business-continuity testing.

○ Coordinate internal teams and third-party vendors to deliver IT projects on time and within

budget.

○ Maintain documentation, runbooks, and standard operating procedures.

○ Own and report on the IT budget and asset allocation.


Required Skills & Experience

● 5+ years in IT systems / infrastructure engineering — with direct, hands-on ownership of the systems

below rather than purely supervisory exposure.

● JumpCloud — demonstrated hands-on expertise across identity, SSO, MFA, and device management.

● Google Workspace (GWS) — deep admin-console experience including security, DLP , and Vault.

● Sophos — hands-on endpoint / XDR administration and threat response.

● Networking — firewall configuration, Wi-Fi, VLANs, VPN, LAN / WAN, and RADIUS / LDAP fundamentals.

● GDPR, SOC 2 & ISO 27001 — hands-on — you have personally taken an organization through at least one

full audit / certification cycle and know the controls, evidence, and auditor expectations inside out.


Cross-platform support — proven troubleshooting across macOS, Windows, and Android in a 24x7, multi-location environment.

System security — solid grasp of IDS / IPS, endpoint hardening, encryption, and backup / recovery.


Education — B.Sc. / B.Tech in Information Technology, Computer Science, or a related discipline.


Mindset — strong documentation discipline, ownership, resourcefulness, and a structured, problem-solving approach.


Preferred Qualifications


●Relevant certifications — e.g., ISO 27001 Lead Implementer / Auditor, CompTIA Security+ / Network+, or vendor certifications from JumpCloud and Sophos.

●Experience with compliance-automation platforms such as Sprinto, Vanta, or Drata.

●Scripting and automation for IT operations (Bash, PowerShell, or Python).

●Experience in a fast-paced SaaS or technology company serving enterprise and global clients.

●Familiarity with supporting creative, 3D, or XR workflows and high-performance computing environments.


Why Join Us

You will own the systems and security posture of a company building category-defining immersive technology for some of the world's most recognizable brands. It is a high-trust, high-ownership role with the autonomy to design things properly — and the visibility that comes with keeping a security- and compliance-first business running

flawlessly.



Read more
company logo
amit verma
Posted by amit verma
Remote only
5 - 15 yrs
₹30L - ₹70L / yr
Cyber Security
Web application security
Penetration testing
skill iconPython
skill iconJava
+2 more

Cybersecurity Engineer – AI Training Project


About the Opportunity

We’re looking for experienced Cybersecurity Engineers to contribute technical expertise to a customer project focused on improving the capabilities of next-generation AI systems.

In this role, you’ll use your real-world experience in cybersecurity, software engineering, vulnerability assessment, and secure development to create high-quality technical inputs that help AI systems better understand, debug, secure, and reason about complex software.


What You’ll Do

  • Analyze, debug, and resolve software bugs, vulnerabilities, and security issues across complex codebases.
  • Review source code and identify potential security weaknesses, vulnerabilities, and attack vectors.
  • Perform security assessments, vulnerability assessments, penetration testing, and codebase audits.
  • Develop and modify software using languages such as Python, Java, Rust, Go, C++, or TypeScript.
  • Implement new features and fix existing functionality while maintaining strong security and engineering standards.
  • Refactor legacy code to improve security, maintainability, reliability, and performance.
  • Work on backend systems and help optimize applications for scalability, performance, and security.
  • Analyze real-world security scenarios and translate your expertise into high-quality technical examples and problem-solving tasks.
  • Document technical findings, vulnerabilities, debugging approaches, and recommended solutions.
  • Provide domain expertise that helps improve how AI systems reason about software engineering and cybersecurity problems.


What We’re Looking For

  • Strong professional experience in Cybersecurity / Application Security / Product Security / DevSecOps / Penetration Testing / Vulnerability Management.
  • Strong programming experience in one or more of:
  • Python
  • Java
  • Rust
  • Go
  • C++
  • TypeScript
  • Proven experience with debugging, troubleshooting, and fixing complex software issues.
  • Hands-on experience with penetration testing, vulnerability assessment, security auditing, or application security.
  • Understanding of secure software development practices and modern security threats.
  • Strong knowledge of data structures, algorithms, software architecture, and code quality.
  • Ability to review unfamiliar codebases and quickly understand how systems work.
  • Strong written communication and the ability to explain complex technical findings clearly.


Nice to Have

  • Experience with OWASP, API security, cloud security, DevSecOps, or threat modeling.
  • Experience performing security assessments on production applications or enterprise systems.
  • Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, SAST/DAST tools, or vulnerability scanners.
  • Contributions to open-source security or software projects.
  • Experience working with AI/ML systems, LLMs, data annotation, or AI training projects.
  • Relevant security certifications such as OSCP, OSWE, CEH, CISSP, Security+, or equivalent practical experience.


Engagement

  • Role: Cybersecurity Engineer
  • Work: Remote(Contract)
  • Experience: Mid-level to Senior
  • Programming: Required
  • Cybersecurity expertise: Required


Why Join?

This is an opportunity to apply your existing cybersecurity expertise to an emerging area of technology. Your practical experience debugging software, identifying vulnerabilities, securing applications, and solving complex engineering problems will directly contribute to improving the capabilities of next-generation AI systems.


If you enjoy breaking down complex technical problems, finding vulnerabilities, fixing software, and thinking deeply about how systems work, this project could be a strong fit.

Read more
company logo
Vijayshree Purohit
Posted by Vijayshree Purohit
icon

The recruiter has not been active on this job recently. You may apply but please expect a delayed response.

Mumbai
3 - 5 yrs
₹8L - ₹9L / yr
Comp TIA A+
Microsoft
CCNA
Security+
Network +
+1 more

About Nerve Solutions

Nerve Solutions is a team of engineers building products for real-time risk management and surveillance in financial markets. Our solutions enable market participants to identify, monitor, and quantify risks and anomalies in live markets, allowing them to take corrective action at sub-second speeds.

We also develop products for automated trading and have become a trusted technology partner to some of the largest financial services organizations in the region.


About the Role

We are looking for a proactive and detail-oriented IT & Information Security Engineer to manage and maintain the organization's IT infrastructure while ensuring the security, availability, and reliability of our systems. The role involves providing technical support, administering hardware and software, strengthening cybersecurity practices, monitoring network activities, and implementing security controls to safeguard organizational assets.

The ideal candidate should have strong infrastructure knowledge, a security-first mindset, and the ability to troubleshoot technical issues while continuously improving the organization's IT environment.


Roles & Responsibilities

  • Manage and maintain the organization's IT infrastructure, including hardware, software, servers, and network systems.
  • Provide technical support to employees by troubleshooting hardware, software, network, and system-related issues.
  • Configure, deploy, and maintain desktops, laptops, peripherals, printers, and other IT equipment.
  • Set up user accounts, systems, and required software for new employees and support onboarding activities.
  • Monitor network performance and employee network activities to ensure system security and compliance.
  • Implement and maintain endpoint security solutions, antivirus tools, firewalls, and access control mechanisms.
  • Perform regular system updates, security patching, vulnerability assessments, and preventive maintenance.
  • Identify infrastructure risks and recommend security enhancements to minimize vulnerabilities.
  • Maintain documentation for IT assets, software licenses, network configurations, security policies, and system inventories.
  • Assist in implementing information security best practices, security audits, and compliance initiatives.
  • Coordinate with internal teams to ensure IT services effectively support business operations.
  • Stay updated with the latest cybersecurity threats, technologies, and industry best practices.



Required Skills

  • 2–4 years of experience in IT Infrastructure, System Administration, or Information Security.
  • Strong knowledge of Windows operating systems, networking, servers, and IT infrastructure.
  • Experience troubleshooting hardware, software, network, and user-related issues.
  • Knowledge of network security, endpoint protection, firewalls, VPNs, and vulnerability management.
  • Experience with Active Directory, user access management, and system administration.
  • Familiarity with Microsoft 365 administration is an added advantage.
  • Understanding of backup, disaster recovery, and IT asset management.
  • Strong analytical and problem-solving skills with attention to detail.
  • Good communication and documentation skills.
  • Ability to work independently and collaboratively in a fast-paced environment.



Preferred Qualifications

  • Bachelor's degree in Information Technology, Computer Science, or a related field.
  • Certifications such as CompTIA A+, Network+, Security+, Microsoft, CCNA, or equivalent will be an added advantage.


Read more
company logo
Shariba Tasneem
Posted by Shariba Tasneem
Bengaluru (Bangalore)
1 - 3 yrs
₹7L - ₹9L / yr
ISO/IEC 27001:2005
skill iconAmazon Web Services (AWS)
Google Cloud Platform (GCP)
GRC

At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.


Learn more at www.shipthis.co


Role Overview

We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.


What You’ll be Doing


Security Operations

  • Monitor infrastructure, application, and security alerts and assist with incident investigation.
  • Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
  • Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
  • Track security issues and corrective actions through closure.

Vulnerability Management

  • Run and review application and infrastructure vulnerability scans.
  • Maintain a vulnerability register and coordinate remediation with engineering teams.
  • Support VAPT and penetration-testing exercises and validate closure of findings.
  • Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.

Compliance & Governance

  • Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
  • Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
  • Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
  • Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.

MDM & Endpoint Security

  • Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
  • Maintain device inventory and monitor endpoint compliance.
  • Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
  • Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
  • Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.

DevOps, CI/CD & Cloud

  • Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
  • Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
  • Automate repetitive deployment, infrastructure, security, and compliance tasks.
  • Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
  • Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.


Required Fundamentals

  • Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
  • Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
  • Strong troubleshooting, ownership, attention to detail, and willingness to learn.


Desired Qualifications

  • 1–2 years of experience with strong fundamentals are welcome.
  • Basic scripting knowledge in Python, Bash, or similar.
  • Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
  • Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.


We Welcome Candidates:

  • Who can join immediately
  • Female candidates returning to work after a career break are strongly encouraged.


We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.


Job Synopsys

Location: Bangalore

Job Type: Full-time, Permanent

Experience: 1-2 years

Industry: Software Product



Read more
company logo
Vasudha Srivastav
Posted by Vasudha Srivastav
Bengaluru (Bangalore)
2 - 4 yrs
Best in industry
Bug Bounty
Exploit Development
Agent Driven Pentesting
Reverse engineering
Penetration testing
+6 more

A BIT ABOUT US

Appknox is one of the top Mobile Application security companies recognized by Gartner and G2. A profitable B2B SaaS startup headquartered in Singapore & working from Bengaluru.

The primary goal of Appknox is to help businesses and mobile developers secure their mobile applications with a focus on delivery speed and high-quality security audits.

Appknox has helped secure mobile apps at Fortune 500 companies with major brands spread across regions like India, South-East Asia, Middle-East, US, and expanding rapidly. We have secured 300+ Enterprises globally.

We are a 65+ incredibly passionate team working to make an impact and helping some of the biggest companies globally. We work in a highly collaborative, very fast-paced work environment. If you have what it takes to be part of the team, we are excited and let’s speak further.



The Opportunity

To join the security team engaging with multiple clients, helping them with end to end security audits, also research about new topics and vulnerabilities to be added to the scanner, present it in conferences.


What An Ideal Candidate Would Look Like: 

  • Skills - Application Penetration Testing (Web, iOS and Android), experience with IoT testing, source code audits.
  • Technology Stack: AWS, GCP, Objective C, Java, Python
  • Responsibilities: Engage with clients for scoping call, perform security audits, remediation call with clients to patch the issues, research on new technologies/vulnerabilities


Minimum Requirements

  • 2-4+ years of experience in application security and vulnerability research
  • Strong foundation in mobile app security - Android or Ios
  • Proven track record of discovering and disclosing CVEs in mobile platforms or popular applications (provide - github/bug bounty profiles)
  • Strong understanding of exploit mitigations and proven ability to bypass them
  • Should be able to architect automated detection logic for new vulnerabilities and integrate them into our security products
  • Develop AI-driven agents to automate dynamic analysis
  • Should be able to Leverage AI/LLMs to augment Pentesting efforts
  • Ability to work independently in a fast-paced environment, balancing deep research with practical deliverables


Good to have Requirements

  • Understanding of AI/ML security risks


Responsibilities

  • Security assessment of web/mobile applications on various platforms
  • Focusing on Mobile Application Security Research for new vulnerabilities
  • Static and Dynamic Code Analysis
  • Develop and interpret security standards and guides
  • Automation of exploit development 
  • Understand and explain the results with impact on business and compliance status
  • Continuously learning and training on latest tools and technique


Work Expectations

Within 1 month

Training on processes, security workflows and develop understanding on internal tools.


Within 3 months

Actively contributing in exploit development and automation of it with the team.


Within 6 months

Expected to achieve Subject Matter Expert status on our core security products. We expect you to validate your findings against real-world conditions, with a strong emphasis on translating internal discoveries into actionable bug bounty submissions and earned CVEs to benchmark your impact against the external security community.


Within 1 Year

By the end of your first year, you will be expected to produce and submit a piece of novel, peer-reviewed security research. This deliverable must be of a quality suitable for top-tier industry conferences.


Personality traits we really admire

  • A confident and dynamic working persona, which can bring fun to the team, and a sense of humour, is an added advantage.
  • Great attitude to ask questions, learn and suggest process improvements.
  • Has attention to details and helps identify edge cases.
  • Highly motivated and coming up with fresh ideas and perspectives to help us move towards our goals faster.
  • Follow timelines and absolute commitment to deadlines.


Interview Process - would be team specific

  • Round 1- CTF round 
  • Round 2 -Profile Evaluation; HR
  • Round 3 -Technical Interview with security team members
  • Round 4 -Technical Interview with the Hiring Manager
  • Round 5 -Technical round with CTO
  • Round 6 -HR Round


Compensation

  • As per Industry Standards


Why Join Us

  • Freedom & Responsibility: If you are a person who enjoys challenging work & pushing your boundaries, then this is the right place for you. We appreciate new ideas & ownership as well as flexibility with working hours.
  • Great Salary & Equity: We keep up with the market standards & provide pay packages considering updated standards. Also as Appknox continues to grow, you’ll have a great opportunity to earn more & grow with us. Moreover, we also provide equity options for our top performers.
  • Holistic Growth: We foster a culture of continuous learning and take a much more holistic approach to train and develop our assets: the employees. We shall also support you all on that journey of yours.
  • Transparency: Being a part of a start-up is an amazing experience, one of the reasons being open communication & transparency at multiple levels. Working with Appknox will give you the opportunity to experience it all first-hand.


Read more
company logo
Vandana Saxena
Posted by Vandana Saxena
Pune, Bengaluru (Bangalore), Noida, Hyderabad, Chennai, trivendam, Chandigarh, Kolkata, Mumbai
5 - 8 yrs
₹12L - ₹18L / yr
Vulnerability assessment
Vulnerability management
Burp suite
Fortify
sonarqube
+2 more

Responsibilities

  • Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
  • Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
  • Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
  • Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
  • Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
  • Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
  • Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
  • Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
  • Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
  • Provide input into policies and standards related to application and cloud security controls.


Qualifications and Education Requirements

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
  • 5-7 years of relevant experience in application security and/or vulnerability management.
  • Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
  • Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
  • Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
  • Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
  • Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
  • Excellent documentation, communication, and stakeholder engagement skills.


Desired Skills

  • Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
  • Experience using the ServiceNow platform for vulnerability or incident tracking.
  • Proficiency in Azure cloud and Azure DevOps environments.
  • Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Read more
company logo
S Suriya Kumar
Posted by S Suriya Kumar
Remote only
10 - 17 yrs
₹9L - ₹50L / yr
Network Security

Role Overview

We are looking for an experienced Network Security Engineer to design, implement, maintain, and secure enterprise network infrastructure. The role requires a strong understanding of network security principles, hands-on experience with security technologies, and the ability to troubleshoot complex network and security issues.

The ideal candidate will work closely with network, infrastructure, cloud, application, and security teams to ensure secure, resilient, and highly available network environments. The candidate should be comfortable handling security incidents, performing root-cause analysis, implementing security controls, and contributing to continuous improvement of the organization's network security posture.


Key Responsibilities

  • Design, implement, configure, and maintain enterprise network security infrastructure.
  • Manage and support network security technologies including firewalls, VPNs, IDS/IPS, secure gateways, and network access controls.
  • Configure and maintain security policies, access rules, NAT, VPN tunnels, and related network security controls.
  • Monitor network traffic and security events to identify potential threats, anomalies, and unauthorized access.
  • Troubleshoot complex network connectivity and security-related issues and perform root-cause analysis.
  • Investigate and respond to network security incidents in coordination with security and infrastructure teams.
  • Review firewall and network security rules regularly and ensure they follow established security standards and business requirements.
  • Support secure connectivity across data centers, corporate networks, remote locations, cloud environments, and third-party networks.
  • Participate in network security assessments, vulnerability remediation, and security hardening activities.
  • Implement and maintain network segmentation and access-control mechanisms.
  • Work with internal teams to assess security requirements for new applications, infrastructure, and network changes.
  • Participate in change management, implementation, and post-change validation activities.
  • Maintain network security documentation, architecture diagrams, configurations, and operational procedures.
  • Contribute to security improvement initiatives, automation, standardization, and operational efficiency.
  • Work with vendors and technology partners for issue resolution, upgrades, and technical escalations.
  • Ensure network security operations align with organizational policies, industry standards, and compliance requirements.


Required Skills

  • Strong experience in network security engineering and enterprise networking.
  • Good understanding of TCP/IP, DNS, DHCP, HTTP/HTTPS, routing, switching, VLANs, and network protocols.
  • Hands-on experience with enterprise firewalls and security gateways.
  • Strong understanding of VPN technologies, IPsec, SSL/TLS, NAT, and access-control policies.
  • Experience with IDS/IPS, network monitoring, traffic analysis, and security event investigation.
  • Experience troubleshooting network and security issues across complex environments.
  • Good understanding of network security architecture, segmentation, and secure connectivity.
  • Experience with incident management, change management, and root-cause analysis.
  • Familiarity with security best practices, vulnerability management, and network hardening.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Good written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.


Preferred Skills

  • Experience with security technologies from vendors such as Palo Alto, Fortinet, Cisco, Check Point, or similar.
  • Exposure to cloud networking and cloud security across AWS, Azure, or GCP.
  • Knowledge of Zero Trust, SASE, SD-WAN, or network access control concepts.
  • Experience with security monitoring/SIEM platforms.
  • Exposure to scripting or automation using Python, PowerShell, or similar technologies.
  • Relevant certifications such as CCNA/CCNP Security, PCNSE, Fortinet certifications, or equivalent are an advantage.


Key Competencies

  • Network Security Engineering
  • Enterprise Network Troubleshooting
  • Firewall & VPN Management
  • Security Incident Handling
  • Network Monitoring & Analysis
  • Security Hardening
  • Root-Cause Analysis
  • Risk & Vulnerability Awareness
  • Change & Configuration Management
  • Stakeholder Communication
  • Problem Solving
  • Documentation & Process Discipline
Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos