Cutshort logo
For Employers
Appknox logo
Sr. Security Researcher
Sr. Security Researcher

Sr. Security Researcher at Appknox · Bengaluru (Bangalore) · 2 - 4 years · Profitable · Posted 28 Sep 2026

Appknox's logo

Sr. Security Researcher

Vasudha Srivastav's profile picture
Posted by Vasudha Srivastav
2 - 4 yrs
Best in industry
Bengaluru (Bangalore)
Skills
Bug Bounty
Exploit Development
Agent Driven Pentesting
Reverse engineering
Penetration testing
IT security
Software security
Mobile security
skill iconAndroid Testing
iOS Testing
Application Security

A BIT ABOUT US

Appknox is one of the top Mobile Application security companies recognized by Gartner and G2. A profitable B2B SaaS startup headquartered in Singapore & working from Bengaluru.

The primary goal of Appknox is to help businesses and mobile developers secure their mobile applications with a focus on delivery speed and high-quality security audits.

Appknox has helped secure mobile apps at Fortune 500 companies with major brands spread across regions like India, South-East Asia, Middle-East, US, and expanding rapidly. We have secured 300+ Enterprises globally.

We are a 65+ incredibly passionate team working to make an impact and helping some of the biggest companies globally. We work in a highly collaborative, very fast-paced work environment. If you have what it takes to be part of the team, we are excited and let’s speak further.



The Opportunity

To join the security team engaging with multiple clients, helping them with end to end security audits, also research about new topics and vulnerabilities to be added to the scanner, present it in conferences.


What An Ideal Candidate Would Look Like: 

  • Skills - Application Penetration Testing (Web, iOS and Android), experience with IoT testing, source code audits.
  • Technology Stack: AWS, GCP, Objective C, Java, Python
  • Responsibilities: Engage with clients for scoping call, perform security audits, remediation call with clients to patch the issues, research on new technologies/vulnerabilities


Minimum Requirements

  • 2-4+ years of experience in application security and vulnerability research
  • Strong foundation in mobile app security - Android or Ios
  • Proven track record of discovering and disclosing CVEs in mobile platforms or popular applications (provide - github/bug bounty profiles)
  • Strong understanding of exploit mitigations and proven ability to bypass them
  • Should be able to architect automated detection logic for new vulnerabilities and integrate them into our security products
  • Develop AI-driven agents to automate dynamic analysis
  • Should be able to Leverage AI/LLMs to augment Pentesting efforts
  • Ability to work independently in a fast-paced environment, balancing deep research with practical deliverables


Good to have Requirements

  • Understanding of AI/ML security risks


Responsibilities

  • Security assessment of web/mobile applications on various platforms
  • Focusing on Mobile Application Security Research for new vulnerabilities
  • Static and Dynamic Code Analysis
  • Develop and interpret security standards and guides
  • Automation of exploit development 
  • Understand and explain the results with impact on business and compliance status
  • Continuously learning and training on latest tools and technique


Work Expectations

Within 1 month

Training on processes, security workflows and develop understanding on internal tools.


Within 3 months

Actively contributing in exploit development and automation of it with the team.


Within 6 months

Expected to achieve Subject Matter Expert status on our core security products. We expect you to validate your findings against real-world conditions, with a strong emphasis on translating internal discoveries into actionable bug bounty submissions and earned CVEs to benchmark your impact against the external security community.


Within 1 Year

By the end of your first year, you will be expected to produce and submit a piece of novel, peer-reviewed security research. This deliverable must be of a quality suitable for top-tier industry conferences.


Personality traits we really admire

  • A confident and dynamic working persona, which can bring fun to the team, and a sense of humour, is an added advantage.
  • Great attitude to ask questions, learn and suggest process improvements.
  • Has attention to details and helps identify edge cases.
  • Highly motivated and coming up with fresh ideas and perspectives to help us move towards our goals faster.
  • Follow timelines and absolute commitment to deadlines.


Interview Process - would be team specific

  • Round 1- CTF round 
  • Round 2 -Profile Evaluation; HR
  • Round 3 -Technical Interview with security team members
  • Round 4 -Technical Interview with the Hiring Manager
  • Round 5 -Technical round with CTO
  • Round 6 -HR Round


Compensation

  • As per Industry Standards


Why Join Us

  • Freedom & Responsibility: If you are a person who enjoys challenging work & pushing your boundaries, then this is the right place for you. We appreciate new ideas & ownership as well as flexibility with working hours.
  • Great Salary & Equity: We keep up with the market standards & provide pay packages considering updated standards. Also as Appknox continues to grow, you’ll have a great opportunity to earn more & grow with us. Moreover, we also provide equity options for our top performers.
  • Holistic Growth: We foster a culture of continuous learning and take a much more holistic approach to train and develop our assets: the employees. We shall also support you all on that journey of yours.
  • Transparency: Being a part of a start-up is an amazing experience, one of the reasons being open communication & transparency at multiple levels. Working with Appknox will give you the opportunity to experience it all first-hand.


Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

About Appknox

Founded :
2014
Type :
Product
Size :
20-100
Stage :
Profitable

About

Appknox, a leading mobile app security solution HQ in Singapore & Bangalore was founded by Harshit Agarwal and Subho Halder.


Since its inception, Appknox has become one of the go-to security solutions with the most powerful plug-and-play security platform, enabling security researchers, developers, and enterprises to build safe and secure mobile ecosystems using a system-plus human approach.


Appknox offers VA+PT solutions ( Vulnerability Assessment + Penetration Testing ) that provide end-to-end mobile application security and testing strategies to Fortune 500, SMB and Large Enterprises Globally helping businesses and mobile developers make their mobile apps more secure, thus not only enhancing protection for their customers but also for their own brand. 


During the course of 9 years, Appknox has scaled up to work with some major brands in India, South-East Asia, Middle-East, Japan, and the US and has also successfully enabled some of the top government agencies with its On-Premise deployments & compliance testing. Appknox helps 500+ Enterprises which includes 20+ Fortune 1000 and ministries/regulators across 10+ countries and some of the top banks across 20+ countries.


A champion of Value SaaS, with its customer and security-first approach Appknox has won many awards and recognitions from G2, and Gartner and is one of the top mobile app security vendors in its 2021 Application security Hype Cycle report. 


Our forward-leaning, pioneering spirit is backed by SeedPlus, JFDI Asia, Microsoft Ventures, and Cisco Launchpad and a legacy of expertise that began at the dawn of 2014.

Read more

Tech stack

skill iconPython
Ember.js
skill iconDjango
skill iconRust
skill iconGo Programming (Golang)
Google Cloud Platform (GCP)
skill iconAmazon Web Services (AWS)
skill iconDocker
VMWARE ESXi
skill iconJavascript
WASM
Cyber Security
Reverse engineering
skill iconAndroid Testing
iOS Testing

Company video

Appknox's video section
Appknox's video section

Photos

Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures
Company featured pictures

Connect with the team

Profile picture
Subho Halder
Profile picture
Harshit Agarwal
Profile picture
Abhinav Vasisth
Profile picture
Raghunandan J
Profile picture
Siddharth Saxena
Profile picture
Suresh Kumar

Company social profiles

bloglinkedintwitterfacebook

Similar jobs (10)

company logo
amit verma
Posted by amit verma
Remote only
5 - 15 yrs
₹30L - ₹70L / yr
Cyber Security
Web application security
Penetration testing
skill iconPython
skill iconJava
+2 more

Cybersecurity Engineer – AI Training Project


About the Opportunity

We’re looking for experienced Cybersecurity Engineers to contribute technical expertise to a customer project focused on improving the capabilities of next-generation AI systems.

In this role, you’ll use your real-world experience in cybersecurity, software engineering, vulnerability assessment, and secure development to create high-quality technical inputs that help AI systems better understand, debug, secure, and reason about complex software.


What You’ll Do

  • Analyze, debug, and resolve software bugs, vulnerabilities, and security issues across complex codebases.
  • Review source code and identify potential security weaknesses, vulnerabilities, and attack vectors.
  • Perform security assessments, vulnerability assessments, penetration testing, and codebase audits.
  • Develop and modify software using languages such as Python, Java, Rust, Go, C++, or TypeScript.
  • Implement new features and fix existing functionality while maintaining strong security and engineering standards.
  • Refactor legacy code to improve security, maintainability, reliability, and performance.
  • Work on backend systems and help optimize applications for scalability, performance, and security.
  • Analyze real-world security scenarios and translate your expertise into high-quality technical examples and problem-solving tasks.
  • Document technical findings, vulnerabilities, debugging approaches, and recommended solutions.
  • Provide domain expertise that helps improve how AI systems reason about software engineering and cybersecurity problems.


What We’re Looking For

  • Strong professional experience in Cybersecurity / Application Security / Product Security / DevSecOps / Penetration Testing / Vulnerability Management.
  • Strong programming experience in one or more of:
  • Python
  • Java
  • Rust
  • Go
  • C++
  • TypeScript
  • Proven experience with debugging, troubleshooting, and fixing complex software issues.
  • Hands-on experience with penetration testing, vulnerability assessment, security auditing, or application security.
  • Understanding of secure software development practices and modern security threats.
  • Strong knowledge of data structures, algorithms, software architecture, and code quality.
  • Ability to review unfamiliar codebases and quickly understand how systems work.
  • Strong written communication and the ability to explain complex technical findings clearly.


Nice to Have

  • Experience with OWASP, API security, cloud security, DevSecOps, or threat modeling.
  • Experience performing security assessments on production applications or enterprise systems.
  • Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, SAST/DAST tools, or vulnerability scanners.
  • Contributions to open-source security or software projects.
  • Experience working with AI/ML systems, LLMs, data annotation, or AI training projects.
  • Relevant security certifications such as OSCP, OSWE, CEH, CISSP, Security+, or equivalent practical experience.


Engagement

  • Role: Cybersecurity Engineer
  • Work: Remote(Contract)
  • Experience: Mid-level to Senior
  • Programming: Required
  • Cybersecurity expertise: Required


Why Join?

This is an opportunity to apply your existing cybersecurity expertise to an emerging area of technology. Your practical experience debugging software, identifying vulnerabilities, securing applications, and solving complex engineering problems will directly contribute to improving the capabilities of next-generation AI systems.


If you enjoy breaking down complex technical problems, finding vulnerabilities, fixing software, and thinking deeply about how systems work, this project could be a strong fit.

Read more
company logo
Vandana Saxena
Posted by Vandana Saxena
Pune, Bengaluru (Bangalore), Noida, Hyderabad, Chennai, trivendam, Chandigarh, Kolkata, Mumbai
5 - 8 yrs
₹12L - ₹18L / yr
Vulnerability assessment
Vulnerability management
Burp suite
Fortify
sonarqube
+2 more

Responsibilities

  • Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
  • Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
  • Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
  • Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
  • Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
  • Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
  • Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
  • Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
  • Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
  • Provide input into policies and standards related to application and cloud security controls.


Qualifications and Education Requirements

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
  • 5-7 years of relevant experience in application security and/or vulnerability management.
  • Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
  • Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
  • Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
  • Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
  • Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
  • Excellent documentation, communication, and stakeholder engagement skills.


Desired Skills

  • Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
  • Experience using the ServiceNow platform for vulnerability or incident tracking.
  • Proficiency in Azure cloud and Azure DevOps environments.
  • Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Read more
company logo
Sandhiya M
Posted by Sandhiya M
Chennai
1 - 5 yrs
₹2L - ₹8L / yr
ISO9001
ISO27001
Security Information and Event Management (SIEM)
Cyber Security
skill iconAmazon Web Services (AWS)
+4 more

Hi Folks, we are currently Hiring for Security Engineer.

Gemini said


Hiring: Security Engineer

Company : Pentabay Softwares

Location : Anna salai, Mount Road

Mode: Fulltime


Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.


The Mission

You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.


Key Responsibilities


Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.

Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.

DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.

Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.

Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.


What You Bring


Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).

Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).

Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.

Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).

Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.

Auditing space like ISO27001 , ISO9001 prefered


Why Pentabay?

At Pentabay, we offer more than just a job; we offer a security-first engineering culture.

Growth: A dedicated learning budget for certifications and conferences.

Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.


Send resumes to : sandhiya.m at pentabay.com

Read more
company logo
Neha Daka
Posted by Neha Daka
Indore
4 - 8 yrs
₹3.5L - ₹10L / yr
ApplicationSecurity,Cybersecurity, DevSecOps,CI/CD
DAST
SAST
Cloud Computing

Job Title: AppSec / AI Security Engineer


Employment Type: Full-time/ Permanent

Location: Indore (Work from Office)


About the Role

We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.

If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.

 

Key Responsibilities

  • Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
  • Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
  • Develop structured code review workflows incorporating specifications, scan results, and code provenance.
  • Optimize security scanning tools to reduce false positives and drive developer adoption.
  • Investigate and manage security findings using established remediation and documentation processes.
  • Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
  • Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.


Required Skills & Experience

  • Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
  • Experience implementing automated security scanning and enforcement — not just operating existing tools.
  • Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
  • Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
  • Ability to design, build, and own security automation and governance solutions from the ground up.
  • Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
  • Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
  • Strong analytical mindset and ability to independently assess security risk across internal and external codebases.


Preferred Qualifications

  • ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
  • Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
  • Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
  • AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
  • Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
  • Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).


About Company:

Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.

 

For more info, please visit our website:  https://5exceptions.com

Read more
company logo
Bhattacharjee Akash
Posted by Bhattacharjee Akash
Bengaluru (Bangalore), Hyderabad, Pune, Kolkata, Chennai, Mumbai
1 - 10 yrs
₹4L - ₹30L / yr
Security Information and Event Management (SIEM)
Cyber Security
Burp suite
Metasploit
Network Security

We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.


Responsibilities

  • Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
  • Monitor and respond to security events using SIEM tools as part of SOC operations
  • Test application security using Burp Suite and similar tools
  • Support ISO 27001 compliance, audits and security policies
  • Harden network infrastructure, firewalls and access controls
  • Document findings and track fixes with engineering teams


Requirements

  • 1+ years of experience in VAPT, SOC or security engineering
  • Hands-on experience with Burp Suite and SIEM tools
  • Knowledge of the OWASP Top 10 and network security fundamentals
  • Exposure to ISO 27001 or similar frameworks
  • Certifications such as CEH, OSCP or CompTIA Security+ are a plus
Read more
company logo
Mayank Choudhary
Posted by Mayank Choudhary
icon

The recruiter has not been active on this job recently. You may apply but please expect a delayed response.

Bengaluru (Bangalore)
3 - 7 yrs
₹40L - ₹45L / yr
Cloud security

Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles

2

Mandatory (Experience 1) – Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience,

3

Mandatory (Experience 2) – Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.

4

Mandatory (Experience 3) – Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.

5

Mandatory (Experience 4) – Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.

6

Mandatory (Experience 5) – Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.

7

Mandatory (Experience 6) – Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.

8

Preferred (Experience 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.

Read more
company logo
Aakanksha Jain
Posted by Aakanksha Jain
Gurugram
2 - 3 yrs
₹10L - ₹15L / yr
Microservices
skill iconPython
Google Cloud Platform (GCP)
Windows Azure
skill iconAmazon Web Services (AWS)

About StrideOne:

StrideOne is a unified tech-enabled financial platform and NBFC focused on enabling MSMEs and SMEs through structured credit solutions, receivables financing, and receivables management. We are designed to simplify access to capital, improve cash flow visibility, and support risk-aware financial decision-making for growing businesses across industries. With a steadily growing disbursement footprint, an expanding anchor network, and established partnerships with multiple lending institutions, StrideOne is entering its next phase of growth. The organisation is building a financial ecosystem that combines lending, receivables management, and data-driven workflows, positioning itself to scale sustainably while maintaining strong governance, portfolio quality, and operational discipline.


Key Responsibilities:

Architect & Design: Design and implement highly scalable, available, and secure web applications. You’ll be responsible for designing multi-tenant architectures, ensuring data isolation, and leveraging modern cloud infrastructure to ensure the platform scales efficiently.


Security Focused Development: Develop and enforce secure coding standards and best practices for cloud-based applications and APIs. Conduct regular code reviews with a focus on security vulnerabilities.


API & Microservices Design: Design and implement secure, scalable, and maintainable APIs and microservices that integrate seamlessly with the platform. Ensure the use of best practices for service discovery, communication, and fault tolerance.


Performance Optimization: Identify and resolve performance bottlenecks in the application and infrastructure, ensuring scalability and responsiveness under varying load conditions.


Compliance & Regulatory Requirements: Ensure that applications comply with industry standards and regulations (e.g., GDPR, HIPAA, SOC 2, ISO 27001). Assist with audits and security certifications.


Collaboration & Leadership: Work closely with product managers, QA engineers, and other stakeholders to define and implement new features and improvements. Collaborate with the infrastructure team to ensure seamless deployment and scaling of the application. Also mentor and guide junior engineers on secure coding practices and development techniques.


Security Automation & Monitoring: Implement logging, monitoring, and alerting systems to continuously assess the security posture of the application. Stay up to date with the latest security trends, vulnerabilities, and best practices. Promote security awareness and training within the engineering team.


Qualifications:

Experience: 2+ years of experience in software engineering, with a focus on developing secure and scalable multi-tenant web applications with customer data isolation and tenant-specific configurations.


Tech Stack: Proficiency in modern web technologies (Python is a plus), relational databases, and cloud platforms (AWS, Azure, GCP).


Microservices Architecture: Strong experience designing and developing microservices-based architectures. Familiarity with service discovery, API Gateway, inter-service communication, and distributed systems principles.


Scalability & Performance: Experience with designing highly scalable and performant systems. Knowledge of caching, database sharding, partitioning, and high-throughput systems.


Security Expertise: Understanding of cloud security principles, cryptography, identity and access management (IAM), and secure coding practices.


Analytical Skills: Strong problem-solving skills with the ability to analyze complex security issues and provide practical solutions.


Soft Skills: Strong communication skills with the ability to explain complex technical concepts to non-technical stakeholders. Experience working in agile, collaborative environments.

Read more
company logo
Shariba Tasneem
Posted by Shariba Tasneem
Bengaluru (Bangalore)
1 - 3 yrs
₹7L - ₹9L / yr
ISO/IEC 27001:2005
skill iconAmazon Web Services (AWS)
Google Cloud Platform (GCP)
GRC

At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.


Learn more at www.shipthis.co


Role Overview

We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.


What You’ll be Doing


Security Operations

  • Monitor infrastructure, application, and security alerts and assist with incident investigation.
  • Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
  • Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
  • Track security issues and corrective actions through closure.

Vulnerability Management

  • Run and review application and infrastructure vulnerability scans.
  • Maintain a vulnerability register and coordinate remediation with engineering teams.
  • Support VAPT and penetration-testing exercises and validate closure of findings.
  • Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.

Compliance & Governance

  • Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
  • Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
  • Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
  • Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.

MDM & Endpoint Security

  • Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
  • Maintain device inventory and monitor endpoint compliance.
  • Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
  • Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
  • Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.

DevOps, CI/CD & Cloud

  • Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
  • Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
  • Automate repetitive deployment, infrastructure, security, and compliance tasks.
  • Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
  • Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.


Required Fundamentals

  • Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
  • Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
  • Strong troubleshooting, ownership, attention to detail, and willingness to learn.


Desired Qualifications

  • 1–2 years of experience with strong fundamentals are welcome.
  • Basic scripting knowledge in Python, Bash, or similar.
  • Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
  • Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.


We Welcome Candidates:

  • Who can join immediately
  • Female candidates returning to work after a career break are strongly encouraged.


We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.


Job Synopsys

Location: Bangalore

Job Type: Full-time, Permanent

Experience: 1-2 years

Industry: Software Product



Read more
MNC
MNC
Agency job
via by Lakshmi Priya
Bengaluru (Bangalore)
7 - 15 yrs
₹25L - ₹30L / yr
Artificial Intelligence (AI)
Generative AI
Large Language Models (LLM)
AWS Bedrock
  • Develop python-based automation for large data sets data analysis for vulnerability management reporting.
  • Leverage machine learning in the process as required.
  • Develop Prompts to automate test data extraction process from databases.
  • Provide technical expertise through a hands-on approach to teams and projects.
  • Experience with one or more general purpose programming languages including but not limited to: Java, Python, R or equivalent
  • Experience and knowledge in designing, building, and deploying multi layered application Infrastructure involving On-premises & AWS Cloud platform using services BedRock LLM models.
  • Handle design, definition, planning and development.
  • 100% adherence to architectural and development best practices including the use of standard architectures, proper use of code management, document design and design artifacts and conduct design/code reviews.
  • Create optimization plans to innovate, shift-left, and mitigate gaps.
  • Apply cloud concepts and capabilities to deliver testing for cloud-hosted apps.
  • Report succinct testing goals and results to the leadership.
  • Train and educate various teams on SV ideas and expectations.
  • Expand responsibilities to drive test data, test environment, and service virtualization strategies.
Read more
company logo
Manind Gupta
Posted by Manind Gupta
Jaipur
1 - 4 yrs
₹2L - ₹8L / yr
Cyber Security
cyber

Cyber Security Expert


We are seeking a highly skilled Cyber Security Expert with strong expertise in AI-driven

security tools and ethical hacking techniques. The ideal candidate will safeguard our digital

infrastructure, proactively identify vulnerabilities, and design intelligent defense mechanisms

against evolving cyber threats.

Key Responsibilities

• Threat Analysis: Identify, assess, and mitigate potential risks across systems and

networks.

• AI Security Tools: Deploy and manage AI-based solutions for intrusion detection,

anomaly monitoring, and predictive threat modelling.

• Ethical Hacking: Conduct penetration testing, simulate cyber-attacks, and recommend

remediation strategies.

• Incident Response: Lead investigations, contain breaches, and implement recovery

measures.

• Compliance & Governance: Ensure adherence to data protection laws, industry

standards, and organizational policies.

• Training & Awareness: Educate employees on best practices and emerging threats.


Required Skills & Qualifications

• Proven hands-on experience with AI-powered security platforms (e.g., SIEM, SOAR,

ML-based anomaly detection).

• Strong knowledge of ethical hacking tools (Metasploit, Burp Suite, Kali Linux, etc.).

• Expertise in network security, firewalls, IDS/IPS, and endpoint protection.

• Familiarity with cloud security (AWS, cloud platform).

• Proficiency in scripting languages (Python, Bash, PowerShell) for automation.

• Solid understanding of cryptography, authentication protocols, and secure coding

practices.



Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos