Senior Security Engineer
NextWebi IT Solutions Pvt. Ltd. · Bangalore, India
Job Description
We are looking for a Senior Security Engineer to join our Security Team and lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives. This role sits at the intersection of traditional application security and emerging AI security threats.
Key Responsibilities
Penetration Testing & Offensive Security
• Lead end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure..
• Design and execute red-team exercises simulating real-world attacks..
• Perform threat modelling for new product features and architectures..
• Develop custom exploits, scripts, and security tools..
• Prepare clear and actionable penetration testing reports..
• Manage third-party penetration testing vendors and responsible disclosure programs..
AI & LLM Security
• Research and execute attacks against AI/LLM-powered systems, including prompt injection, jailbreaks, and indirect prompt injection..
• Assess risks related to data exfiltration through model responses..
• Assess security risks inModel Context Protocol (MCP)deployments, including tool-call boundaries, context poisoning, and privilege escalation..
• Build an internal threat library for AI attack patterns..
• Develop and maintain red-teaming playbooks for LLM-based features..
• Work with ML and Product teams to integrate security into the AI development lifecycle..
DevSecOps
• Integrate security controls into CI/CD pipelines, includingSAST, DAST, SCA, secret scanning, and container scanning..
• Define and enforce secure coding standards and security review gates..
• Drive security automation across engineering teams..
Risk Assessment & Governance
• Assess and prioritize security risks using frameworks such asCVSS, DREAD, or FAIR..
• Maintain risk registers and track remediation progress..
• Evaluate risks from third-party vendors, integrations, and open-source dependencies..
• Support security audits, gap assessments, policies, standards, and exception processes..
• Communicate security findings and business impact to technical and non-technical stakeholders..
Required Skills & Experience
• 4+ years of experience in Security Engineering, with at least2 years of hands-on penetration testing experience..
• Strong experience inweb application and API penetration testing..
• Good knowledge of OWASP Top 10, business logic vulnerabilities, and authentication/authorization bypasses..
• Hands-on experience withAI/LLM security, including prompt injection, model manipulation, or MCP security assessments..
• Strong scripting skills inPython, Go, or Bash..
• Experience with cloud security acrossAWS, GCP, or Azure..
• Knowledge of cloud misconfigurations, IAM abuse, and lateral movement..
• Experience integratingSAST/DAST/SCAtools into CI/CD pipelines..
• Experience conducting risk assessments and communicating findings effectively..
Good to Have
• Bug bounty experience or CVE publications..
• Experience with agentic AI frameworks such asLangChain, AutoGPT, or Claude Agents..
• Experience with red-team tools and security automation..
• Security certifications such asOSCP, OSWE, OSEP, CEH, or equivalent..
Details
| Company | NextWebi IT Solutions Pvt. Ltd. |
| Location | Bangalore, India |
| Type | FULL TIME |
| Niche | tech |
