NewAI impact in application development 2026 guide Explore Now

Recruiters' Notice : For any inquiries regarding the recruitment process or to connect with our Talent Acquisition team, please email us at hr@nextwebi.com. Phone calls will not be entertained.

Note for Job Seekers : For job-related queries, please apply only through the job application form provided on the respective job description page.
For any other communication, contact hr@nextwebi.com.
Phone inquiries will not be addressed.

Senior SecOps Engineer

  • 4+ years
  • Senior SecOps Engineer
  • IT Services / Software Company
  • Security
  • Full time
  • DevSecOps Engineer
  • Any Graduate
  • Bangalore

About the Role

We are looking for a skilled Senior SecOps Engineer to join our Security team. The ideal candidate will take ownership of offensive security initiatives, lead penetration testing activities, and contribute to building a strong security-first culture across engineering teams.

This role combines traditional Application Security (AppSec) with emerging AI security challenges. The candidate will work on identifying, assessing, and addressing security risks across applications, cloud environments, APIs, and AI/LLM-powered systems.

Key Responsibilities

Penetration Testing

  • Lead and execute end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure.
  • Design and conduct red team exercises that simulate real-world adversarial scenarios.
  • Perform threat modeling for new product features and architectures before deployment.
  • Develop custom exploits, scripts, and tools to improve testing coverage and repeatability.
  • Prepare clear and actionable penetration testing reports for engineering teams and management.
  • Coordinate with third-party penetration testing vendors and support responsible disclosure programs.

AI & LLM Security

  • Research and perform security testing against AI/LLM-powered systems, including prompt injection, jailbreaks, indirect prompt injection through tool outputs, and data exfiltration through model responses.
  • Assess security risks in Model Context Protocol (MCP) deployments, including tool call boundaries, context poisoning vectors, and privilege escalation through agentic workflows.
  • Build and maintain an internal threat library for AI attack patterns and contribute to red-teaming playbooks for LLM features.
  • Work closely with ML and product teams to integrate security throughout the AI feature development lifecycle.

DevSecOps

  • Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secret scanning, and container scanning.
  • Define and enforce secure coding standards and security review processes across development teams.
  • Drive security automation initiatives to help engineering teams maintain development speed while reducing critical security vulnerabilities.

Risk Assessment

  • Assess and prioritize security risks across the organization using frameworks such as CVSS, DREAD, or FAIR.
  • Maintain and manage a risk register, track remediation progress, and communicate the overall risk posture to relevant stakeholders.
  • Evaluate security risks associated with third-party vendors, integrations, and open-source dependencies.
  • Assess and communicate the business impact of vulnerabilities to support effective remediation prioritization.

Compliance & Governance

  • Assist with security audits and gap assessments.
  • Support the development and maintenance of security policies, standards, and exception processes.

Required Skills & Experience

  • 4+ years of experience in Security Engineering, including at least 2 years of hands-on experience in Penetration Testing.
  • Demonstrated experience with AI/LLM security, including prompt injection, model manipulation, or MCP security assessments.
  • Strong expertise in web application and API penetration testing, including OWASP Top 10, business logic flaws, and authentication bypasses.
  • Strong scripting skills in Python, Go, or Bash for developing custom security tools and automation.
  • Experience with cloud security across AWS, GCP, or Azure, including misconfigurations, IAM abuse, and lateral movement.
  • Familiarity with CI/CD security tools and integrating SAST, DAST, and SCA into development pipelines.
  • Experience in conducting risk assessments and communicating security findings to both technical and non-technical stakeholders.

Good to Have

  • Bug bounty experience or CVE publications.
  • Experience with agentic AI frameworks such as LangChain, AutoGPT, or Claude Agents from a security testing or attacker's perspective.
  • Knowledge of compliance and security frameworks such as SOC 2, ISO 27001, and PCI-DSS.

Apply For This Job

Only .pdf, .docx, .doc, .png, .jpeg, .jpg files are accepted
Only .png, .jpeg,.jpg, files are accepted