NewAI impact in application development 2026 guide Explore Now

Recruiters' Notice : For any inquiries regarding the recruitment process or to connect with our Talent Acquisition team, please email us at hr@nextwebi.com. Phone calls will not be entertained.

Note for Job Seekers : For job-related queries, please apply only through the job application form provided on the respective job description page.
For any other communication, contact hr@nextwebi.com.
Phone inquiries will not be addressed.

Senior Security Engineer

  • 4
  • Senior Security Engineer
  • Full time
  • Any
  • Bangalore

We are looking for a Senior Security Engineer to join our Security Team and lead offensive security, penetration testing, AI/LLM security, and DevSecOps initiatives. This role sits at the intersection of traditional application security and emerging AI security threats.

Key Responsibilities

Penetration Testing & Offensive Security

  • Lead end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure.
  • Design and execute red-team exercises simulating real-world attacks.
  • Perform threat modelling for new product features and architectures.
  • Develop custom exploits, scripts, and security tools.
  • Prepare clear and actionable penetration testing reports.
  • Manage third-party penetration testing vendors and responsible disclosure programs.

AI & LLM Security

  • Research and execute attacks against AI/LLM-powered systems, including prompt injection, jailbreaks, and indirect prompt injection.
  • Assess risks related to data exfiltration through model responses.
  • Assess security risks in Model Context Protocol (MCP) deployments, including tool-call boundaries, context poisoning, and privilege escalation.
  • Build an internal threat library for AI attack patterns.
  • Develop and maintain red-teaming playbooks for LLM-based features.
  • Work with ML and Product teams to integrate security into the AI development lifecycle.

DevSecOps

  • Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secret scanning, and container scanning.
  • Define and enforce secure coding standards and security review gates.
  • Drive security automation across engineering teams.

Risk Assessment & Governance

  • Assess and prioritize security risks using frameworks such as CVSS, DREAD, or FAIR.
  • Maintain risk registers and track remediation progress.
  • Evaluate risks from third-party vendors, integrations, and open-source dependencies.
  • Support security audits, gap assessments, policies, standards, and exception processes.
  • Communicate security findings and business impact to technical and non-technical stakeholders.

Required Skills & Experience

  • 4+ years of experience in Security Engineering, with at least 2 years of hands-on penetration testing experience.
  • Strong experience in web application and API penetration testing.
  • Good knowledge of OWASP Top 10, business logic vulnerabilities, and authentication/authorization bypasses.
  • Hands-on experience with AI/LLM security, including prompt injection, model manipulation, or MCP security assessments.
  • Strong scripting skills in Python, Go, or Bash.
  • Experience with cloud security across AWS, GCP, or Azure.
  • Knowledge of cloud misconfigurations, IAM abuse, and lateral movement.
  • Experience integrating SAST/DAST/SCA tools into CI/CD pipelines.
  • Experience conducting risk assessments and communicating findings effectively.

Good to Have

  • Bug bounty experience or CVE publications.
  • Experience with agentic AI frameworks such as LangChain, AutoGPT, or Claude Agents.
  • Experience with red-team tools and security automation.
  • Security certifications such as OSCP, OSWE, OSEP, CEH, or equivalent.

Apply For This Job

Only .pdf, .docx, .doc, .png, .jpeg, .jpg files are accepted
Only .png, .jpeg,.jpg, files are accepted