S

Senior Security Engineer

Smartstream Limited Bengaluru, Karnataka, India

Financial Services · 1,001-5,000 employees

7 h ago
Remote security Senior (5-10 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Security Engineer will lead complex security engineering tasks, including LLM-assisted code scanning, adversarial AI simulations, and threat-led penetration testing. They will also act as a technical authority for embedded security teams, mentor developers, and drive remediation through the vulnerability backlog.

What they look for

Application Security Penetration Testing OWASP Top 10 SANS Top 25 SAST DAST SCA Variant Analysis Code Review Threat Modelling Cryptography Secret Scanning Java Python LLM Security AI Security

Requirements

Candidates must have 7+ years of experience in application and product security, with strong proficiency in offensive and defensive security practices. A solid programming background in languages such as Java, Python, or Go, along with experience in SAST/DAST/SCA at scale, is required.

Full description

As a Senior Security Engineer at Smartstream, you will join our Security Engineering Centre of Excellence and serve as a senior technical member across the entire Security Engineering function. You'll be the escalation point for embedded Security Engineers and Security Champions on the most complex problems - novel vulnerability classes, adversarial-AI scenarios, LLM-driven code-scan findings, and regulator-mandated threat-led penetration tests.

This is a hands-on, deeply technical individual-contributor role. You will write code, build tooling, perform tool integrations, run scans across a large enterprise codebase, mentor peers, and help shape how Smartstream uses AI inside the Secure SDLC.

You will work upstream of the VulnOps function, which owns the unified vulnerability backlog and remediation pipeline. Your focus is on original analysis, novel vulnerability classes, adversarial AI, complex penetration testing, variant analysis, and technical mentoring - findings you produce or validate flow into the VulnOps backlog for tracked closure under SLA.

•      LLM-based code scanning. Own and operate LLM-assisted code scanning across the Smartstream product portfolio. Tune prompts and pipelines, triage false positives, validate and demonstrate exploitability of findings where necessary, and drive remediation through the VulnOps backlog in partnership with engineering teams.

•      SAST/DAST escalation support. Act as the technical authority for embedded Security Engineers and developers on hard SAST and DAST findings, exploitability assessment, fix design, false-positives elimination, and pattern publication.

•      Adversarial AI & blue team. Run the in-house adversarial-AI simulation platform and blue-team activities. Manage outsourced red-team engagements and route findings into the VulnOps backlog.

•      DORA TLPT technical lead. Provide the technical lead during DORA Article 26 threat-led penetration tests when financial-institution customers pull Smartstream into scope.

•      Variant analysis. Lead variant analysis whenever a Critical/High finding is confirmed - identify similar attack vectors across the codebase, produce engineering-grade remediation guidance, and feed the resulting issue set into VulnOps for tracked closure.

•      Internal pen testing. Lead internal web-application pen testing (OWASP Top 10, SANS Top 25). Scope and sign off release pen tests; manage outsourced pen-test engagements jointly with the Security Engineering Manager. Findings flow into the VulnOps backlog.

•      Cryptography & Secrets Management Provide guidance on approved cryptographic libraries, TLS, key management, and secrets handling practices. Partner with engineering teams to ensure secure implementation across products

•      Supply-chain & secret-scanning advisory. Set the technical strategy for SBOM, supply-chain scanning, and secret-scanning detection - what to scan, how to interpret reachability, how to triage high-impact dependency CVEs, and which detection rules to use. Operational pipeline ownership sits with VulnOps; the Senior SE owns the technical part of it.

•      Mentoring & enablement. Lead the Security Champions mentoring programme. Run developer security training workshops. Be the escalation path for embedded SEs on novel findings.

•      Culture. Evangelise a security-first culture across engineering - code reviews, design reviews, brown bags, internal comms.

•      Customer-facing pen tests. Support annual customer-driven penetration tests of Smartstream products.

Required qualifications

•      7+ years in application / product security, including hands-on offensive (pen testing) and defensive (secure SDLC, code review) work.

•      Strong programming background in at least two of: Java, Python, JavaScript/TypeScript, Go, C#.

•      Demonstrable experience running SAST/DAST/SCA at scale and triaging output with low false-positive rates.

•      Hands-on with modern static-analysis variant-analysis tooling.

•      Deep familiarity with OWASP Top 10, SANS Top 25, ASVS, and modern web-app attack patterns.

•      Experience operating enterprise-grade DAST tooling for authenticated scans.

•      Track record mentoring developers and running internal security workshops.

Preferred qualifications

•      OSCP, GWAPT, GPEN, OSWE, or equivalent.

•      Experience with LLM-assisted security tooling (code scanning, threat modelling, fuzzing).

•      Experience with adversarial AI / red-team automation platforms.

•      Prior involvement in DORA TLPT will be a plus

•      Cryptography depth (TLS, key management, HSMs, post-quantum awareness).

•      Active contributions to open-source security tools, CVEs, or research.

Key Skills

Application Security, Penetration Testing, OWASP Top 10, SANS Top 25, ASVS, SAST, DAST, SCA, Variant Analysis, Code Review, Threat Modelling, Cryptography, TLS, Key Management, Secret Scanning, Web Application Security, Java, Python, JavaScript, TypeScript, LLM Security, AI Security, Secure SDLC.

Desired Skills

OSCP, GWAPT, GPEN, OSWE, DORA TLPT, Adversarial Red Team, Blue Team, Post-Quantum Cryptography, Open-Source Security Research, CVE Disclosure.

Similar roles