Lead Cybersecurity & Application Security Engineer
Weekday AI Hyderabad, Telangana, India
Technology, Information and Internet · 11-50 employees
About the role
The Lead Cybersecurity & Application Security Engineer will own the end-to-end security posture of applications, infrastructure, and internal systems through offensive and defensive security measures. Responsibilities include conducting penetration tests, managing incident response, and embedding security-by-design principles across the development lifecycle.
What they look for
Requirements
Candidates must have 5+ years of hands-on experience in cybersecurity, specifically in penetration testing, vulnerability management, and incident response. A strong understanding of OWASP Top 10, cloud security, and the ability to collaborate with engineering teams are essential for this role.
Full description
This role is for one of the Weekday's clients
Min Experience: 5+ years
Location: Hyderabad, Telangana, India JobType: full-time
We are looking for a highly experienced Lead Cybersecurity & Application Security Engineer to own and strengthen the end-to-end security posture of our applications, platform, infrastructure, and internal systems.
This is a hands-on, high-impact role combining offensive security and defensive security. You will think like an attacker while operating as a defender—identifying vulnerabilities, conducting penetration tests and red-team exercises, strengthening preventive controls, and leading security response efforts.
You will work closely with Engineering, IT, and leadership teams to proactively identify, exploit, remediate, and monitor security risks across mobile applications, APIs, backend systems, cloud infrastructure, and internal environments.
Key ResponsibilitiesApplication Security & Penetration Testing• Lead manual and automated penetration testing across Android/iOS applications, APIs, backend services, admin panels, and internal dashboards.
- Conduct deep security assessments aligned with the OWASP Top 10.
- Test authentication and authorization controls, access management, session security, token handling, business logic, API abuse, and rate-limit protections.
- Identify, validate, document, and demonstrate vulnerabilities through proof-of-concept exploits.
- Work with engineering teams to prioritize remediation, validate fixes, and complete security re-testing.
Phishing & Social Engineering Defense• Design and execute phishing simulations covering credential harvesting, email-based attacks, MFA fatigue, and social engineering scenarios.
- Evaluate and improve organizational phishing detection and response mechanisms.
- Track security awareness metrics, including click rates, credential submission, and incident-reporting behavior.
- Conduct employee security awareness programs and simulations.
Internal Security & Insider Threat Protection• Simulate internal attack scenarios involving lateral movement, privilege escalation, excessive permissions, and insider threats.
- Review RBAC, least-privilege controls, identity configurations, and access policies.
- Identify high-risk access paths and recommend appropriate security controls.
Threat Assessment & Security Architecture• Assess exposure to web application attacks, API abuse and scraping, third-party dependencies, and emerging threats.
- Conduct threat modelling across application and infrastructure layers.
- Monitor emerging vulnerabilities, zero-day threats, and evolving attack techniques.
- Advise engineering and leadership teams on security risks associated with architecture and product decisions.
Incident Response & Forensics• Develop, test, and maintain incident response playbooks.
- Lead response efforts during security incidents, attacks, data exposure, and potential breaches.
- Conduct root-cause analysis and post-incident reviews.
- Recommend preventive controls and improvements to reduce the likelihood of recurrence.
Secure SDLC & DevSecOps• Embed security-by-design principles throughout the software development lifecycle.
- Partner with engineering teams on secure coding, secrets management, API security, and vulnerability remediation.
- Support DevSecOps initiatives and security automation.
- Review and validate application logging, monitoring, alerting, and security controls.
IT & Infrastructure Security• Work with IT teams to assess MDM, endpoint security, identity, and access controls.
- Validate whether security policies are effectively enforced in real-world scenarios.
- Identify gaps between documented security controls and actual implementation.
- Provide security guidance and approve risk exceptions and mitigation strategies.
Governance & Reporting• Maintain a centralized security risk and vulnerability register.
- Prepare vulnerability trends, security posture reports, and executive-level security briefings.
- Support compliance initiatives, audits, security assessments, and investor due diligence.
- Clearly communicate technical risks and remediation priorities to non-technical stakeholders.
Required Technical SkillsOffensive & Application Security
- Strong hands-on experience in web, mobile, and API penetration testing.
- Deep understanding of OWASP Top 10 and common application security vulnerabilities.
- Experience with manual exploitation, proof-of-concept development, vulnerability validation, and re-testing.
- Strong understanding of authentication, authorization, session management, and access-control vulnerabilities.
Defensive Security & Incident Response
- Strong knowledge of identity and access security, endpoint protection, threat detection, security monitoring, and logging.
- Experience responding to live security incidents and conducting breach investigations and root-cause analysis.
Tools & Platforms
- Burp Suite
- OWASP ZAP
- Nuclei
- Metasploit
- Postman and API testing tools
- Security testing and automation tools
- SIEM and log-analysis platforms such as Splunk, ELK, or equivalent
- Exposure to AWS, GCP, or Azure security environments
Qualifications & Experience• 5–6+ years of hands-on cybersecurity experience.
- Proven experience across penetration testing, application security, vulnerability management, and incident response.
- Experience securing SaaS, fintech, technology, or startup environments is preferred.
- Strong understanding of secure application development and cloud security principles.
- Ability to work closely with software engineers, IT teams, and senior leadership.
- Strong analytical, documentation, reporting, and communication skills.
- Ability to explain complex security risks clearly to technical and non-technical stakeholders.
- High ownership and ability to independently drive security initiatives from identification through remediation.
Ideal CandidateThe ideal candidate is a security professional who can think offensively, respond defensively, and drive security improvements proactively. You should be comfortable getting hands-on with applications and infrastructure, challenging existing security assumptions, collaborating with engineering teams, and taking ownership of critical security risks.
Good-to-have skills:
- Penetration Testing
- Application Security
- Incident Response
- Red Teaming
- OWASP
- Cloud Security
- DevSecOps
Similar roles
-
Cyber Security Engineer
Zensar Pune, Maharashtra, India
-
Italian Speaking Cybersecurity Customer Experts - Work In Athens, Greece
Mercier Consultancy Group Belgium
-
Cybersecurity Incident Commander - CIRT
Thrive Mabalacat, Pampanga, Philippines
-
Cybersecurity Expert
Consort Group Porto, Porto, Portugal · €43K–€52K/yr
-
Senior Consultant - Cybersecurity
UL Solutions Bangalore, Karnataka, India
-
Project Managerc (Cybersecurity, Finance)
Sakana AI Minato, Japan