Senior Lead Engineer, Information Security
- Hiring from
- India
- Work type
- Remote
- Posted
- Sep 29, 2026
Is this job info correct?
Key Responsibilities
Security Engineering & Architecture
- Design, implement, and maintain enterprise security controls across cloud, infrastructure, and application environments.
- Evaluate emerging threats and technologies and recommend improvements to the organization's security architecture.
- Develop security standards, engineering patterns, and technical guidance to improve the overall security posture.
Security Automation & DevSecOps
- Design and develop security automation solutions that improve operational efficiency and reduce manual effort.
- Integrate security controls and validation activities into CI/CD pipelines and software delivery workflows.
- Build and maintain GitHub Actions and related automation to support secure development practices.
- Automate vulnerability management, policy enforcement, reporting, and remediation tracking activities.
Application Security
- Lead security engineering efforts focused on protecting internally developed applications and APIs.
- Perform and coordinate:
- Threat modeling
- Secure design and architecture reviews
- Secure code reviews
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Open-source dependency and supply chain security reviews
- Secret and credential exposure detection
- API security testing and assessments
- CI/CD pipeline security reviews
- Security validation of application deployments
- Partner with development teams to identify, prioritize, and remediate security risks.
Web Application Firewall (WAF) & Edge Security
- Design, implement, and maintain Web Application Firewall (WAF) capabilities.
- Develop and tune security rules, attack detection logic, bot mitigation, rate limiting, and application-layer protections.
- Continuously monitor and improve protections against OWASP Top 10 and emerging web application threats.
Offensive Security & Penetration Testing
- Conduct application red team exercises and adversarial security assessments.
- Perform manual and automated penetration testing of web applications, APIs, and supporting services.
- Simulate real-world attack techniques to identify weaknesses in application design, authentication, authorization, and deployment architectures.
- Document findings, provide remediation guidance, and validate corrective actions.
Collaboration & Security Operations Support
- Partner with engineering, infrastructure, and cloud teams to implement secure solutions.
- Support incident response investigations involving applications, cloud services, and development platforms.
- Provide technical leadership and mentorship on security engineering practices and security tool adoption.
Success Measures
- Increased automation and efficiency of security processes.
- Successful integration of security controls into engineering and CI/CD workflows.
- Reduction of application and cloud security risks.
- Effective implementation and management of WAF protections.
- Timely identification and remediation of vulnerabilities.
- Successful execution of penetration testing and red team activities.
- Improved security posture across applications, APIs, and software delivery platforms.