Technology

Senior Application Security Engineer

Bengaluru
Work Type: Full Time
At Zerodha Fund House, we are enabling the next generation of Indian investors. We think the mutual fund needs to be re-imagined as a product: simple, transparent, and relevant enough to bring the next 10 crore Indians into the capital markets. We are building the founding team and are looking for smart, passionate people to join us.
We are looking for a Senior Security Engineer to own security at ZFH. This is a foundational role. You will be the person who defines what security means here, sets the standards the rest of engineering builds against, and grows the function (and eventually the team) as we scale.

Responsibilities
  • Own the complete security layer at ZFH
  • Own application security across our web and mobile products, from threat modelling at design time through code review, CI scanning with sane triage thresholds, and driving pentest and bug bounty findings through to verified fixes
  • Own AWS security end to end: multi-account and multi-region guardrails, least-privilege IAM, segmented networks, encryption and key management, all codified in Terraform
  • Build detection and response that people act on: GuardDuty, CloudTrail, Config, Security Hub, WAF, and centralised logging wired to alerts someone actually reads
  • Handle compliance: SEBI cybersecurity framework, CERT-In reporting, system audits, partner security reviews
  • Own incident response, playbooks, and escalation
  • Work with engineers so security is built in early, not bolted on late
  • Hire and grow the security team over time

Requirements
  • 6-9 years in security, with depth in cloud and app security
  • Hands-on AWS security. You can spot what is wrong with an IAM policy or a VPC
  • A hacking mindset, and the judgement to tell a real risk from a noisy scanner finding
  • Strong Unix, plus Python and shell scripting
  • Web app security fundamentals: SQLi, XSS, CSRF, SSRF, IDOR, auth flaws, OWASP Top 10
  • Networking and network security: firewalls, VPNs, TLS, traffic analysis, pentesting
  • Experience with vulnerability scanners, IDS/IPS, WAFs, VAPT engagements
  • Working knowledge of data security: classification, encryption, key management, and access control for data at rest and in motion
  • Interest in building a team

Nice to have
  • BFSI or fintech experience
  • CTF background. Tell us your team, your handle, and anything you are proud of
  • Android and mobile app security
  • Interest in markets

Submit Your Application

You have successfully applied
  • You have errors in applying