Jobs Companies Weekday AI Lead Cybersecurity & Application Security Engineer

Über diese Lead Cybersecurity & Application Security Engineer Stelle bei Weekday AI

Weekday AI · Vor Ort · Hyderabad, Telangana, India

This role is for one of the Weekday's clients

Min Experience: 5+ years

Location: Hyderabad, Telangana, India
JobType: full-time

We are looking for a highly experienced Lead Cybersecurity & Application Security Engineer to own and strengthen the end-to-end security posture of our applications, platform, infrastructure, and internal systems.

This is a hands-on, high-impact role combining offensive security and defensive security. You will think like an attacker while operating as a defender—identifying vulnerabilities, conducting penetration tests and red-team exercises, strengthening preventive controls, and leading security response efforts.

You will work closely with Engineering, IT, and leadership teams to proactively identify, exploit, remediate, and monitor security risks across mobile applications, APIs, backend systems, cloud infrastructure, and internal environments.

Requirements

Key Responsibilities

Application Security & Penetration Testing

  • Lead manual and automated penetration testing across Android/iOS applications, APIs, backend services, admin panels, and internal dashboards.
  • Conduct deep security assessments aligned with the OWASP Top 10.
  • Test authentication and authorization controls, access management, session security, token handling, business logic, API abuse, and rate-limit protections.
  • Identify, validate, document, and demonstrate vulnerabilities through proof-of-concept exploits.
  • Work with engineering teams to prioritize remediation, validate fixes, and complete security re-testing.

Phishing & Social Engineering Defense

  • Design and execute phishing simulations covering credential harvesting, email-based attacks, MFA fatigue, and social engineering scenarios.
  • Evaluate and improve organizational phishing detection and response mechanisms.
  • Track security awareness metrics, including click rates, credential submission, and incident-reporting behavior.
  • Conduct employee security awareness programs and simulations.

Internal Security & Insider Threat Protection

  • Simulate internal attack scenarios involving lateral movement, privilege escalation, excessive permissions, and insider threats.
  • Review RBAC, least-privilege controls, identity configurations, and access policies.
  • Identify high-risk access paths and recommend appropriate security controls.

Threat Assessment & Security Architecture

  • Assess exposure to web application attacks, API abuse and scraping, third-party dependencies, and emerging threats.
  • Conduct threat modelling across application and infrastructure layers.
  • Monitor emerging vulnerabilities, zero-day threats, and evolving attack techniques.
  • Advise engineering and leadership teams on security risks associated with architecture and product decisions.

Incident Response & Forensics

  • Develop, test, and maintain incident response playbooks.
  • Lead response efforts during security incidents, attacks, data exposure, and potential breaches.
  • Conduct root-cause analysis and post-incident reviews.
  • Recommend preventive controls and improvements to reduce the likelihood of recurrence.

Secure SDLC & DevSecOps

  • Embed security-by-design principles throughout the software development lifecycle.
  • Partner with engineering teams on secure coding, secrets management, API security, and vulnerability remediation.
  • Support DevSecOps initiatives and security automation.
  • Review and validate application logging, monitoring, alerting, and security controls.

IT & Infrastructure Security

  • Work with IT teams to assess MDM, endpoint security, identity, and access controls.
  • Validate whether security policies are effectively enforced in real-world scenarios.
  • Identify gaps between documented security controls and actual implementation.
  • Provide security guidance and approve risk exceptions and mitigation strategies.

Governance & Reporting

  • Maintain a centralized security risk and vulnerability register.
  • Prepare vulnerability trends, security posture reports, and executive-level security briefings.
  • Support compliance initiatives, audits, security assessments, and investor due diligence.
  • Clearly communicate technical risks and remediation priorities to non-technical stakeholders.

Required Technical Skills

Offensive & Application Security

  • Strong hands-on experience in web, mobile, and API penetration testing.
  • Deep understanding of OWASP Top 10 and common application security vulnerabilities.
  • Experience with manual exploitation, proof-of-concept development, vulnerability validation, and re-testing.
  • Strong understanding of authentication, authorization, session management, and access-control vulnerabilities.

Defensive Security & Incident Response

  • Strong knowledge of identity and access security, endpoint protection, threat detection, security monitoring, and logging.
  • Experience responding to live security incidents and conducting breach investigations and root-cause analysis.

Tools & Platforms

  • Burp Suite
  • OWASP ZAP
  • Nuclei
  • Metasploit
  • Postman and API testing tools
  • Security testing and automation tools
  • SIEM and log-analysis platforms such as Splunk, ELK, or equivalent
  • Exposure to AWS, GCP, or Azure security environments

Qualifications & Experience

  • 5–6+ years of hands-on cybersecurity experience.
  • Proven experience across penetration testing, application security, vulnerability management, and incident response.
  • Experience securing SaaS, fintech, technology, or startup environments is preferred.
  • Strong understanding of secure application development and cloud security principles.
  • Ability to work closely with software engineers, IT teams, and senior leadership.
  • Strong analytical, documentation, reporting, and communication skills.
  • Ability to explain complex security risks clearly to technical and non-technical stakeholders.
  • High ownership and ability to independently drive security initiatives from identification through remediation.

Ideal Candidate

The ideal candidate is a security professional who can think offensively, respond defensively, and drive security improvements proactively. You should be comfortable getting hands-on with applications and infrastructure, challenging existing security assumptions, collaborating with engineering teams, and taking ownership of critical security risks.

Good-to-have skills:

  • Penetration Testing
  • Application Security
  • Incident Response
  • Red Teaming
  • OWASP
  • Cloud Security
  • DevSecOps
Bereit, sich bei Weekday AI zu bewerben?
Bei Weekday AI bewerben

Über Weekday AI

At Weekday (backed by YC; also Product Hunt #1 product of the day), we are building the next frontier in hiring. We have built the largest database of white collar talent in India and have built outreach tools on top of it to generate highest response rates.

Alle Jobs bei Weekday AI ansehen →

Ähnliche Jobs

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Weekday AI

Alle Jobs bei Weekday AI ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos