Jobs Companies Weekday AI Lead Cybersecurity & Application Security Engineer

Sobre este puesto de Lead Cybersecurity & Application Security Engineer en Weekday AI

Weekday AI · Presencial · Hyderabad, Telangana, India

This role is for one of the Weekday's clients

Min Experience: 5+ years

Location: Hyderabad, Telangana, India
JobType: full-time

We are looking for a highly experienced Lead Cybersecurity & Application Security Engineer to own and strengthen the end-to-end security posture of our applications, platform, infrastructure, and internal systems.

This is a hands-on, high-impact role combining offensive security and defensive security. You will think like an attacker while operating as a defender—identifying vulnerabilities, conducting penetration tests and red-team exercises, strengthening preventive controls, and leading security response efforts.

You will work closely with Engineering, IT, and leadership teams to proactively identify, exploit, remediate, and monitor security risks across mobile applications, APIs, backend systems, cloud infrastructure, and internal environments.

Requirements

Key Responsibilities

Application Security & Penetration Testing

  • Lead manual and automated penetration testing across Android/iOS applications, APIs, backend services, admin panels, and internal dashboards.
  • Conduct deep security assessments aligned with the OWASP Top 10.
  • Test authentication and authorization controls, access management, session security, token handling, business logic, API abuse, and rate-limit protections.
  • Identify, validate, document, and demonstrate vulnerabilities through proof-of-concept exploits.
  • Work with engineering teams to prioritize remediation, validate fixes, and complete security re-testing.

Phishing & Social Engineering Defense

  • Design and execute phishing simulations covering credential harvesting, email-based attacks, MFA fatigue, and social engineering scenarios.
  • Evaluate and improve organizational phishing detection and response mechanisms.
  • Track security awareness metrics, including click rates, credential submission, and incident-reporting behavior.
  • Conduct employee security awareness programs and simulations.

Internal Security & Insider Threat Protection

  • Simulate internal attack scenarios involving lateral movement, privilege escalation, excessive permissions, and insider threats.
  • Review RBAC, least-privilege controls, identity configurations, and access policies.
  • Identify high-risk access paths and recommend appropriate security controls.

Threat Assessment & Security Architecture

  • Assess exposure to web application attacks, API abuse and scraping, third-party dependencies, and emerging threats.
  • Conduct threat modelling across application and infrastructure layers.
  • Monitor emerging vulnerabilities, zero-day threats, and evolving attack techniques.
  • Advise engineering and leadership teams on security risks associated with architecture and product decisions.

Incident Response & Forensics

  • Develop, test, and maintain incident response playbooks.
  • Lead response efforts during security incidents, attacks, data exposure, and potential breaches.
  • Conduct root-cause analysis and post-incident reviews.
  • Recommend preventive controls and improvements to reduce the likelihood of recurrence.

Secure SDLC & DevSecOps

  • Embed security-by-design principles throughout the software development lifecycle.
  • Partner with engineering teams on secure coding, secrets management, API security, and vulnerability remediation.
  • Support DevSecOps initiatives and security automation.
  • Review and validate application logging, monitoring, alerting, and security controls.

IT & Infrastructure Security

  • Work with IT teams to assess MDM, endpoint security, identity, and access controls.
  • Validate whether security policies are effectively enforced in real-world scenarios.
  • Identify gaps between documented security controls and actual implementation.
  • Provide security guidance and approve risk exceptions and mitigation strategies.

Governance & Reporting

  • Maintain a centralized security risk and vulnerability register.
  • Prepare vulnerability trends, security posture reports, and executive-level security briefings.
  • Support compliance initiatives, audits, security assessments, and investor due diligence.
  • Clearly communicate technical risks and remediation priorities to non-technical stakeholders.

Required Technical Skills

Offensive & Application Security

  • Strong hands-on experience in web, mobile, and API penetration testing.
  • Deep understanding of OWASP Top 10 and common application security vulnerabilities.
  • Experience with manual exploitation, proof-of-concept development, vulnerability validation, and re-testing.
  • Strong understanding of authentication, authorization, session management, and access-control vulnerabilities.

Defensive Security & Incident Response

  • Strong knowledge of identity and access security, endpoint protection, threat detection, security monitoring, and logging.
  • Experience responding to live security incidents and conducting breach investigations and root-cause analysis.

Tools & Platforms

  • Burp Suite
  • OWASP ZAP
  • Nuclei
  • Metasploit
  • Postman and API testing tools
  • Security testing and automation tools
  • SIEM and log-analysis platforms such as Splunk, ELK, or equivalent
  • Exposure to AWS, GCP, or Azure security environments

Qualifications & Experience

  • 5–6+ years of hands-on cybersecurity experience.
  • Proven experience across penetration testing, application security, vulnerability management, and incident response.
  • Experience securing SaaS, fintech, technology, or startup environments is preferred.
  • Strong understanding of secure application development and cloud security principles.
  • Ability to work closely with software engineers, IT teams, and senior leadership.
  • Strong analytical, documentation, reporting, and communication skills.
  • Ability to explain complex security risks clearly to technical and non-technical stakeholders.
  • High ownership and ability to independently drive security initiatives from identification through remediation.

Ideal Candidate

The ideal candidate is a security professional who can think offensively, respond defensively, and drive security improvements proactively. You should be comfortable getting hands-on with applications and infrastructure, challenging existing security assumptions, collaborating with engineering teams, and taking ownership of critical security risks.

Good-to-have skills:

  • Penetration Testing
  • Application Security
  • Incident Response
  • Red Teaming
  • OWASP
  • Cloud Security
  • DevSecOps
¿Listo para postularte en Weekday AI?
Postúlate en Weekday AI

Sobre Weekday AI

At Weekday (backed by YC; also Product Hunt #1 product of the day), we are building the next frontier in hiring. We have built the largest database of white collar talent in India and have built outreach tools on top of it to generate highest response rates.

Ver todos los empleos en Weekday AI →

Empleos similares

Plaud
SeniorSecurity Engineer (Application Security) - Singapore
Plaud
⚡ Postúlate pronto Singapore Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1h
Flexport
Product Security Engineer II
Flexport
⚡ Postúlate pronto Amsterdam, Netherlands Presencial
● Nuevo 👁 Visto ✓ Postulado hace 3h
EG
Application & AI Cyber Security Engineer
EQT Group
⚡ Postúlate pronto Stockholm, Stockholm, Sweden Presencial
● Nuevo 👁 Visto ✓ Postulado hace 5h
Roblox
Principal Security Software Engineer, Application Security
Roblox
⚡ Postúlate pronto San Mateo, CA, United States Presencial $326,060–$385,050
● Nuevo 👁 Visto ✓ Postulado hace 6h
Roblox
Senior Security Software Engineer, Application Security
Roblox
⚡ Postúlate pronto San Mateo, CA, United States Presencial $269,170–$326,060
● Nuevo 👁 Visto ✓ Postulado hace 6h
SpaceX
Product Security Engineer (Starlink)
SpaceX
⚡ Postúlate pronto Bastrop, TX Presencial
● Nuevo 👁 Visto ✓ Postulado hace 9h
SpaceX
Product Security Engineer (Starlink)
SpaceX
⚡ Postúlate pronto Hawthorne, CA Presencial $130,000–$160,000
● Nuevo 👁 Visto ✓ Postulado hace 9h
SpaceX
Product Security Engineer (Starlink)
SpaceX
⚡ Postúlate pronto Redmond, WA Presencial $130,000–$165,000
● Nuevo 👁 Visto ✓ Postulado hace 9h
Lob
Staff Security Engineer, Cloud and Product Security
Lob
⚡ Postúlate pronto United States Presencial $197,500–$220,000
● Nuevo 👁 Visto ✓ Postulado hace 12h

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Weekday AI

Ver todos los empleos en Weekday AI →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis