Jobs Companies Weekday AI Lead Cybersecurity & Application Security Engineer

À propos de ce poste Lead Cybersecurity & Application Security Engineer chez Weekday AI

Weekday AI · Sur site · Hyderabad, Telangana, India

This role is for one of the Weekday's clients

Min Experience: 5+ years

Location: Hyderabad, Telangana, India
JobType: full-time

We are looking for a highly experienced Lead Cybersecurity & Application Security Engineer to own and strengthen the end-to-end security posture of our applications, platform, infrastructure, and internal systems.

This is a hands-on, high-impact role combining offensive security and defensive security. You will think like an attacker while operating as a defender—identifying vulnerabilities, conducting penetration tests and red-team exercises, strengthening preventive controls, and leading security response efforts.

You will work closely with Engineering, IT, and leadership teams to proactively identify, exploit, remediate, and monitor security risks across mobile applications, APIs, backend systems, cloud infrastructure, and internal environments.

Requirements

Key Responsibilities

Application Security & Penetration Testing

  • Lead manual and automated penetration testing across Android/iOS applications, APIs, backend services, admin panels, and internal dashboards.
  • Conduct deep security assessments aligned with the OWASP Top 10.
  • Test authentication and authorization controls, access management, session security, token handling, business logic, API abuse, and rate-limit protections.
  • Identify, validate, document, and demonstrate vulnerabilities through proof-of-concept exploits.
  • Work with engineering teams to prioritize remediation, validate fixes, and complete security re-testing.

Phishing & Social Engineering Defense

  • Design and execute phishing simulations covering credential harvesting, email-based attacks, MFA fatigue, and social engineering scenarios.
  • Evaluate and improve organizational phishing detection and response mechanisms.
  • Track security awareness metrics, including click rates, credential submission, and incident-reporting behavior.
  • Conduct employee security awareness programs and simulations.

Internal Security & Insider Threat Protection

  • Simulate internal attack scenarios involving lateral movement, privilege escalation, excessive permissions, and insider threats.
  • Review RBAC, least-privilege controls, identity configurations, and access policies.
  • Identify high-risk access paths and recommend appropriate security controls.

Threat Assessment & Security Architecture

  • Assess exposure to web application attacks, API abuse and scraping, third-party dependencies, and emerging threats.
  • Conduct threat modelling across application and infrastructure layers.
  • Monitor emerging vulnerabilities, zero-day threats, and evolving attack techniques.
  • Advise engineering and leadership teams on security risks associated with architecture and product decisions.

Incident Response & Forensics

  • Develop, test, and maintain incident response playbooks.
  • Lead response efforts during security incidents, attacks, data exposure, and potential breaches.
  • Conduct root-cause analysis and post-incident reviews.
  • Recommend preventive controls and improvements to reduce the likelihood of recurrence.

Secure SDLC & DevSecOps

  • Embed security-by-design principles throughout the software development lifecycle.
  • Partner with engineering teams on secure coding, secrets management, API security, and vulnerability remediation.
  • Support DevSecOps initiatives and security automation.
  • Review and validate application logging, monitoring, alerting, and security controls.

IT & Infrastructure Security

  • Work with IT teams to assess MDM, endpoint security, identity, and access controls.
  • Validate whether security policies are effectively enforced in real-world scenarios.
  • Identify gaps between documented security controls and actual implementation.
  • Provide security guidance and approve risk exceptions and mitigation strategies.

Governance & Reporting

  • Maintain a centralized security risk and vulnerability register.
  • Prepare vulnerability trends, security posture reports, and executive-level security briefings.
  • Support compliance initiatives, audits, security assessments, and investor due diligence.
  • Clearly communicate technical risks and remediation priorities to non-technical stakeholders.

Required Technical Skills

Offensive & Application Security

  • Strong hands-on experience in web, mobile, and API penetration testing.
  • Deep understanding of OWASP Top 10 and common application security vulnerabilities.
  • Experience with manual exploitation, proof-of-concept development, vulnerability validation, and re-testing.
  • Strong understanding of authentication, authorization, session management, and access-control vulnerabilities.

Defensive Security & Incident Response

  • Strong knowledge of identity and access security, endpoint protection, threat detection, security monitoring, and logging.
  • Experience responding to live security incidents and conducting breach investigations and root-cause analysis.

Tools & Platforms

  • Burp Suite
  • OWASP ZAP
  • Nuclei
  • Metasploit
  • Postman and API testing tools
  • Security testing and automation tools
  • SIEM and log-analysis platforms such as Splunk, ELK, or equivalent
  • Exposure to AWS, GCP, or Azure security environments

Qualifications & Experience

  • 5–6+ years of hands-on cybersecurity experience.
  • Proven experience across penetration testing, application security, vulnerability management, and incident response.
  • Experience securing SaaS, fintech, technology, or startup environments is preferred.
  • Strong understanding of secure application development and cloud security principles.
  • Ability to work closely with software engineers, IT teams, and senior leadership.
  • Strong analytical, documentation, reporting, and communication skills.
  • Ability to explain complex security risks clearly to technical and non-technical stakeholders.
  • High ownership and ability to independently drive security initiatives from identification through remediation.

Ideal Candidate

The ideal candidate is a security professional who can think offensively, respond defensively, and drive security improvements proactively. You should be comfortable getting hands-on with applications and infrastructure, challenging existing security assumptions, collaborating with engineering teams, and taking ownership of critical security risks.

Good-to-have skills:

  • Penetration Testing
  • Application Security
  • Incident Response
  • Red Teaming
  • OWASP
  • Cloud Security
  • DevSecOps
Prêt à postuler chez Weekday AI ?
Postuler chez Weekday AI

À propos de Weekday AI

At Weekday (backed by YC; also Product Hunt #1 product of the day), we are building the next frontier in hiring. We have built the largest database of white collar talent in India and have built outreach tools on top of it to generate highest response rates.

Voir tous les emplois chez Weekday AI →

Emplois similaires

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Weekday AI

Voir tous les emplois chez Weekday AI →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit