Application Security Engineer-2

UPSTOX · Bengaluru

  • Experience3–5 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Posted25 Sept 2026

About UPSTOX

UPSTOX is hiring in Bengaluru in financial services. This role looks for around 3+ years of experience.

Skills

  • AWS
  • CI/CD pipelines
  • Docker
  • Kubernetes
  • Python
  • Go
  • Rust
  • penetration testing
  • Secure SDLC
  • threat modeling
  • SAML
  • OAuth
  • OIDC
  • Terraform
  • CloudFormation
  • software supply chain security
  • AI/LLM security

The role

An application security engineer at a financial services product company embeds security across AWS, CI/CD pipelines, Docker, and Kubernetes, and builds security automation for web, mobile, and API systems. The role applies penetration testing, threat modeling, and Secure SDLC practices while using Python, Go, or Rust to deliver production security tools.

Full job description

Job Description

Security Engineer 2 — Application Security

Location: Bangalore/Mumbai

Function: Application Security

Reports to: Director of Application Security

Experience: 3-5 years

About the Role

Upstox is looking for a Security Engineer 2 to join our Application Security team. This is a senior individual-contributor role for someone who has moved beyond executing assessments to owning the security posture of our cloud infrastructure, CI/CD pipelines, and containerized services — and who can write real production-quality code to build the internal tools that scale our security program. You'll work closely with engineering, platform, and DevOps teams to embed security into how we build and ship software, while also mentoring Security Engineer 1s and raising the technical bar across the team.

What You'll Do

Own end-to-end security architecture reviews for new and changing systems — assessing the application layer, AWS infrastructure, and container/orchestration layer together as one system, rather than reviewing each in isolation, and driving remediation of what you find at scale rather than flagging issues one at a time.

Embed security checks directly into CI/CD pipelines (SAST, SCA/dependency scanning, container image scanning, secrets detection, IaC scanning) so vulnerabilities are caught before merge, not after deployment.

Own container and orchestration security — hardening Docker images, reviewing Kubernetes configurations (RBAC, network policies, pod security standards), and closing gaps in how workloads are built and run in production.

Design, build, and maintain in-house security tools and automation — think internal scanners, policy-as-code checks, dashboards that aggregate findings across systems, Just in time access tools or automation that removes manual steps from recurring assessments. This is a coding role as much as a security one.

Perform penetration testing across web applications, mobile applications (Android/iOS), and APIs to identify vulnerabilities before they reach production.

Conduct manual and tool-assisted source code reviews to catch security issues early in the development cycle.

Partner with engineering teams to embed security into the Secure SDLC, including security requirements, design reviews, and release gating.

Drive and participate in threat modelling exercises for new features and systems.

Configure, tune, and manage WAF rules (Cloudflare/AWS WAF) to protect production applications and APIs.

Stay current with the evolving threat landscape, new attack techniques, and security tooling.

Partner with the platform/DevOps team on infrastructure-as-code (Terraform, CloudFormation) security reviews before infrastructure changes ship.

Track and drive remediation of vulnerabilities across applications against SLA, working directly with engineering and platform teams to close gaps.

What We're Looking For

3-5 years of hands-on experience in application, product, or cloud security.

Strong, hands-on AWS security knowledge — IAM design and least-privilege policies, VPC/network security, secrets management (e.g., Secrets Manager/KMS), logging and detection (CloudTrail, Guard Duty), and common cloud misconfiguration patterns. This needs to be real operational depth, not just familiarity with the console.

Solid understanding of CI/CD pipelines and how to secure them — pipeline-as-code, build system trust boundaries, artifact integrity, secrets in pipelines, and where to insert automated security gates (SAST, SCA, container scanning, IaC scanning) without breaking developer velocity.

Practical container security experience — Docker image hardening, and Kubernetes security fundamentals (RBAC, network policies, secrets handling, pod security standards).

Strong coding fundamentals in at least one of Python, Go, or Rust, with the ability to design and ship a real tool, not just write one-off scripts — this role builds security tooling that other engineers will depend on.

Solid foundation in application security fundamentals: penetration testing across web/mobile/API, manual source code review, Secure SDLC and threat modeling, and authentication/authorization protocols (SAML, OAuth, OIDC).

Experience with infrastructure-as-code security review (Terraform, CloudFormation, or similar).

Understanding of software supply chain security — dependency risk, SBOMs, and build/artifact integrity.

Working understanding of AI/LLM security risks — prompt injection, insecure output handling, model/data poisoning, and excessive agency in AI-integrated systems.

Strong communication skills — this role influences engineering and platform teams directly and will mentor more junior engineers.

Good to Have

Experience with policy-as-code tools (OPA/Rego, Kyverno, or similar) for automated compliance/security checks.

Exposure to a service mesh (Istio, Linkerd) and its security implications.

Relevant certifications (e.g., OSCP, OSWE, OSCE, AWS Security Specialty, CKS) and bug bounty experience are a plus but not mandatory.

Experience operating or building internal security platforms/dashboards at a previous company.

Why Join Us

Own security architecture decisions for high-scale, high-stakes financial products used by millions of users — not just review them after the fact.

Build real internal tools used daily by the security and engineering teams, with the autonomy to decide how they're designed.

Work across the full stack of modern cloud-native security — AWS, CI/CD, containers, and application code — rather than being siloed into one narrow area.

A collaborative team that invests in your growth, including a path toward technical leadership and mentoring the next generation of AppSec engineers.

By applying for this position, you acknowledge that you have reviewed our Prospective Employee Privacy Notice, which outlines how Upstox collects, uses, and protects your Personal Information ("PI"). I accept Upstox's Prospective Employee Privacy Notice.

Upstox is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or other characteristics.