Lead Security Engineer
Flipkart · Bengaluru
- Experience5–10 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelsenior
- Posted22 Sept 2026
About Flipkart
Flipkart is hiring in Bengaluru in ecommerce retail. This role looks for around 5+ years of experience.
Skills
- Security standards
- Security configuration reviews
- Threat modeling
- Python
- Bash
- PowerShell
- CIS
- STRIDE
- PASTA
- SOAR
- SIEM
- XDR
- Networking
- Infrastructure security
- Identity security
- Endpoint security
- Cloud security
- Application security
- Incident response
- Linux
- Windows
- Microsoft Azure Active Directory
- ISO 27001
- NIST
The role
A security engineer at a large e-commerce marketplace develops security standards, performs security configuration reviews and threat modeling, and builds AI-powered SOC operations with Python and Bash. The role applies CIS standards, security automation, and cloud security to strengthen infrastructure and organizational controls.
Full job description
About the Team
The Security Standards team is a part of the central Information security function which is primarily responsible for security standards, secure configuration reviews, architecture reviews, validating efficacy and efficiency of the existing security controls, threat modeling, assessment of the various security controls / technologies based on the gaps identified, security metrics, analytics, automation, AI-powered SOC operations, and autonomous threat detection etc. This team owns the IT Security, Security controls and reviews them on a regular basis to ensure IT/Security controls are working as designed, and all features/capabilities of IT and Security products are being used to the maximum.The InfoSec Security Standards team is primarily responsible for defining new and reviewing existing hardening standards, and carrying out secure configuration review assessments for Flipkart and Group. This function is also responsible for reviewing and approving technical security exceptions against the defined security standards.
About the Role
Flipkart is seeking a skilled, technocrat, motivated, strong security mindset and collaborative Senior Information Security Engineer in the Security Standards team. You will be a strong communicator and influencer, demonstrating curiosity to learn and understand the business. In this role, you will lead complex engineering tasks, leveraging security automation frameworks, programming capabilities, AI-powered SOC platforms, agentic security workflows, and emerging AI tools to safeguard organizational baselines.
What you’ll do:
Security Standards Customization: Specializes in Security Standards Development, meticulously crafting security standards and protocols to fortify digital infrastructures.Comprehensive Assessments: Conducts comprehensive Security Standards Assessments, scrutinizing systems for gaps and vulnerabilities.Industry Framework Compliance: Develop standards in accordance with industry recognised standards like CIS (Center for Internet Security), standards implementation and interpretation across FK Group.Architecture & Design Reviews: Security review of the architecture for the new projects and existing infrastructure setup. Expert in Security Configuration Reviews, ensuring optimal secure configurations and settings to mitigate risks.Efficacy & Tool Utilization: Ensure efficacy of security controls deployed. Work with the technical operations team to understand security controls / tech deployed and come up with recommendations to address gaps and also take full advantage of the deployed technologies.Threat Modeling & AI Integration: Conduct threat modeling based on well known standards / frameworks such as STRIDE, PASTA etc. Utilize AI technologies, machine learning, and LLM-powered tools to optimize vulnerability discovery, configuration audits, and AI-assisted SOC operations including automated alert triage and threat hunting.Security Automation: Implement robust security automation & scripting pipelines to proactively continuously monitor drift across endpoints and servers. Design and operationalize AI-powered SOC workflows including agentic response playbooks, LLM-assisted incident triage, and SOAR integration with AI-native SIEM/XDR platforms such as Palo Alto XSIAM or Microsoft Sentinel with Copilot for Security.Governance & Continuous Protection: Defining and maintaining security procedures, standards, guidelines and procedures as required. Executes proactive measures to safeguard against emerging threats and collaborates cross-functionally to maintain cutting-edge security protocols.
What you’ll need:
Education: Bachelor’s degree(B.E/B.Tech or M.S/M.Tech) in Information Technology or other related fields.Experience: At least 5-10 years of working experience in domains related to Information security and with a very strong security mindset.Coding & Scripting Skills: Solid development/coding skills (e.g., Python, Bash, PowerShell) to construct custom continuous security validation scripts and parse complex security telemetry.AI & Emerging Technologies: Hands-on experience with AI SOC platforms (AI-native SIEM/XDR), SOAR with AI-driven playbooks, LLM-based threat hunting, prompt engineering for security use cases, and AI-assisted detection engineering. Strong understanding of how to augment configuration analysis and risk scoping using AI-driven platforms.Security Solutions: Implementation experience in Security technologies (at least 2+ years) such as Next Gen Firewall / IDS/ IPS / NAC / Email Security/CASB / EDR / WAF / AV / DLP / ATP / PIM / PAM / DAM / SIEM etc.Infrastructure & Networking: In-depth understanding of networking concepts, protocols and in-depth knowledge of infrastructure, identity and endpoint security technology such as AD, Azure AD, Next Gen Firewall, IDS, IPD, AV, EDR, CASB, WAF, NAC, Wi-fi security, DLP, ATP, SIEM, Proxy etc. Very good understanding of Operating systems (Windows, MAC, Linux) & VDI etc.Standards & Architecture: Knowledge and understanding of security standards, security configuration reviews, secure architecture and cloud security. Proficiency in CIS standards implementation and interpretation. Good understanding of security frameworks, standards such as ISO 27001, NIST, CIS etc.Professional Competencies: Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls, network security, cloud security, application security, endpoint security, data protection, incident response, and AI SOC operations. Familiarity with AI-native SOC platforms, agentic security workflows, LLM-assisted threat investigation, and AI-driven alert triage is a strong plus. Excellent problem solving, interpersonal, communication and presentation skills. Able to work independently and efficiently.