Security Engineer

Wayfair · Bengaluru

  • Experience1–2 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Leveljunior
  • Posted2 Sept 2026

About Wayfair

Wayfair is hiring in Bengaluru in ecommerce retail. This role looks for around 1+ years of experience.

Skills

  • DevSecOps
  • penetration testing
  • Python
  • Kubernetes
  • Google Cloud
  • REST
  • GraphQL
  • Secure SDLC
  • CI/CD
  • dynamic analysis
  • JWT
  • OAuth
  • AI coding assistants

The role

A security engineer at an e-commerce retail company builds enterprise security solutions and secures applications through application security, DevSecOps, and penetration testing. The role applies threat modeling, Python, and cloud security to web services, AI-powered features, and security automation.

Full job description

Responsibilities:

Assist in building and deploying security solutions that will be used across the enterprise.

Liaise with development and product teams to develop secure products and features for customers, suppliers, partners, and employees.

Implement Sec in a DevSecOps model of operations.

Perform penetration testing and code reviews of highly complex services that are used by millions of customers, leveraging AI-assisted tooling to expand coverage and accelerate findings.

Conduct risk analysis and threat modelling, leveraging AI to accelerate analysis and broaden coverage.

Build threat models for AI/LLM-powered features (prompt injection, model abuse, sensitive data exposure through RAG and agents).

Assist in onboarding applications to web application firewall (WAF), maintain and tune WAF rules.

Triage Bug Bounty reports and coordinate with external hackers as part of Wayfair's Bug Bounty Program.

Build automations to streamline security workflows and detections, including LLM-powered tooling for triage, code review, report summarisation, and vulnerability discovery.

Use AI coding assistants (e. g., Claude, Cursor, Copilot) as a daily multiplier - for writing detection logic, drafting remediation guidance, scripting one-off analysis, and for code reviews.

Requirements:

0-1 year of experience in the cybersecurity domain.

Hands-on scripting experience in Python.

Exposure to k8s and cloud platforms (Google Cloud preferred).

Exposure to securing applications, REST and GraphQL services.

Understanding of secure application development or Secure SDLC.

Understanding of build and release management, CI/CD platforms.

Exposure to dynamic analysis.

Understanding of Authentication mechanisms such as JWT and OAuth.

Experience with utilising AI assistants (Claude, Cursor, Copilot, or similar) for day-to-day work.

What we'd love to see (but isn't required):

Experience securing any of these cloud service platforms - GCP, AWS, Azure.

Comfort using AI coding assistants (Claude, Cursor, Copilot, or similar) as part of day-to-day security work.

Experience building security automation with LLMs - e. g., bug bounty triage, code review assistants, alert enrichment, or report normalisation.

Hands-on experience assessing the security of AI/LLM-powered applications - prompt injection, jailbreaks, insecure tool/agent use, RAG data exposure, model abuse.

Familiarity with AI security frameworks such as OWASP LLM Top 10 MITRE ATLAS, or NIST AI RMF.

Relevant security certifications like GCP Professional Cloud Security Engineer, OSCP, OSWE, CKS, GWAPT, GPEN, GSEC.