Senior Application Security Engineer
Flipkart · Bengaluru
- Experience5–8 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted30 Sept 2026
About Flipkart
Flipkart is hiring in Bengaluru in ecommerce retail. This role looks for around 5+ years of experience.
Skills
- VAPT
- OWASP Top 10
- GCP
- Tenable
- Burp Suite
- Postman
- Microsoft Sentinel
- NIST
- ISO 27001
- RBI guidelines
The role
An application security engineer at a marketplace finance company conducts VAPT and GCP security reviews for web applications, mobile apps, APIs, and infrastructure, applies OWASP Top 10, and manages vulnerability remediation. The role also uses Burp Suite and Tenable to validate findings and support regulatory audits.
Full job description
About the Company
Location: Bangalore
Team: Information Security / AppSec
Experience: 5–8+ Years
As a Senior Security Engineer at Flipkart Finance Private Limited (FFPL), you will be the technical cornerstone of our security posture. This is a high-impact, hands-on role requiring a blend of technical expertise in Vulnerability Assessment and Penetration Testing (VAPT) and strong stakeholder management skills. You will oversee the end-to-end security lifecycle of our products, cloud infrastructure (GCP), and third-party integrations, ensuring that FFPL remains resilient against evolving threats while maintaining compliance with rigorous financial regulations.
About the Role
As a Senior Security Engineer at Flipkart Finance Private Limited (FFPL), you will be the technical cornerstone of our security posture, overseeing the end-to-end security lifecycle of our products, cloud infrastructure (GCP), and third-party integrations, while ensuring resilience against evolving threats and compliance with rigorous financial regulations.
Responsibilities
Key Responsibilities
1. Hands-on Technical Testing (VAPT)Conduct comprehensive Vulnerability Assessments (VA) and Penetration Testing (PT) across FFPL’s ecosystem, including Web Applications, Mobile Apps (Android/iOS), APIs, and Infrastructure.Perform deep-dive Cloud Security Reviews, specifically focusing on Google Cloud Platform (GCP) environments.Execute independent security testing to validate the integrity of new features before they go live.
2. Vendor & Stakeholder LiaisonAct as the primary technical point of contact for external VAPT vendors and third-party development partners.Organize and lead walkthroughs between external testers and the FFPL Product/Engineering teams.Clarify technical requirements for external teams and evaluate the quality and performance of vendor-led security assessments.
3. Vulnerability Management & RemediationCollate vulnerabilities from multiple sources: manual testing, automated tools, and external reports.Analyze findings, perform revalidation/retesting, and share actionable insights with the development team.Manage a centralized VA/PT Tracker, ensuring every finding is tracked from discovery to verified closure with valid Evidence of Closure (EoC) and Proof of Concept (PoC).
4. Cloud Security & Infrastructure CollaborationPartner closely with SRE (Site Reliability Engineering) to remediate infrastructure gaps.Manage and monitor security tools including Ox, Tenable, Sentinel (XDR), and Google Security Command Center (SCC).Collaborate with Group Flipkart AppSec and IT teams for the installation, licensing, and upgrading of security software.
5. Compliance & Audit SupportMaintain meticulous records of security testing and remediation for regulatory scrutiny.Support the organization during audits such as ISO 27001 LA, NIST 2.0, and RBI IS Audits, providing necessary technical evidence and documentation.Support the CISO in a couple of other random activities on a need basis.
Qualifications
Experience: 5–8+ Years
Required Skills
VAPT Excellence: Proven experience in manual and automated testing for OWASP Top 10 (Web/API/Mobile).Cloud Security: Deep familiarity with GCP (IAM, VPC Service Controls, GKE security, etc.).Tooling: Proficiency with Tenable, Burp Suite, Postman (API testing), and XDR solutions like Microsoft Sentinel.Compliance Knowledge: Understanding of financial sector regulations (RBI guidelines) and security frameworks (NIST, ISO).
Preferred Skills
Certifications: OSCP, CEH, CISSP, or Google Professional Cloud Security Engineer.Experience: Prior experience in FinTech or Banking sectors is a massive plus.Communication: Ability to translate complex technical vulnerabilities into business risk for non-technical stakeholders.