Sr Security Engineer

Hr · Hyderabad

  • Experience4–8 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelmid
  • Posted16 Sept 2026

About Hr

Hr is hiring in Hyderabad in technology software. This role looks for around 4+ years of experience.

Skills

  • cloud security
  • Application Security
  • Secure SDLC
  • Threat Modeling
  • DevSecOps
  • Vulnerability Assessments
  • Kubernetes
  • Docker
  • container security
  • SAST
  • DAST
  • SCA
  • REST APIs
  • microservices
  • IAM
  • secrets management
  • Python
  • Bash
  • Go

The role

A security engineer at a human resources software company designs cloud security controls, embeds application security and DevSecOps into software delivery, and secures Kubernetes workloads. The role also applies threat modeling and vulnerability assessments to SaaS products.

Full job description

Senior Security Engineer – Platform & Cloud Security

Location: Hyderabad / Bangalore

About Keka

Keka is one of India's fastest-growing HRTech SaaS companies, trusted by thousands of businesses globally. We build products that simplify HR, Payroll, Talent Management, and Employee Experience. Security is fundamental to everything we build, and we're looking for engineers who can help us build secure, scalable, and resilient products.

We're looking for a Senior Security Engineer who thrives in a product engineering environment and enjoys solving complex security challenges across cloud infrastructure, applications, and engineering platforms. This is a highly hands-on technical role where you'll work closely with Engineering, Platform, SRE, and Product teams to embed security throughout the software development lifecycle.

What You'll Do

Design and implement security controls across cloud-native infrastructure and SaaS applications.

Partner with Engineering teams to build security into every phase of the Software Development Lifecycle (SSDLC).

Perform threat modeling and security architecture reviews for new products and platform services.

Drive vulnerability management by identifying, prioritizing, and partnering with engineering teams to remediate risks.

Build and improve DevSecOps practices by integrating security tools into CI/CD pipelines.

Conduct application security assessments, secure code reviews, and penetration testing.

Secure Kubernetes workloads, containers, APIs, and cloud infrastructure.

Build automation to improve vulnerability detection, security monitoring, and remediation.

Investigate and respond to security incidents while driving root cause analysis and long-term fixes.

Collaborate with Platform Engineering and SRE teams to improve cloud security posture.

Evaluate third-party services and open-source components from a security perspective.

Mentor junior engineers and promote secure engineering practices across development teams.

Stay updated on emerging threats, cloud security trends, and modern attack techniques.

What We're Looking For

4–8 years of experience in Security Engineering, Product Security, Application Security, or Cloud Security.

Experience securing cloud platforms such as AWS, Azure, or GCP.

Hands-on experience with Kubernetes, Docker, and container security.

Strong understanding of Application Security and Secure SDLC practices.

Experience with Threat Modeling, Secure Design Reviews, and Architecture Reviews.

Hands-on experience with DevSecOps and integrating security into CI/CD pipelines.

Experience performing Vulnerability Assessments and working with engineering teams on remediation.

Knowledge of SAST, DAST, SCA, and modern application security tools.

Experience securing REST APIs and microservices.

Good understanding of IAM, secrets management, and cloud security best practices.

Hands-on scripting experience using Python, Bash, or Go for security automation.

Strong debugging and problem-solving skills.

Excellent collaboration and communication skills.

Good to Have

Experience with CSPM solutions such as Wiz, Prisma Cloud, Lacework, or Microsoft Defender for Cloud.

Exposure to Infrastructure as Code security (Terraform, CloudFormation).

Experience with API security testing.

Familiarity with Zero Trust architecture.

Experience with SOC 2, ISO 27001, or GDPR compliance initiatives.

Exposure to AI/LLM security concepts and secure AI application development.

Security certifications such as Security+, AWS Security Specialty, CCSK, CCSP, or OSCP.

What Makes You Successful

You enjoy solving security problems rather than just identifying them.

You are comfortable working directly with software engineers and influencing design decisions.

You take ownership of security initiatives from design through implementation.

You automate repetitive security tasks wherever possible.

You stay curious and continuously learn about evolving threats and technologies.

You thrive in fast-paced, product-focused environments.

Why Join Keka?

Work on security challenges at SaaS scale.

Partner with high-performing engineering teams.

Build modern cloud-native security solutions.

Opportunity to influence the security posture of a rapidly growing global product.

High ownership, fast decision-making, and the ability to make a measurable impact.