Staff Security Engineer

2 Minutes ago • 5 Years + • Cyber Security

Job Summary

Job Description

We're looking for a Senior Security Engineer with deep technical expertise in application security, penetration testing, and offensive security practices. You will lead efforts to proactively identify and exploit vulnerabilities across our products and infrastructure, working alongside engineering and security teams to design robust defences and build security into everything we deploy. This hands-on technical role involves performing code reviews, threat modeling, conducting penetration tests against web applications, APIs, and cloud environments, and planning red team operations. You will also mentor junior team members, support security audits, and contribute to incident response, significantly influencing the company's security posture from code to cloud.
Must have:
  • Perform code reviews, threat modelling, and architecture assessments across internal and customer-facing applications.
  • Guide engineering teams on secure design patterns, libraries, and development practices.
  • Integrate and maintain security tooling (SAST, DAST, SCA) into CI/CD pipelines.
  • Collaborate with product and engineering teams to remediate identified vulnerabilities and design secure solutions.
  • Conduct manual and automated penetration tests against Ethos Web Application, APIs, infrastructure, and cloud environments.
  • Simulate attacker behaviors to assess technical weaknesses and business risks.
  • Create detailed, developer-friendly reports with risk ratings and actionable remediation guidance.
  • Re-test findings and validate security fixes in collaboration with product owners.
  • Plan and execute red team operations, simulating advanced persistent threat (APT) scenarios.
  • Develop custom tools, scripts, and exploits to test detection and response capabilities.
  • Collaborate to improve detection, logging, and incident response based on attack insights.
  • Contribute to the development of offensive security playbooks and adversary emulation plans.
  • Mentor junior team members and evangelize security best practices across the company.
  • Participate in investigations, threat hunting, and incident response activities; build playbooks for specific incident response scenarios
  • Communicate risks to engineering staff through training and technical demonstration of vulnerabilities and secure design patterns
  • Support security audits, compliance efforts, and executive briefings with technical depth.
Good to have:
  • OSCP certification
  • OSWE certification
  • OSEP certification
  • GXPN certification
  • Threat modeling methodologies
  • STRIDE
  • PASTA
  • MITRE ATT&CK
  • Adversary emulation
  • Purple teaming
  • Security research
  • Open-source tools
  • Bug bounty platforms

Job Details

About the Role:

We're looking for a Senior Security Engineer with deep technical expertise in application security, penetration testing, and offensive security practices. You will lead efforts to proactively identify and exploit vulnerabilities across our products and infrastructure, working alongside engineering and security teams to design robust defences and build security into everything we deploy.

This is a hands-on technical role with significant influence over the security posture of the company, from code to cloud.

Duties and Responsibilities:

----------------------------

Application Security

  • Perform code reviews, threat modelling, and architecture assessments across internal and customer-facing applications.
  • Guide engineering teams on secure design patterns, libraries, and development practices.
  • Integrate and maintain security tooling (SAST, DAST, SCA) into CI/CD pipelines.
  • Collaborate with product and engineering teams to remediate identified vulnerabilities and design secure solutions.

Penetration Testing

  • Conduct manual and automated penetration tests against Ethos Web Application, APIs, infrastructure, and cloud environments.
  • Simulate attacker behaviors to assess technical weaknesses and business risks.
  • Create detailed, developer-friendly reports with risk ratings and actionable remediation guidance.
  • Re-test findings and validate security fixes in collaboration with product owners.

Offensive Security

  • Plan and execute red team operations, simulating advanced persistent threat (APT) scenarios.
  • Develop custom tools, scripts, and exploits to test detection and response capabilities.
  • Collaborate to improve detection, logging, and incident response based on attack insights.
  • Contribute to the development of offensive security playbooks and adversary emulation plans.

Other Responsibilities

  • Mentor junior team members and evangelize security best practices across the company.
  • Participate in investigations, threat hunting, and incident response activities; build playbooks for specific incident response scenarios
  • Communicate risks to engineering staff through training and technical demonstration of vulnerabilities and secure design patterns
  • Support security audits, compliance efforts, and executive briefings with technical depth.

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in Bengaluru, Karnataka, India

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Cyber Security Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

Ethos was built to make it faster and easier to get term life insurance. Our approach blends industry expertise, technology, and the human touch to find you the right policy to protect your loved ones. Using predictive analytics, we are able to transform a traditionally 15-week process into a modern digital experience for our users. Ethos has raised over $400 million from Sequoia Capital, SoftBank Vision Fund 2, Accel, and Google Ventures (GV). We are scaling quickly and looking for passionate people to join us in our mission to protect the next million families!

Bengaluru, Karnataka, India (Hybrid)

Bengaluru, Karnataka, India (Hybrid)

Bengaluru, Karnataka, India (On-Site)

United States (Remote)

Bengaluru, Karnataka, India (Hybrid)

United States (Remote)

Bengaluru, Karnataka, India (Hybrid)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

View All Jobs

Get notified when new jobs are added by Ethos Life

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug