S

Security Engineer II

Setu · Bengaluru, Karnataka, India

full_timePosted 2w ago
Apply now →

Job description

**Security Engineer II** **4+ years of work experience** We at Setu are looking for those who share our core belief - “Every Day is Game Day”. We bring our best selves to work each day to realize our mission of enriching the world through the power of digital commerce and financial services. **Importance of the role** As a critical member of the Engineering team, you will be working on raising the bar by implementing and following security best practices. We're on the lookout for a passionate candidate who will have the capability to identify potential risks and craft solutions to eliminate those risks. You will be required to provide the Engineering and Product teams with your infrastructure security expertise to ensure that our products don't have any security flaws. **What will you do at Setu?** In this role, you’ll spend your time ● Lead in the development of security projects, processes, and initiatives within your technical focus area (cloud security, identity access management, vulnerability management, penetration testing, etc). ● Driving security audit requirements such as VAPTs. ● Contributing to automation of repeated manual tasks for compliance reporting and to improve team productivity. ● Contributing to automation of active scans that can detect security lapses in infra. ● Scoping activities of functional security assignments from product and engineering teams. ● Improving security operations by enhancing use cases, processes, and/or code structure. ● Enforcing secure coding practices via DevSecOps and bringing visibility to the current state of things. ● Collaborating with the broader team on security reviews that follow the standards and best practices of information security. **Who is the right fi t for this role?** To excel in this role, you will need— ● One or preferably two of these software programming skills: Python, Ruby, Golang, Rust, and a working knowledge of microservices application architecture. ● Thorough understanding of OWASP Top Ten for web, mobile, and APIs. ● Strong understanding of cloud-native architectures and microservices-based web and mobile applications including API contracts. ● Deep understanding of API security tooling like OAuth2.0, SAML, and Keycloak. ● To independently drive security posture enhancement projects like automation, threat modeling, 'security-as-code', application security validation, testing, QA integration, and vulnerability/bug remediation through calibration and fi ltering false positives. ● To use SAST and DAST tools like OWASP ZAP and BurpSuite. Experience in using manual and automated scanners like Nessus, Nexpose, QualysGuard, Nmap, and OpenVAS, Nexpose besides PT kits like Kali Linux, Metasploit. ● An in-depth understanding of at least a few security domains (application, network, identity access management, vulnerability management, incident response, encryption, remote access). ● Knowledge of Cloud security and DevSecOps practices on ECS & EKS based environments ● To be comfortable with tools like AWS WAF, AWS Detective Lambda, AWS Guardduty, AWS Shield, and AWS Inspector ● Working knowledge of SIEM and similar security posture tools. ● Combining red/blue team strategies to test and improve detection/response capabilities, including vulnerability scanning and network security ● Design and implement autonomous AI Agents and multi-agent systems to automate repetitive security tasks and workflows **Why join us at Setu?** **Why Setu?** We will spare no efforts to ensure that Setu empowers you to do the most important and impactful work of your career— - Opportunity to work closely with the founding team who built and scaled public infrastructure such as UPI, GST, Aadhaar, etc. - We care deeply about your growth. So we work hard to provide you with— - A fully stocked library and unlimited book budget. - Tickets to conferences and industry events. - Learning sessions where we invite both team members and external experts to teach you something new. - Learning and development allowance that gives access to subscriptions, courses, certifications, music classes, and much more. Grow, learn, and improve with Setu! - Kick-ass benefits including comprehensive health insurance for you and your family, personal accident and term life insurance, access to mental health counsellors, extraordinary coffee, and a beautiful office with lots of solid wood and natural light. - We work hard to make sure our team is diverse and varied. We interview and hire purely on merit, skill, and competence—everything else is irrelevant. **Our core DNA** Our culture code—How We Move, defines the behaviors we expect from our people. When you display any of the six culture code elements, you demonstrate ‘Every Day is Game Day’. The six elements of our culture code— - **Take the shot:** You decide fast and deliver right. - **Sign your work like an artist:** You master what you do and take pride in it. - **Be the sherpa:** You lead your crew on every expedition. - **Be the CEO of what you do:** You own it and make things happen. - **Care with tough love:** You empower others with trust, respect, and openness. - **Own tomorrow:** You innovate for the customer and beyond. Join us if you want to be part of a company that’s building infrastructure that will directly impact financial inclusion and improve millions of lives. No cashbacks, no growth-hacks, no gimmicks. Just an audacious mission, and an obsession with craftsmanship in code.