Base Career helps you apply smarter for this job.
Key skills for this role
Angel One is looking for an experienced Senior Security Engineer – Security Assurance to strengthen its offensive security capabilities across cloud, applications, infrastructure, APIs, Kubernetes, and enterprise environments.
This is a highly technical, hands-on role focused on Vulnerability Assessment and Penetration Testing (VAPT), cloud exploitation, adversary emulation, and security validation. The successful candidate will go beyond identifying vulnerabilities—they will demonstrate exploitability, assess business impact, and provide actionable remediation guidance to engineering teams.
The ideal candidate should have deep expertise in offensive security techniques across AWS, GCP, or Azure, with a strong understanding of modern cloud-native architectures, containerized workloads, identity systems, and CI/CD pipelines. They should be capable of conducting manual penetration testing, chaining vulnerabilities, and simulating realistic attack scenarios.
Angel One is one of India’s fastest growing fin-techs, on a bold mission to make investing simple, smart, and inclusive for every Indian. With over 3+ crore clients, we’re building at scale – and building for impact.
Our Super App helps clients manage their investments, trade seamlessly, and access financial tools tailored to their goals. We are working to build personalized financial journeys for our clients, powered by new-age tech, AI, Machine Learning and Data Science.
We're a builder company at heart. You’ll have the space to experiment, the freedom to move with velocity, and the mandate to make bold, user-first decisions – every single day.
The vibe? Think less hierarchy, more momentum. Everyone has a seat at the table and a shot to build something that lasts.
Be part of a team that’s scaling sustainably, thinking big, and building for the next billion.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Tech Systems that run at Scale: From AI to real-time data infra, you’ll work on tech that’s ahead of the curve and solve problems that truly matter.
Build one of India’s Leading Fintech Platform: We’re not just disrupting finance – we’re shaping how billion Indians access wealth.
Own It. Drive It. Scale It: You’ll have the freedom to lead, the resources to build, and the opportunity to leave your mark.
Empowered Growth: We invest in your growth and empower you to explore your full potential.
Angel One is looking for an experienced Senior Security Engineer – Security Assurance to strengthen its offensive security capabilities across cloud, applications, infrastructure, APIs, Kubernetes, and enterprise environments.
This is a highly technical, hands-on role focused on Vulnerability Assessment and Penetration Testing (VAPT), cloud exploitation, adversary emulation, and security validation. The successful candidate will go beyond identifying vulnerabilities—they will demonstrate exploitability, assess business impact, and provide actionable remediation guidance to engineering teams.
The ideal candidate should have deep expertise in offensive security techniques across AWS, GCP, or Azure, with a strong understanding of modern cloud-native architectures, containerized workloads, identity systems, and CI/CD pipelines. They should be capable of conducting manual penetration testing, chaining vulnerabilities, and simulating realistic attack scenarios.
Perform advanced manual testing to identify vulnerabilities not detected by automated tools, including:
Authentication and authorization flaws
Business logic vulnerabilities
Chained attack paths
Insecure object references
API abuse
SSRF
RCE
XXE
Deserialization attacks
OAuth/OIDC implementation issues
JWT weaknesses
Cloud-native attack paths
Demonstrate proof-of-concept exploits while adhering to established safety and change-management procedures.
Conduct controlled adversary simulations to evaluate the effectiveness of preventive and detective controls.
Execute:
Privilege escalation
Lateral movement
Credential attacks
Cloud identity attacks
Attack-path validation
Défense evasion techniques (where authorized)
Attack chain simulations
Map findings to the MITRE ATT&CK framework and provide recommendations to strengthen detection and response capabilities.
Kubernetes API exposure
RBAC configurations
Admission controller policies
Network policies
Secrets management
Image security
Pod Security Standards
Container runtime configurations
Service account permissions
Validate container escape and privilege escalation scenarios in authorized environments.
True positives
Exploitability
Business impact
Severity
Remediation effectiveness
Reduce false positives and ensure consistent risk ratings
Strong expertise in manual penetration testing
Hands-on experience with cloud exploitation (AWS, Azure, and/or GCP)
Deep understanding of web application and API security
Experience with container and Kubernetes security testing
Ability to validate exploitability beyond automated scanner findings
Strong knowledge of authentication and authorization mechanisms
Familiarity with attack-path analysis and offensive security methodologies
Experience testing for: OWASP Top 10, OWASP API Security Top 10
Experience with scripting in Python, Bash, or PowerShell to automate assessments is highly desirable.
7–10 years of experience in Information Security
Minimum 4 years focused on penetration testing and offensive security
Experience testing cloud-native applications and infrastructure
Experience conducting manual exploitation beyond automated scanning
Experience working with cloud engineering and DevSecOps teams
Experience in financial services, fintech, or regulated environments is preferred
As an Equal opportunity employer, we wholeheartedly welcome people from all backgrounds irrespective of caste, religion, gender, marital status, sexuality, disability, class or age to be part of our team. We believe that everyone's unique experiences and viewpoints make us stronger together. Come and be a part of #OneSpace*, where your individuality is celebrated and embraced.
Indian publicly listed retail stockbroker serving investors through trading, investing, advisory, credit, wealth, and insurance services.
Visit company websiteJobs and hiring trendsFull-time
Senior · 4+ years experience
Onsite
Apply faster on company sites with our extension.