Senior Security Engineer

Vegapay Technology Private LimitedBengaluru, KarnatakaOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

The Impact You’ll Drive We're looking for a Senior Security Engineer to own key pillars of Vegapay's security program across application security, cloud security, security operations, and compliance. You will be the hands-on technical anchor of the security team: leading VAPT and secure design reviews, hardening our cloud and container environments, running detection and incident response, and driving audit readiness across PCI DSS, ISO 27001, SOC 2, and CICRA. Reporting to the Head of Information Security, you will set technical standards, mentor engineers and analysts, and act as a trusted security partner to engineering, product, and our banking and NBFC partners.
The Hats You Will Wear
- Lead and mentor a high-performing team of engineers, providing strategic technical guidance and driving career development to cultivate future leaders.
- Champion a collaborative, inclusive team culture while conducting in-depth performance reviews, offering actionable feedback to elevate individual and team capabilities.
- Spearhead the technical execution of complex projects, ensuring successful delivery within scope, timeline, and budget, while aligning solutions with overarching business objectives.
- Architect and design scalable, high-impact software systems, providing oversight on technical designs, code quality, and system architecture to ensure robustness and efficiency.
- Stay ahead of industry advancements, integrating cutting-edge innovations into projects to maintain a competitive edge.
- Define and enforce best practices for coding standards, testing, and deployment, ensuring the highest levels of reliability, performance, and security.
- Drive code reviews and advocate for the adoption of automated testing methodologies to elevate product quality and development efficiency.
- Collaborate closely with cross-functional teams, articulating complex technical concepts to non-technical stakeholders and bridging communication gaps between teams.
- Proactively identify and mitigate technical risks, providing expert-level problem-solving to ensure smooth project execution.
- Foster a culture of continuous improvement, innovation, and technical excellence, inspiring teams to push boundaries and deliver transformative solutions.

The Perfect Fit
- 6+ years of experience in information security, with depth in at least two of: application security, cloud security, security operations, or GRC.
- Strong hands-on VAPT experience across web, mobile, API, and network, with a proven ability to find and exploit complex business-logic vulnerabilities.
- Deep knowledge of OWASP Top 10 and common attack and defense techniques, plus working familiarity with MITRE ATT&CK and CIS Benchmarks.
- Proficiency with commercial and open-source tools such as Burp Suite, OWASP ZAP, Metasploit, Nessus, Qualys, Snyk, SonarQube, Trivy, and Wazuh.
- Practical experience in security monitoring and incident response using SIEM/XDR tools, including detection tuning and running investigations.
- Strong cloud security fundamentals in AWS (preferred), GCP, or Azure, including IAM hardening, S3, load balancers, Kubernetes, and Docker.
- Hands-on experience running or significantly contributing to compliance programs such as PCI DSS, ISO 27001, SOC 2, CICRA, NIST, or RBI guidelines, including direct auditor interactions.
- Solid understanding of authentication and authorization standards: OAuth 2.0, OIDC, and SAML.
- Ability to read and review Java code, and to script in Python or Bash; familiarity with securing IaC (Terraform, Ansible).
- Ability to communicate security risks clearly to both technical and non-technical stakeholders, and to influence without direct authority.
Your Edge Over the Rest
- Bachelor's or Master's degree in Computer Science, Information Security, or a related field
- Industry-recognized certifications such as OSCP, CISSP, CISA, CEH, CCSP, or AWS Security Specialty
- Prior experience in FinTech, SaaS, or other regulated environments, especially card, lending, or UPI systems
- Experience mentoring security engineers or leading security initiatives across multiple teams
- Exceptional communication and documentation skills, with the ability to align security practices with business goals

The Problem We’re Solving Financial institutions today are held back by legacy systems that are slow, rigid, and expensive to scale. Launching or evolving credit, lending, and UPI products often takes months, requires heavy engineering effort, and limits the ability to create personalized customer experiences.
At the same time, customer expectations have changed - speed, flexibility, and tailored financial products are no longer optional. Banks and fintechs need infrastructure that allows them to innovate quickly, adapt continuously, and scale without friction.
This is where we come in.
At Vegapay, we are building modern, configurable fintech infrastructure that enables banks, NBFCs, and enterprises to design, launch, and manage credit and payment programs with ease. Our platform brings together flexibility, speed, and control - helping our partners unlock new growth opportunities and deliver personalized banking experiences at scale.
The Opportunity Ahead
- Lead and shape high-impact engineering teams building real-world fintech infrastructure
- Drive both technical direction and team growth - with real ownership and decision-making authority
- Work on complex, scalable systems that directly power banking, credit, and payments
- Collaborate with strong product and leadership teams in a fast-moving, execution-first environment