Top

Senior Security Engineer

Navi Mumbai, Maharashtra, India

54 Days ago

Job Description


Company - Arcitech AI Location :?Turbhe, Navi Mumbai (On site) Experience :?5+ Years Budget - 12lpa Immediate Joiners preferred

About Arcitech :-</strong> Arcitech is an enterprise AI automation and software development company building modern, AI-native products at scale. Several of our products handle sensitive data, and security is central to how we build and ship. We are looking for a hands-on Senior Security Engineer to own the security of our applications and cloud infrastructure end to end.

About the Role:- This is a hands-on, implementation-focused role ? not an advisory one. You will spend most of your time finding real vulnerabilities, deploying real security controls, and securing real CI/CD pipelines and cloud environments. Our infrastructure is AWS-primary, and you will also help us introduce and secure additional, cost-optimized cloud and server environments as we grow. You will work directly with our product tech leads, our DevOps team, and an external security testing partner to take each product to a strong, audit-ready security posture. If you enjoy building and shipping security controls rather than only writing policy, this role is for you.

Key Responsibilities:- Application Security-

  • Conduct threat modeling on real application architectures, data flows, and APIs, producing

specific, actionable output.

  • Perform vulnerability assessments and penetration testing on web applications and APIs;

identify, prioritize, and track findings to closure.

  • Perform secure code review and partner with developers to fix vulnerabilities, with

attention to authentication, payment flows, data isolation, and PII handling.

  • Define and enforce a secure-coding standard tailored to our stack (Python/Django,

Node.js, React). Cloud & Infrastructure Security (AWS-Primary, Multi-Cloud Capable)-

  • Harden and continuously monitor our AWS environment (primary platform): IAM least-

privilege, network segmentation, encryption, logging (CloudTrail), and threat detection (GuardDuty, Inspector, or equivalent).

  • Implement and operate Cloud Security Posture Management (CSPM) to detect

misconfigurations and drift ? across AWS and any additional providers we adopt.

  • Apply portable, vendor-neutral security through Infrastructure as Code (Terraform) and

container/Kubernetes security, so controls travel with the workload regardless of provider.

  • Manage secrets properly (AWS Secrets Manager / Parameter Store or HashiCorp Vault)

and eliminate hardcoded credentials.

  • Work with the DevOps team to introduce and secure additional, cost-optimized server

environments (e.g., Azure or cost-focused providers), extending our security standards to each new platform.

  • Administer Linux servers and cloud environments with security as the default; support

uptime, scalability, and patching. DevSecOps & Pipeline Security-

  • Build and maintain security gates in CI/CD pipelines (Jenkins, GitHub Actions, or GitLab

CI/CD): SAST, DAST, software composition analysis, container image scanning, and IaC scanning.

  • Implement Infrastructure as Code security using Terraform or CloudFormation with

automated policy checks (e.g., Checkov, Trivy).

  • Deploy and validate developer-side security tooling and automate security tasks using

Python and/or Bash. Monitoring, Incident Response & Collaboration-

  • Set up centralized logging and monitoring (CloudWatch, ELK, Prometheus, Grafana, or

equivalent) with alerting and incident workflows.

  • Define and run an incident response process; investigate and remediate security incidents.
  • Work directly with tech leads, DevOps, QA, and developers to ensure controls are

implemented, not just recommended.

  • Coordinate an external security testing partner for periodic deep penetration testing, and

drive their findings to closure. Compliance & Audit Readiness-

  • Build and maintain the security artifacts required during enterprise customer due diligence

(security questionnaires, VAPT reports, data-handling documentation).

  • Establish practices aligned with relevant standards (e.g., OWASP, and PCI-DSS / data-

protection requirements where applicable).

Required Qualifications:-

  • 5+ years hands-on experience in application security, cloud security, and/or DevSecOps,

with controls you have personally implemented ? not only assessed or advised on.

  • AWS expertise (mandatory, primary). Deep, hands-on experience securing AWS

environments. Most of our infrastructure runs on AWS and will continue to.

  • A second cloud (required, demonstrated). Hands-on experience securing at least one

other provider ? Azure, GCP, or a cost-focused provider such as DigitalOcean, Hetzner, or OVH. This must be work you have actually delivered, not a willingness to learn.

  • Portable, vendor-neutral skills. Strong Infrastructure as Code (Terraform) and

container/Kubernetes security ? the skills that let security and workloads move safely between providers.

  • Application security depth. Proven experience with threat modeling, VAPT, and secure

code review on real applications and APIs.

  • CI/CD and IaC security. Hands-on experience integrating security into pipelines and

securing Infrastructure as Code (Terraform / CloudFormation).

  • Containers. Working experience securing Docker and Kubernetes environments.
  • Scripting. Practical Python and/or Bash for automation.
  • Tooling. Familiarity with SAST/DAST/SCA tools, vulnerability scanners, CSPM, and

monitoring stacks.

  • Linux. Solid Linux system administration.
  • Communication. Able to give a tech lead a clear, specific, prioritized list of what to fix and

why.

Job Overview


Job Function: IT/Computers - Software & Software Services

Job Type: Full Time

Workplace Type: On-site

Experience Level: Mid-Senior level

Salary: Competitive & Based on Experience

Experience: 5 - 6 yrs

Contact Information


Company Name: Arcot AI Solutions Private Limited

Recruiting People: HR Department

Website: https://www.arcotgroup.com/

Location

Important Alert:
Beware of people who promise you a job or interview in exchange for money. If someone asks you for money and says it's for something like a registration fee or a refundable deposit, it could be a scam. Please be cautious. Remember, elsejob.com does not guarantee a job or interview in exchange for money, so don't give money to anyone like that.

Similar Jobs

Wordpress Developer

Arcot AI Solutions Private Limited • Navi Mumbai, Maharashtra, India

Experience: 2 - 3 yrs

Salary: Competitive & Based on Experience

View Job
Full Stack Data Engineer

Unison Group • Navi Mumbai, Maharashtra, India

Salary: Competitive & Based on Experience

View Job
Software Tester - Automation

Arcot AI Solutions Private Limited • Navi Mumbai, Maharashtra, India

Experience: 2 - 4 yrs

Salary: Competitive & Based on Experience

View Job
C# Developer

Arcot AI Solutions Private Limited • Navi Mumbai, Maharashtra, India

Experience: 1 - 2 yrs

Salary: Competitive & Based on Experience

View Job
Sr. DOT NET Core Developer (Immediate)

Tech Firefly • Navi Mumbai, Maharashtra, India

Experience: 3 - 8 yrs

Salary: Competitive & Based on Experience

View Job
Sr. Java Developer - Hiring Immediately

Tech Firefly • Navi Mumbai, Maharashtra, India

Salary: Competitive & Based on Experience

View Job
Sr. DOT NET Core Developer (Immediate)

Tech Firefly • Navi Mumbai, Maharashtra, India

Salary: Competitive & Based on Experience

View Job
Field Operations Executive

Rentokil Initial • Navi Mumbai, Maharashtra, India

Salary: Competitive & Based on Experience

View Job
React Developer

Arcot Group • Navi Mumbai, Maharashtra, India

Salary: Competitive & Based on Experience

View Job
Technical Support Engineer

Carbon Clean • Navi Mumbai, Maharashtra, India

Experience: 3 - 4 yrs

Salary: Competitive & Based on Experience

View Job