Security Engineering Lead
Security Engineering Lead
paragoncorp10-12 Years
- Posted 18 hours ago
- Be among the first 10 applicants
Job Description
About the Role
We're building out our Security Engineering function and looking for a Lead with a strong offensive security and application security background from high-scale, high-attack-surface consumer platforms (fintech, e-commerce, crypto/exchange, or ride-hailing). This person will own our offensive security, DevSecOps, and product security programs end-to-end, and help mature our security posture as we scale
Job Description
- Lead offensive security programs: penetration testing, red/purple team exercises, bug bounty, and continuous VAPT
- Own application security strategy: SAST/DAST/SCA integration, secure SDLC, and secure-by-design practices across engineering
- Lead vulnerability management and attack surface management programs across cloud (AWS/GCP), on-prem, and enterprise SaaS
- Drive incident response, threat intelligence, and security monitoring in partnership with the SOC function
- Partner with Infrastructure, Software Engineering, and GRC to embed security into the technology delivery lifecycle
- Evaluate emerging risk areas, including securing AI/LLM-generated code and safe enablement of agentic AI tooling, as the org adopts new technology
- Ensure compliance alignment (ISO 27001, PCI DSS, and applicable financial-sector regulations)
Requirements
- Bachelor's degree in Computer Science, Information Technology, Computer Engineering, or another STEM field
- Minimum 10 years in security engineering, including at least 5 years in a Lead or Manager capacity leading offensive security or application security functions
- Prior experience at a high-scale, high-attack-surface company, such as fintech, e-commerce, crypto exchange, or a large consumer platform
- Track record owning or maturing programs such as bug bounty, red/purple teaming, VAPT, or DevSecOps
- Bonus: active involvement in the security research/CTF community, published CVEs, or relevant certifications (OSCP, OSWE, OSEP, CISSP, etc.)
More Info
Key Skills
bug bounty
offensive security
attack surface management
OSWE
continuous VAPT
red purple team exercises
on-prem
CTF community
published CVEs
enterprise SaaS
SCA integration
secure-by-design practices
OSEP
