Security Engineer – Application & Cloud Security
Company: NStarX India Private Limited
Location: Hyderabad
Work Mode: Work from Office (WFO)
Experience: 6+ Years Employment Type: Full-Time
ABOUT NSTARX
NStarX is an AI-first, Cloud-first engineering services company built and led by practitioners. With over a decade of industry experience, we help organizations accelerate business value through AI, ML, Cloud, Automation, and Software Engineering.
ABOUT THE ROLE
We are looking for a Security Engineer to provide security assurance for a cloud-deployed AI application. The role focuses on application and cloud security, vulnerability assessment, identity and access management, security testing, and preparing security evidence for enterprise reviews and third-party penetration testing.
KEY RESPONSIBILITIES
- Execute and interpret SAST, SCA, secrets, and container image scanning across the codebase and CI/CD pipeline.
- Perform DAST against deployed applications and drive vulnerability remediation.
- Review and strengthen SSO/SAML authentication and RBAC authorization implementations.
- Assess authentication and authorization risks, including session management, privilege escalation, and IDOR.
- Implement and review AWS security controls including IAM, Secrets Manager, network controls, and least-privilege access.
- Identify and document security findings for current-state assessments and target architecture.
- Prepare security evidence, reports, and documentation for enterprise security reviews.
- Collaborate with engineering and DevOps teams to remediate security vulnerabilities.
- Support security readiness activities and prepare systems for third-party penetration testing.
REQUIRED SKILLS & EXPERIENCE
- 6+ years of experience in Application Security, Cloud Security, or Cybersecurity.
- Hands-on experience with SAST, SCA, DAST, secrets scanning, and container security tools.
- Strong experience in AWS Security, including IAM, Secrets Manager, networking, and least-privilege design.
- Strong understanding of SSO/SAML, authentication, authorization, RBAC, session security, IDOR, and privilege escalation.
- Ability to triage security findings and distinguish true vulnerabilities from false positives/noise.
- Experience integrating security controls into development and CI/CD workflows.
- Strong analytical, problem-solving, and technical documentation skills.
- Ability to communicate security findings effectively to both engineering teams and enterprise security stakeholders.
PREFERRED SKILLS
- Experience securing LLM / Generative AI applications.
- Knowledge of prompt injection, AI-generated data leakage, and model-gateway abuse.
- Experience with CI/CD pipeline security and DevSecOps.
- Experience preparing applications for VAPT / penetration testing.
- Certifications such as OSCP, CISSP, GWAPT, or equivalent.
To apply for this job email your details to recruiting@nstarxinc.com
