Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Expert Security Engineer - Offensive Security

AT Finastra
Finastra

Expert Security Engineer - Offensive Security

Bangalore, India

Responsibilities

What will you contribute?

As an Expert Offensive Security Engineer within the Cyber Defense Team, you'll lead offensive security assessments that strengthen our defense capabilities. Working closely with the larger InfoSec team, detection engineers, and external engineering partners, you'll identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You'll collaborate with various architecture and engineering teams to continuously validate and improve our security controls and detection capabilities, with a strong focus on developing repeatable testing frameworks and metrics-driven security improvements.

Want more jobs like this?

Get jobs delivered to your inbox every week.

Select a location
By signing up, you agree to our Terms of Service & Privacy Policy.


Responsibilities & Deliverables:

  • Lead Offensive Security Assessments: Conduct full-stack security assessments across our entire technology stack, including web and mobile applications, APIs, on-premises and cloud infrastructure, and backend systems.
  • Drive Detection Engineering Partnerships: Collaborate with detection engineers through purple team exercises, attack simulations, and threat emulation to improve detection coverage and response capabilities.
  • Develop Custom Tools and Frameworks: Build and maintain security testing tools, frameworks, and automation scripts using scripting languages (e.g., Python, Bash, PowerShell) and cloud platforms (AWS, Azure, GCP) to enable repeatable testing and quantifiable security improvements.
  • Enhance Cloud and Container Security: Develop and automate security checks for cloud environments (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes). Integrate security practices into CI/CD pipelines and Infrastructure as Code (IaC) deployments.
  • Strengthen API and Web Security: Secure and test APIs (RESTful, GraphQL) and modern web applications, addressing common vulnerabilities (e.g., OWASP Top Ten) and ensuring robust security measures are in place.
  • Build Security Metrics: Design and implement frameworks to measure security control effectiveness, detection coverage, and improvement over time through consistent testing methodologies.
  • Research and Innovate: Stay current with the latest attack techniques, tools, and methodologies while building out both offensive and defensive security improvements, including applying machine learning and AI techniques to security problems.
  • Mentor and Collaborate: Share knowledge across security teams and foster a culture of continuous security improvement. Mentor junior team members and provide guidance on best practices.
  • Project Management: Manage and lead security projects, including planning, execution, and delivery of offensive security assessments and initiatives. Coordinate with cross-functional teams, manage timelines, and ensure project goals are met.

Required Experience:

Professional Experience:

  • 5+ years of professional experience in offensive security, including red team and purple team exercises, penetration testing, and collaboration with detection engineering teams.
  • Proficiency in scripting languages (Python, Bash, PowerShell, JavaScript/TypeScript) and cloud platforms (AWS, Azure, GCP) for developing security tools, automation scripts, and securing cloud environments.
  • Experience with containerization (Docker, Kubernetes), Infrastructure as Code (Terraform, Ansible), CI/CD pipeline security, web and API security, reverse engineering, and applying machine learning to security problems.
  • Experience in conducting threat modeling and risk assessments to identify and mitigate potential security threats.

Security Assessment Expertise:

  • Expertise in conducting full-stack security assessments of web (including SPAs like React, Angular, .Net Blazor) and mobile applications (including React Native), APIs, on-premises and cloud infrastructure, and backend systems.

Deep Understanding:

  • In-depth knowledge of common attack techniques, exploit development, post-exploitation methodologies, security assessment frameworks (e.g., MITRE ATT&CK, PTES), and modern detection stack components (e.g., EDR, SIEM, XDR).

Knowledge:

  • Strong understanding of networking, operating systems, security protocols, and security concepts, including reverse engineering, cloud security (AWS/Azure), container security, CI/CD pipeline security, API security, and security metrics development.

Certifications:

  • Relevant certifications such as OSCP, OSCE, GXPN, or equivalent practical experience.

Interpersonal Skills:

  • Strong analytical and problem-solving abilities, excellent technical writing skills for detailed reports, ability to clearly communicate complex technical concepts, and a self-motivated passion for offensive security and detection engineering.

Project Management Skills:

  • Proven ability to manage and lead security projects, including planning, execution, and delivery of offensive security assessments and initiatives.
  • Experience in coordinating with cross-functional teams, managing timelines, and ensuring project goals are met.

Job Location: Bangalore

Client-provided location(s): Bengaluru, Karnataka, India; Guadalajara, Jalisco, Mexico; Pune, Maharashtra, India
Job ID: Finastra-10432
Employment Type: Full Time

Perks and Benefits

  • Health and Wellness

    • Vision Insurance
    • Life Insurance
    • Dental Insurance
    • Health Insurance
    • Mental Health Benefits
    • Health Reimbursement Account
    • Short-Term Disability
    • Long-Term Disability
    • Pet Insurance
    • FSA
    • HSA
  • Parental Benefits

    • Birth Parent or Maternity Leave
  • Work Flexibility

    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Happy Hours
    • Company Outings
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Unlimited Paid Time Off
    • Paid Holidays
    • Personal/Sick Days
    • Volunteer Time Off
  • Financial and Retirement

    • Financial Counseling
    • 401(K) With Company Matching
  • Professional Development

    • Internship Program
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Promote From Within
    • Access to Online Courses
    • Lunch and Learns