Role Summary
IronTrex is seeking a highly experienced Lead Cybersecurity & Application Security Engineer to own and drive the end-to-end security posture of our platform and internal systems. This role blends offensive security (penetration testing, red teaming) with defensive security (incident response, threat prevention, employee protection).
The ideal candidate will think like an attacker, act like a defender, and work closely with engineering and IT teams to proactively identify, exploit and remediate vulnerabilities across mobile apps, APIs, backend systems and internal infrastructure. This is a hands-on, high-impact role critical to protecting the company, employees and users from both external and internal cyber threats.
Location: Hyderabad – On-site | Employment Type: Full-Time | Experience: 5–6+ years | Level: Senior / Principal Engineer
Key Responsibilities
1. Application Security & Penetration Testing
- Lead and execute manual and automated penetration testing for mobile applications (Android / iOS), backend services and APIs, and admin panels and internal dashboards
- Perform deep testing aligned with OWASP Top 10, including authentication & authorization bypass, broken access control, business logic abuse, session and token hijacking, and API abuse and rate-limit bypass
- Identify, validate and document vulnerabilities with proof-of-concept exploits
- Work closely with engineering teams to prioritise remediation, validate fixes, and perform re-testing and closure
2. Phishing Detection & Social Engineering Defense
- Design and execute phishing simulations targeting email-based phishing, credential harvesting attacks, and MFA fatigue and social engineering attacks
- Evaluate and improve phishing detection mechanisms within the IronTrex app
- Track and report metrics such as click rates, credential submission rates and reporting behaviour
- Conduct security awareness programs and simulations for employees
3. Internal Security & Insider Threat Protection
- Simulate internal attack scenarios including lateral movement, privilege escalation, abuse of misconfigured permissions and insider threat scenarios
- Review and validate role-based access control (RBAC), least-privilege enforcement, and identity and access configurations
- Identify high-risk access paths and recommend corrective controls
4. External Threat Defense & Risk Assessment
- Assess exposure to web application attacks, API scraping and abuse, and dependency and third-party risks
- Perform threat modelling across application and infrastructure layers
- Track emerging threats, zero-day vulnerabilities and industry attack trends
- Advise leadership on security risks tied to architecture and product decisions
5. Incident Detection, Response & Forensics
- Design and validate incident response playbooks
- Lead response efforts during active attacks and data exposure or breach scenarios
- Perform root cause analysis (RCA) and post-incident reviews
- Recommend preventive controls to avoid recurrence
6. Collaboration with IT Admin & Engineering Teams
- Work alongside IT Admins to validate MDM, endpoint and access controls, challenge security assumptions and test real-world enforcement effectiveness
- Partner with engineering teams to embed security-by-design into development workflows
- Act as the final authority on security approvals, risk exceptions and mitigations
7. Preventive Security & Secure SDLC
- Drive secure development practices across the organisation
- Support DevSecOps initiatives including secure coding guidance, secrets management best practices and secure API design reviews
- Review and validate logging, monitoring and alerting mechanisms
8. Reporting, Governance & Executive Communication
- Maintain a centralised security risk register
- Deliver vulnerability trend reports, security posture summaries and executive-level security briefings
- Support compliance readiness, audits and investor security reviews
Required Technical Skills
Offensive & Application Security
- Strong hands-on experience with web, mobile and API penetration testing
- OWASP Top 10 vulnerabilities; authentication and authorization flaws
- Manual exploitation, proof-of-concept development, vulnerability validation and re-testing
Defensive Security & Incident Response
- Strong understanding of identity & access security, endpoint and internal threat detection, and security logging and alerting
- Experience handling live security incidents, breach investigations and root cause analysis
Tools & Platforms (representative, not exhaustive)
- Burp Suite, OWASP ZAP, Nuclei, Metasploit
- API testing tools (Postman, custom scripts)
- Security testing automation tools
- SIEM and log analysis tools (Splunk, ELK or equivalent)
- Cloud security exposure (AWS / GCP / Azure)
Professional Qualifications
- 5–6+ years of hands-on cybersecurity experience
- Proven experience in penetration testing, application security and incident response
- Prior experience in SaaS, fintech or startup environments preferred
- Ability to clearly explain security risks to non-technical stakeholders
- Strong documentation, reporting and communication skills