Angel One
Website:
angelone.in
Job details:
About Angel One:
Angel One is one of India’s fastest growing fin-techs, on a bold mission to make investing simple, smart, and inclusive for every Indian. With over 3+ crore clients, we’re building at scale – and building for impact.
Our Super App helps clients manage their investments, trade seamlessly, and access financial tools tailored to their goals. We are working to build personalized financial journeys for our clients, powered by new-age tech, AI, Machine Learning and Data Science.
We're a builder's company at heart. You’ll have the space to experiment, the freedom to move with velocity, and the mandate to make bold, user-first decisions – every single day.
The vibe? Think less hierarchy, more momentum. Everyone has a seat at the table and a shot to build something that lasts.
Be part of a team that’s scaling sustainably, thinking big, and building for the next billion.
Why You'll Love Working at Angel One!
- Tech Systems that run at Scale: From AI to real-time data infra, you’ll work on tech that’s ahead of the curve and solve problems that truly matter.
- Build one of India’s Leading Fintech Platform: We’re not just disrupting finance – we’re shaping how billion Indians access wealth.
- Own It. Drive It. Scale It: You’ll have the freedom to lead, the resources to build, and the opportunity to leave your mark.
- Empowered Growth: We invest in your growth and empower you to explore your full potential.
- Exceptional Benefits: Our comprehensive benefits package includes health insurance, wellness programs, learning & development opportunities, and more.
Lead Security Engineer – Security Assurance (Cloud & Offensive Security)
Location: Bengaluru / Mumbai
Department: Information Security – Security Assurance
Reports To: Security Manager / Senior Director – Security Assurance
About the Role
Angel One is looking for an experienced Senior Security Engineer – Security Assurance to strengthen its offensive security capabilities across cloud, applications, infrastructure, APIs, Kubernetes, and enterprise environments.
This is a highly technical, hands-on role focused on Vulnerability Assessment and Penetration Testing (VAPT), cloud exploitation, adversary emulation, and security validation. The successful candidate will go beyond identifying vulnerabilities—they will demonstrate exploitability, assess business impact, and provide actionable remediation guidance to engineering teams.
The ideal candidate should have deep expertise in offensive security techniques across AWS, GCP, or Azure, with a strong understanding of modern cloud-native architectures, containerized workloads, identity systems, and CI/CD pipelines. They should be capable of conducting manual penetration testing, chaining vulnerabilities, and simulating realistic attack scenarios.
Key Responsibilities
1. Vulnerability Assessment & Penetration Testing (Primary Responsibility)
Plan and execute end-to-end VAPT engagements across Angel One's technology landscape, including:
- Web applications
- Mobile applications (Android & iOS)
- APIs (REST, GraphQL, gRPC)
- Internal and external infrastructure
- Cloud environments
- Containers and Kubernetes
- Perform both automated and manual testing to identify vulnerabilities, validate findings, and assess real-world exploitability.
2. Cloud Offensive Security (Primary Responsibility)
Conduct offensive security assessments across AWS, Azure, and GCP environments.
Identify and exploit cloud-specific weaknesses, including:
- IAM privilege escalation
- Misconfigured storage services
- Over-permissive roles and policies
- Serverless function vulnerabilities
- Metadata service abuse
- Kubernetes RBAC weaknesses
- Container escape scenarios
- Secrets exposure
- Insecure CI/CD pipelines
- Cross-account trust issues
- Publicly exposed cloud services
- Network segmentation bypass
- Identity federation weaknesses
- Validate the business impact of cloud misconfigurations through controlled exploitation.
3. Manual Penetration Testing
Perform advanced manual testing to identify vulnerabilities not detected by automated tools, including:
- Authentication and authorization flaws
- Business logic vulnerabilities
- Chained attack paths
- Insecure object references
- API abuse
- SSRF
- RCE
- XXE
- Deserialization attacks
- OAuth/OIDC implementation issues
- JWT weaknesses
- Cloud-native attack paths
- Demonstrate proof-of-concept exploits while adhering to established safety and change-management procedures.
4. Adversary Simulation & Exploitation
Conduct controlled adversary simulations to evaluate the effectiveness of preventive and detective controls.
Execute:
- Privilege escalation
- Lateral movement
- Credential attacks
- Cloud identity attacks
- Attack-path validation
- Défense evasion techniques (where authorized)
- Attack chain simulations
- Map findings to the MITRE ATT&CK framework and provide recommendations to strengthen detection and response capabilities.
5. Container & Kubernetes Security Testing
Assess the security of containerized environments by evaluating:
- Kubernetes API exposure
- RBAC configurations
- Admission controller policies
- Network policies
- Secrets management
- Image security
- Pod Security Standards
- Container runtime configurations
- Service account permissions
- Validate container escape and privilege escalation scenarios in authorized environments
.
6. Application Security Assessments
Perform in-depth security assessments of applications throughout the SDLC, including:
- Source-assisted testing (when applicable)
- API testing
- Authentication flows
- Authorization controls
- Session management
- Input validation
- Encryption implementations
- Secure coding practices
- Collaborate with developers to explain findings and recommend secure remediation strategies.
7. Vulnerability Validation
Review findings from SAST, DAST, SCA, cloud security tools, and infrastructure scanners.
Validate:
- True positives
- Exploitability
- Business impact
- Severity
- Remediation effectiveness
- Reduce false positives and ensure consistent risk ratings
Required Technical Skills
Mandatory
- Strong expertise in manual penetration testing
- Hands-on experience with cloud exploitation (AWS, Azure, and/or GCP)
- Deep understanding of web application and API security
- Experience with container and Kubernetes security testing
- Ability to validate exploitability beyond automated scanner findings
- Strong knowledge of authentication and authorization mechanisms
- Familiarity with attack-path analysis and offensive security methodologies
- Experience testing for: OWASP Top 10, OWASP API Security Top 10
- Experience with scripting in Python, Bash, or PowerShell to automate assessments is highly desirable.
Experience
- 7–10 years of experience in Information Security
- Minimum 4 years focused on penetration testing and offensive security
- Experience testing cloud-native applications and infrastructure
- Experience conducting manual exploitation beyond automated scanning
- Experience working with cloud engineering and DevSecOps teams
- Experience in financial services, fintech, or regulated environments is preferred
Qualifications
Bachelor's degree in Computer Science, Engineering, Information Security, or a related discipline.
Preferred certifications:
- OSCP (Highly Preferred)
- OSWE
- OSEP
- CRTO
- PNPT
- CARTP / CARTE
- AWS Certified Security – Specialty
- Google Professional Cloud Security Engineer
- Microsoft Certified: Azure Security Engineer Associate
- Burp Suite Certified Practitioner
- eCPPT
What Makes an Ideal Candidate
The ideal candidate is a technically accomplished offensive security professional who enjoys understanding how complex systems can be compromised—and using that knowledge to make them more secure. They are comfortable exploiting vulnerabilities in cloud-native environments, validating business impact, and partnering with engineering teams to eliminate risk. Beyond running tools, they understand modern architectures, think like an attacker, and can adapt to evolving technologies while maintaining the rigor expected in a regulated financial services environment.
Click on Apply to know more.