Website:
oolka.ai
Job details:
About the role
Oolka is looking for a hands-on senior security engineer to own security across our AWS infrastructure, application layer, and data protection posture for a consumer fintech platform handling sensitive financial and personal data.
Two things make this role unusual. First, it's genuinely full-stack security — cloud, application, and data, rather than one lane. Second, we're shipping AI-assisted features into a product that touches real financial data, which means you'd be designing the security model for those features at the same time as you're running the foundations underneath them.
You'll work alongside engineering to build security into the SDLC rather than bolting it on afterward. Expect to move between AWS console and Terraform, code review, AI feature design reviews, and the occasional policy document or audit response.
What you'll own
AI/LLM security. We're putting LLM-backed features in front of customer financial data, and the threat model doesn't map cleanly onto anything established. You'd own:
- Agent permissions — scoping tool and API access, credential handling for model-initiated calls, and human-approval gates on high-impact actions the model can't route around
- Prompt injection defence — direct and indirect (retrieved documents, user-supplied content entering the context window), plus testing that defences hold
- Data boundaries and output trust — what reaches the context window, tenant isolation in retrieval, PII in prompts and inference logs, and treating model output as untrusted input to downstream systems
- Assurance — adversarial testing before release, regression testing as prompts and models change, and third-party model risk (data processing terms, where inference happens)
In line with current OWASP LLM guidance, but we're looking for someone who's solved this in production rather than read about it.
Cloud infrastructure and threat detection. Design and maintain our AWS security baseline — account structure, network segmentation, IAM least-privilege — and run our detection stack (GuardDuty, Security Hub, CloudTrail, Config). You'll be first responder when something looks anomalous, and you'll own the tooling that makes anomalies visible in the first place.
Data protection and PII. Encryption strategy (KMS key management, field-level encryption and tokenization for high-sensitivity data like PAN and credit information), data classification via Macie, and access governance across RDS, MongoDB and S3. You'll also own data handling policy for non-production environments — making sure real customer PII never reaches staging or QA.
Application security and vulnerability management. Build and maintain our SAST/SCA/secrets-scanning pipeline in CI/CD, triage and drive remediation with engineering teams, run or coordinate periodic penetration testing, and review code and architecture for injection flaws — SQL, NoSQL, and prompt injection in our AI-assisted features.
Perimeter and availability. WAF rule sets, DDoS posture (Shield, rate limiting), and API-level abuse protection — balancing controls against legitimate traffic and product experience.
Governance and incident response. Maintain our incident response plan and run periodic tabletop exercises alongside our existing DR drill practice, support ISO 27001 / RBI / DPDP-aligned control documentation, and represent security in external audits. Your runbooks will need to cover AI-specific incidents too — a successful injection, an agent acting outside its intended scope, PII surfacing in model output.
What you'll need
- 4–8+ years in security engineering, with hands-on depth in at least two of: cloud security (AWS strongly preferred), application security, or data protection engineering — plus working familiarity with the others
- Practical experience with AWS security services (GuardDuty, Security Hub, IAM, KMS, WAF, Shield), not just conceptual knowledge
- Comfortable reading and reviewing application code, not just infrastructure. You don't need to be a full-time developer, but you should spot an injection flaw or an overprivileged service account in a PR
- Experience building or operating a CI/CD security pipeline (SAST/SCA/secrets scanning)
- Solid understanding of encryption, key management, and secure credential handling in production
- Enough familiarity with how LLM applications are built — context windows, retrieval, tool calling — to reason about where the trust boundaries sit
Strong pluses
- Experience securing an LLM or agentic feature in production, including permission scoping and approval gates
- Prior experience in regulated fintech or financial services (RBI cybersecurity framework, PCI-DSS, or equivalent regional regulation)
- Exposure to India's DPDP Act or equivalent data protection regimes
- Experience red-teaming AI systems, or building evaluation harnesses for adversarial inputs
- Relevant certifications (AWS Security Specialty, OSCP, CISSP) — a plus, but not a substitute for demonstrated hands-on work
How you'll work
You'll partner closely with engineering leadership rather than operating as a separate gatekeeping function. The goal is security that ships with the product, not security that blocks it afterward. Expect meaningful time in AWS console and Terraform, in code review, in AI feature design discussions, and in conversation with auditors.
Click on Apply to know more.