CareerScanCareerScan
JobsCompanies
BlogContact
For Employers
Sign InRegister Free
CareerScanCareerScan

India's verified job platform connecting candidates directly with employers. 100% free applications with instant ATS resume scoring.

Chennai, Bengaluru & Hyderabad
Jobs by location
Jobs in ChennaiJobs in BengaluruJobs in HyderabadJobs in PuneJobs in Mumbai
Popular roles
AR Caller JobsHealthcare Medical CodingReact / Full Stack DeveloperData & Power BI AnalystCustomer Support Executive
Top companies
TCS CareersCognizant JobsInfosys OpeningsApollo HospitalsOmega Healthcare
Career services
Free ATS Resume CheckerAI Resume Builder (Free)AI Job MatcherSalary Guide & BenchmarksJob Alerts on WhatsApp
© 2026 CareerScan India. All rights reserved.256-bit SSL encrypted & verified
Back to all jobs
  1. Home
  2. Jobs
  3. Senior Security Engineer
SmartStream
SmartStream

Senior Security Engineer

Bengaluru, Karnataka, India
7+ years exp
Full-time
Posted 2d ago
0 views
Actively Hiring Direct 1-Click Apply

Check Your Resume Match Score

Scan your resume against ATS criteria for this Senior Security Engineer role at SmartStream.

Apply for this position

Apply on Company Website
Notice a broken link or wrong info?

Job Description

As a Senior Security Engineer at Smartstream, you will join our Security Engineering Centre of Excellence and serve as a senior technical member across the entire Security Engineering function. You'll be the escalation point for embedded Security Engineers and Security Champions on the most complex problems - novel vulnerability classes, adversarial-AI scenarios, LLM-driven code-scan findings, and regulator-mandated threat-led penetration tests.

This is a hands-on, deeply technical individual-contributor role. You will write code, build tooling, perform tool integrations, run scans across a large enterprise codebase, mentor peers, and help shape how Smartstream uses AI inside the Secure SDLC.

You will work upstream of the VulnOps function, which owns the unified vulnerability backlog and remediation pipeline. Your focus is on original analysis, novel vulnerability classes, adversarial AI, complex penetration testing, variant analysis, and technical mentoring - findings you produce or validate flow into the VulnOps backlog for tracked closure under SLA.

Requirements

  • LLM-based code scanning.

Own and operate LLM-assisted code scanning across the Smartstream product portfolio. Tune prompts and pipelines, triage false positives, validate and demonstrate exploitability of findings where necessary, and drive remediation through the VulnOps backlog in partnership with engineering teams.

  • SAST/DAST escalation support

. Act as the technical authority for embedded Security Engineers and developers on hard SAST and DAST findings, exploitability assessment, fix design, false-positives elimination, and pattern publication.

  • Adversarial AI & blue team.

Run the in-house adversarial-AI simulation platform and blue-team activities. Manage outsourced red-team engagements and route findings into the VulnOps backlog.

  • DORA TLPT technical lead.

Provide the technical lead during DORA Article 26 threat-led penetration tests when financial-institution customers pull Smartstream into scope.

  • Variant analysis.

Lead variant analysis whenever a Critical/High finding is confirmed - identify similar attack vectors across the codebase, produce engineering-grade remediation guidance, and feed the resulting issue set into VulnOps for tracked closure.

  • Internal pen testing.

Lead internal web-application pen testing (OWASP Top 10, SANS Top 25). Scope and sign off release pen tests; manage outsourced pen-test engagements jointly with the Security Engineering Manager. Findings flow into the VulnOps backlog.

  • Cryptography & Secrets Management

Provide guidance on approved cryptographic libraries, TLS, key management, and secrets handling practices. Partner with engineering teams to ensure secure implementation across products

  • Supply-chain & secret-scanning advisory.

Set the technical strategy for SBOM, supply-chain scanning, and secret-scanning detection - what to scan, how to interpret reachability, how to triage high-impact dependency CVEs, and which detection rules to use. Operational pipeline ownership sits with VulnOps; the Senior SE owns the technical part of it.

  • Mentoring & enablement.

Lead the Security Champions mentoring programme. Run developer security training workshops. Be the escalation path for embedded SEs on novel findings.

  • Culture.

Evangelise a security-first culture across engineering - code reviews, design reviews, brown bags, internal comms.

  • Customer-facing pen tests.

Support annual customer-driven penetration tests of Smartstream products.

Required qualifications

  • 7+ years in application / product security, including hands-on offensive (pen testing) and defensive (secure SDLC, code review) work.
  • Strong programming background in at least two of: Java, Python, JavaScript/TypeScript, Go, C#.
  • Demonstrable experience running SAST/DAST/SCA at scale and triaging output with low false-positive rates.
  • Hands-on with modern static-analysis variant-analysis tooling.
  • Deep familiarity with OWASP Top 10, SANS Top 25, ASVS, and modern web-app attack patterns.
  • Experience operating enterprise-grade DAST tooling for authenticated scans.
  • Track record mentoring developers and running internal security workshops.

Preferred qualifications

  • OSCP, GWAPT, GPEN, OSWE, or equivalent.
  • Experience with LLM-assisted security tooling (code scanning, threat modelling, fuzzing).
  • Experience with adversarial AI / red-team automation platforms.
  • Prior involvement in DORA TLPT will be a plus
  • Cryptography depth (TLS, key management, HSMs, post-quantum awareness).
  • Active contributions to open-source security tools, CVEs, or research.

Key Skills

Application Security, Penetration Testing, OWASP Top 10, SANS Top 25, ASVS, SAST, DAST, SCA, Variant Analysis, Code Review, Threat Modelling, Cryptography, TLS, Key Management, Secret Scanning, Web Application Security, Java, Python, JavaScript, TypeScript, LLM Security, AI Security, Secure SDLC.

Desired Skills

OSCP, GWAPT, GPEN, OSWE, DORA TLPT, Adversarial Red Team, Blue Team, Post-Quantum Cryptography, Open-Source Security Research, CVE Disclosure.

Benefits & Perks

ptography & Secrets Management** Provide guidance on approved cryptographic libraries, TLS, key management, and secrets handling practices. Partner with engineering teams to ensure secure implementation across products

Frequently Asked Questions

How to apply for Senior Security Engineer at SmartStream?

Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.

What is the salary for this role?

Salary details will be discussed during the interview.

What experience is required?

7+ years of experience is required.

Is this position still open?

Yes, currently active and accepting applications.

ApplicationActively Hiring
Apply on Company Website
Broken link or expired?
SmartStream

SmartStream

About Smartstream: AI-Driven Financial Technology | Smartstream Skip to content Solutions Close Solutions Open Solutions Smart Reconciliations Reconciliations & Exceptions Management Smart Fees Fees and Expense Management Smart Agents Agentic AI Smart Actions Corporate Actions Processing Smart Liquidity Cash and Liquidity Management Smart Data Reference Data Services Smart Collateral Collateral Management Smart Payments Digital Payments and Investigations Our AI-driven data intelligence platform Learn More Services Close Services Open Services Managed Services Managed Services & Cloud

Visit Company Website

More jobs at SmartStream

Analyst

Pune, Maharashtra, India

Associate

Mumbai, Maharashtra, India

Full Stack Developer

Mumbai, Maharashtra, India

Share this Opening

Job Alerts for security

Receive email alerts whenever new security roles in Bengaluru are posted.

Set Free Alert →

Similar Openings

Explore related active roles in security

View all
UrgentActively Hiring
Doppel
Product Security
Doppel Verified
7+ years
₹12.1L – ₹13.8L/mo
US Remote
securityFull-timeRemote
Posted 19h ago
Apply Now
UrgentActively Hiring
Immersivelabs
Solutions Consultant (Cyber Security) - Portugal
Immersivelabs Verified
2+ years
₹1,245/mo
Portugal
securityFull-time
Posted 19h ago
Apply Now
UrgentActively Hiring
Teciem
Job Role – IAM and PAM Security Lead
Teciem Verified
8+ years
Salary not disclosed
TCMi - Bengaluru
securityFull-time
Posted 19h ago
Apply Now

Senior Security Engineer

SmartStream · Bengaluru

Apply on Company Website