SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Cybersecurity Engineer

Aspire - Bengaluru, Karnataka, India - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Aspire is a Series C fintech company building a financial operating system for global founders, trusted by 50,000+ startups worldwide. The Security Team is seeking a Senior Cybersecurity Engineer to lead application security, infrastructure protection, and compliance initiatives. You will own end-to-end security testing processes, including the Responsible Disclosure Policy and remediation coordination with engineering teams. You'll implement DevSecOps practices by integrating SAST, SCA, and Secret Detection into the CI/CD pipeline (GitHub), developing custom automation to prevent data leaks. Your infrastructure security responsibilities include managing CSPM tools (Orca), WAF (Cloudflare), conducting AWS infrastructure reviews, and performing internal network penetration tests. You will identify and resolve critical vulnerabilities, including LLM-specific risks, and manage Docker/application dependency patching. You'll build security dashboards to track KPIs, automate PII detection in logs, and support ISO/SOC2 audits with technical evidence. Additionally, you'll scope, manage, and coordinate external penetration testing engagements with third-party vendors, communicating findings and tracking remediation to closure. Required: Bachelor's in Computer Science or Information Security (or equivalent); 6+ years in Application Security, Product Security, or Cloud Security. Deep expertise in OWASP Top 10, AWS (IAM, Security Groups, NACLs), DevSecOps/CI-CD integration, Python/Bash/Go scripting, Docker/Kubernetes security, and security tools (CSPM, WAF, vulnerability scanners). Strong cross-functional collaboration skills with Product, DevOps, and Engineering teams. Preferred: LLM/GenAI security threat modeling, advanced Cloudflare WAF configuration, ISO 27001/SOC2/PCI-DSS compliance experience, Bug Bounty program management, certifications (OSCP, OSWE, CISSP, AWS Security Specialty), and threat modeling expertise.

Similar roles