- Location
- IN Bangalore, India
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Source
- Workday
Description
Founded in 2014, Circles is a global technology company reimagining the telco industry with its innovative SaaS platform, empowering telco operators worldwide to effortlessly launch innovative digital brands or refresh existing ones, accelerating their transformation into techcos.
Today, Circles partners with leading telco operators across multiple countries and continents, including KDDI Corporation, Etisalat Group (e&), AT&T, and Telkomsel, creating blueprints for future telco and digital experiences enjoyed by millions of consumers globally.
Besides its SaaS business, Circles operates three other distinct businesses:
- Circles.Life: A wholly-owned digital lifestyle telco brand based in Singapore, Circles.Life is powered by Circles’ SaaS platform and pioneering go-to-market strategies. It is the digital market leader in Singapore and has won numerous awards for marketing, customer service, and innovative product offerings beyond connectivity.
- Circles Aspire: A global provider of Communications Platform-as-a-Service (CPaaS) solutions. Its cloud-based Experience Cloud platform enables enterprises, service providers and developers to deliver and scale mobile, messaging, IoT, and connectivity services worldwide.
- Jetpac: Specializing in travel tech solutions, Jetpac provides seamless eSIM roaming for over 200 destinations and innovative travel lifestyle products, redefining connectivity for digital travelers. Jetpac was awarded Travel eSIM of the Year.
Circles is backed by renowned global investors, including Peak XV Partners (formerly Sequoia), Warburg Pincus, Founders Fund, and EDBI (the investment arm of the Singapore Economic Development Board), with a track record of backing industry challengers.
Security Engineer
Department:
Information Security
Reports To: Head of Security Engineering
Experience: 4–6 Years
Type: Individual Contributor (IC)
Location - Bangalore
Role Summary
We're looking for a hands-on Security Engineer to strengthen our security posture across applications, APIs, and cloud infrastructure. This IC role focuses on secure architecture support, application security testing, and penetration testing, with the automation skills to scale security work — partnering closely with Engineering and DevOps to embed security throughout the SDLC.
Key Responsibilities
Secure Architecture & Threat Modeling
Support threat modeling sessions (STRIDE, PASTA, or equivalent) for new applications, features, and platform changes, under guidance from senior security staff
Conduct security architecture reviews for applications, APIs, and cloud services
Apply and help document secure design patterns; provide security input during design and development
Application & API Security
Execute and help maintain the Application Security program: SAST, DAST, and SCA scanning — configuration, triage, and false-positive analysis
Support integration of security testing into CI/CD pipelines and DevSecOps workflows
Test REST and GraphQL APIs against the OWASP API Security Top 10 (broken object/function-level authorization, excessive data exposure, rate limiting, business logic abuse)
Work directly with engineering teams to explain findings, recommend fixes, and track remediation to closure
Penetration Testing & Vulnerability Management
Perform internal penetration tests across web applications, APIs, and cloud infrastructure
Support and help coordinate external penetration testing engagements
Manually validate scanner findings to confirm exploitability and reduce noise before findings reach engineering backlogs
Track vulnerabilities through the remediation lifecycle and help maintain remediation SLAs
Security Automation
Build automation in Python (or equivalent) for security scanning, findings de-duplication, ticketing, and reporting
Help integrate security tooling into CI/CD to reduce manual, repetitive security tasks
Identify opportunities to automate recurring testing and reporting workflows
Required Qualifications
3–6 years of hands-on experience in Cybersecurity, Application Security, or Security Engineering
Working experience in:
Threat modeling and secure architecture review
Microservice architecture
Penetration testing[Web, API, Mobile] and vulnerability management
SAST, DAST, SCA, and API security testing
DevSecOps and CI/CD security integration
Python (or equivalent) scripting for automation
Working knowledge of the OWASP Top 10, OWASP API Security Top 10, and secure coding practices
Experience evaluating and securing AI implementations
Capability to identify AI-specific vulnerabilities such as prompt injection, data poisoning, system prompt leakage, and insecure output handling.
Ability to read and understand code to identify vulnerabilities; proficiency in Java or Go (Golang) is a strong plus.
Good communication skills, able to explain security findings clearly to engineers
Preferred Qualifications
Certifications: OSCP, GWAPT, GPEN, Security+, or equivalent
Exposure to AWS, Azure, or GCP security, and container/Kubernetes environments
Familiarity with security frameworks such as OWASP SAMM, BSIMM, or NIST CSF
Circles is committed to a diverse and inclusive workplace. We are an equal opportunity employer and do not discriminate on the basis of race, national origin, gender, disability or age.
Data Protection and Privacy Statement
By submitting an application for this position, you, as the applicant, or your authorised representative(s), consent to Circles’ Candidate Data Protection and Privacy Policy. You also agree to the collection, use, and/or disclosure of your personal data by us solely for recruitment purposes as specified in the Policy. You acknowledge that you have read and understood the Policy, are aware of your rights regarding your personal data, and accept the terms relating to international data transfers, where applicable. You further understand that you may withdraw consent at any time, which may affect our ability to consider your application. In instances where your personal data or application is submitted by a third party, it is understood that such third party has been duly authorised by you to disclose the relevant personal data and provide consent on your behalf, and that you have been made aware of this Policy.
To all recruitment agencies: Circles will only acknowledge resumes shared by recruitment agencies if selected in our preferred supplier partnership program.
Please do not forward resumes to our jobs alias, Circles, employees or any other company location. Circles will not be held accountable for any fees related to unsolicited resumes not uploaded via our ATS.