Hiring.Camp

Engineer II, Security Engineering

Circles is

·

Today

Location
IN Bangalore, India
Workplace
Hybrid
Type
Full-time
Department
Engineering
Source
Workday

Description

Founded in 2014, Circles is a global technology company reimagining the telco industry with its innovative SaaS platform, empowering telco operators worldwide to effortlessly launch innovative digital brands or refresh existing ones, accelerating their transformation into techcos.

Today, Circles partners with leading telco operators across multiple countries and continents, including KDDI Corporation, Etisalat Group (e&), AT&T, and Telkomsel, creating blueprints for future telco and digital experiences enjoyed by millions of consumers globally.

Besides its SaaS business, Circles operates three other distinct businesses:

  • Circles.Life: A wholly-owned digital lifestyle telco brand based in Singapore, Circles.Life is powered by Circles’ SaaS platform and pioneering go-to-market strategies. It is the digital market leader in Singapore and has won numerous awards for marketing, customer service, and innovative product offerings beyond connectivity.

  • Circles Aspire: A global provider of Communications Platform-as-a-Service (CPaaS) solutions. Its cloud-based Experience Cloud platform enables enterprises, service providers and developers to deliver and scale mobile, messaging, IoT, and connectivity services worldwide.

  • Jetpac: Specializing in travel tech solutions, Jetpac provides seamless eSIM roaming for over 200 destinations and innovative travel lifestyle products, redefining connectivity for digital travelers. Jetpac was awarded Travel eSIM of the Year.

Circles is backed by renowned global investors, including Peak XV Partners (formerly Sequoia), Warburg Pincus, Founders Fund, and EDBI (the investment arm of the Singapore Economic Development Board), with a track record of backing industry challengers.

Security Engineer

Department:

Information Security

Reports To: Head of Security Engineering

Experience: 4–6 Years

Type: Individual Contributor (IC)

Location - Bangalore

Role Summary

We're looking for a hands-on Security Engineer to strengthen our security posture across applications, APIs, and cloud infrastructure. This IC role focuses on secure architecture support, application security testing, and penetration testing, with the automation skills to scale security work — partnering closely with Engineering and DevOps to embed security throughout the SDLC.

Key Responsibilities

Secure Architecture & Threat Modeling

  • Support threat modeling sessions (STRIDE, PASTA, or equivalent) for new applications, features, and platform changes, under guidance from senior security staff

  • Conduct security architecture reviews for applications, APIs, and cloud services

  • Apply and help document secure design patterns; provide security input during design and development

Application & API Security

  • Execute and help maintain the Application Security program: SAST, DAST, and SCA scanning — configuration, triage, and false-positive analysis

  • Support integration of security testing into CI/CD pipelines and DevSecOps workflows

  • Test REST and GraphQL APIs against the OWASP API Security Top 10 (broken object/function-level authorization, excessive data exposure, rate limiting, business logic abuse)

  • Work directly with engineering teams to explain findings, recommend fixes, and track remediation to closure

Penetration Testing & Vulnerability Management

  • Perform internal penetration tests across web applications, APIs, and cloud infrastructure

  • Support and help coordinate external penetration testing engagements

  • Manually validate scanner findings to confirm exploitability and reduce noise before findings reach engineering backlogs

  • Track vulnerabilities through the remediation lifecycle and help maintain remediation SLAs

Security Automation

  • Build automation in Python (or equivalent) for security scanning, findings de-duplication, ticketing, and reporting

  • Help integrate security tooling into CI/CD to reduce manual, repetitive security tasks

  • Identify opportunities to automate recurring testing and reporting workflows

Required Qualifications

  • 3–6 years of hands-on experience in Cybersecurity, Application Security, or Security Engineering

  • Working experience in:

    • Threat modeling and secure architecture review

    • Microservice architecture

    • Penetration testing[Web, API, Mobile] and vulnerability management

    • SAST, DAST, SCA, and API security testing

    • DevSecOps and CI/CD security integration

    • Python (or equivalent) scripting for automation

  • Working knowledge of the OWASP Top 10, OWASP API Security Top 10, and secure coding practices

  • Experience evaluating and securing AI implementations 

  • Capability to identify AI-specific vulnerabilities such as prompt injection, data poisoning, system prompt leakage, and insecure output handling.

  • Ability to read and understand code to identify vulnerabilities; proficiency in Java or Go (Golang) is a strong plus.

  • Good communication skills, able to explain security findings clearly to engineers

Preferred Qualifications

  • Certifications: OSCP, GWAPT, GPEN, Security+, or equivalent

  • Exposure to AWS, Azure, or GCP security, and container/Kubernetes environments

  • Familiarity with security frameworks such as OWASP SAMM, BSIMM, or NIST CSF

Circles is committed to a diverse and inclusive workplace. We are an equal opportunity employer and do not discriminate on the basis of race, national origin, gender, disability or age.

Data Protection and Privacy Statement 

By submitting an application for this position, you, as the applicant, or your authorised representative(s), consent to Circles’ Candidate Data Protection and Privacy Policy. You also agree to the collection, use, and/or disclosure of your personal data by us solely for recruitment purposes as specified in the Policy. You acknowledge that you have read and understood the Policy, are aware of your rights regarding your personal data, and accept the terms relating to international data transfers, where applicable. You further understand that you may withdraw consent at any time, which may affect our ability to consider your application. In instances where your personal data or application is submitted by a third party, it is understood that such third party has been duly authorised by you to disclose the relevant personal data and provide consent on your behalf, and that you have been made aware of this Policy.

To all recruitment agencies: Circles will only acknowledge resumes shared by recruitment agencies if selected in our preferred supplier partnership program.

Please do not forward resumes to our jobs alias, Circles, employees or any other company location. Circles will not be held accountable for any fees related to unsolicited resumes not uploaded via our ATS.

Skills

PythonJavaAWSAzureGCPKubernetesCI/CDCybersecurityPenetration TestingRESTGraphQLDevOpsCustomer ServiceGo

Similar Jobs

30

Security Engineer II

Mapbox · Mapbox US

6 days ago

Security Engineer II

Advantage Solutions · Chicago, IL, US

4 weeks ago

Security Engineer II

Metropolis · Los Angeles, California, United States +4

1 month ago

Security Engineer II

Metropolis · New York, New York, United States +4

1 month ago

Security Engineer II

Tekion · Bengaluru, Karnataka, India

1 month ago

Security Engineer II

Liveperson · Sofia, Bulgaria

1 month ago

Security Engineer II

AssetMark is · Atlanta, United States of America +2 · Hybrid

2 months ago

Security Engineer II

Lennar · Irving TX (Greenway), United States of America · Hybrid

4 months ago

Security Engineer II, AWS Security, Hardware Supply Chain Security

Amazon · Remote

Today

Security Engineer II, Stores Security Review Operations

Amazon

Yesterday

Security Engineer II, Stores Security - HealthCare

Amazon

Yesterday

Security Engineer II (Full Time) - United States STO/Cloud Security Engineering ETR

Cisco · USA-CHICAGO, United States of America · Hybrid

2 days ago

Product Security Engineer II

Affirm · Remote Canada · Remote

3 days ago

Product Security Engineer II

Affirm · Remote US · Remote

3 days ago

Product Security Engineer II

Affirm · Remote Canada · Remote

3 days ago

Security Engineer II, Infrastructure Security Identity

Amazon

3 days ago

Security Engineer II, Security Incident Response Team (SIRT)

Amazon

3 days ago

Security Engineer II, Differentiated Security Team (DST)

Amazon

3 days ago

Senior Security Engineer II

Braze · Austin +1

6 days ago

Senior Security Engineer II

Braze · Chicago +1

6 days ago

Senior Security Engineer II

Braze · San Francisco +1

6 days ago

Senior Security Engineer II

Braze · New York City

6 days ago

Security Engineer II (AI)

Sixt · Bengaluru, Karnataka, India · Hybrid

6 days ago

Security Engineer II – Vulnerability Patch Management

Cmegroup · Bangalore - Bagmane Tridib, India

1 week ago

Product Security Engineer II

Zeta · Hyderabad · Onsite

1 week ago

Information Security Engineer II

Candescent · SQ - Belgrade - Office, Serbia

1 week ago

Information Security Engineer II

Candescent · SQ - Belgrade - Office, Serbia

1 week ago

Security Engineer II, LOAF - Lifecycle of A Finding

Amazon

1 week ago

Security Engineer II - AMZ27587.1

Amazon

1 week ago

Security Engineer II - Information Technology

Pima County Careers · Tucson, AZ, United States of America · Remote, Onsite

1 week ago