About the job
apna is hiring a Senior Security Engineer in Bengaluru to strengthen the security of its AI platforms, microservices, data pipelines, and mobile/web products. This position focuses on designing, building, and automating security controls that fit smoothly into CI/CD processes and cloud infrastructure. The role calls for hands-on technical expertise, effective risk management, and close collaboration with AI, product development, and DevOps teams.
Key Responsibilities
Security Engineering & Automation
- Design and implement automated security frameworks for threat detection, remediation, and compliance across cloud and application layers.
- Develop tools and scripts to boost security visibility in AI model pipelines, APIs, and data integrations.
- Integrate security controls into CI/CD workflows, including SAST, DAST, SCA, and IaC scanning.
- Apply experience with XDR/SIEM for automated detection and response.
Application & API Security
- Conduct secure code reviews and threat modeling for AI microservices, REST APIs, and agent frameworks.
- Work with developers to address vulnerabilities and uphold secure SDLC practices.
- Lead regular Vulnerability Assessment & Penetration Testing (VAPT) for web and mobile applications, the Agentic AI platform, and related services.
- Identify and mitigate vulnerabilities, such as OTP bypass and data leaks in public GCS buckets.
Cloud & Infrastructure Security
- Secure multi-cloud environments (GCP and AWS) using both native and third-party tools.
- Set and maintain Infrastructure as Code (IaC) security baselines and automate configuration drift detection.
- Configure and manage Web Application Firewalls (WAF) for custom DDoS and bot protection.
- Oversee secrets management, IAM, and container security best practices in production workloads.
- Address misconfigurations, default credentials, and public exposures in systems such as Grafana, Zookeeper, and Prometheus.
AI & Data Security
- Monitor for compromised datasets, credentials, and model theft attempts, including activity on deep and dark web sources.
- Implement data protection measures for AI training pipelines, model storage, and inference endpoints.
- Assess and mitigate risks related to prompt injection, model leakage, and data exfiltration in AI agents.
Monitoring & Incident Response
- Work with internal teams to improve threat detection, alert triage, and response automation.
Position Details
- Location: Bengaluru, Karnataka, India
- Employment Type: Full-time
- Team: Security Engineering

