368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$31k – $70k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Senior · 5+ years exp
Overview
Company
Impact
Profile match
Locus is developing a real-time tracking and management solution for on-demand businesses. Has raised $2.75 million in funding. Founding team from IIT and BITS with experience at Google, Amazon and eBay.

We are looking for a Senior Security Engineer to own and drive our security engineering programme across cloud and infrastructure security, DevSecOps, and detection engineering. You will work on a next-generation multi-tenant SaaS running on Kubernetes, served to enterprise clients across multiple regions. Beyond the platforms, Locus operates a suite of AI-agent products in production, adding a modern and growing attack surface that this role will actively help secure. This is a hands-on senior IC role with broad scope. You will work closely with engineering and DevOps teams, set technical direction for security across the organisation, and operate with a high degree of autonomy. Minimum 5 years of experience in a multi-domain security engineering role is required.

Responsibilities:

  • Lead threat modeling and security design reviews for cloud infrastructure, multi-tenant application architectures, and AI-agent systems integrating security from the design stage, not as an afterthought.
  • Own cloud security posture across AWS and Kubernetes, enforce IAM least-privilege, harden cluster security (pod security standards, network policies, admission controls), manage secrets hygiene, and drive compliance with cloud security benchmarks.
  • Drive DevSecOps security controls across CI/CD pipelines, including SAST, DAST, SCA, secrets scanning, container image scanning, and IaC security as enforcing gates, not advisory checks.
  • Own and harden supply-chain security: dependency and base image governance, build provenance controls, branch protection enforcement, and ensuring every new repository inherits security gates from creation.
  • Design, implement, and continuously improve security detections across cloud, runtime, and endpoint layers author detection rules, tune alerts, reduce false-positive rates, and build towards proactive threat hunting.
  • Own the vulnerability management process end-to-end: triage findings from multiple scanner sources using risk-based prioritisation, drive SLA adherence with engineering teams, and report risk posture to leadership.
  • Build and own incident response capability: define and maintain response playbooks, run tabletop exercises on realistic scenarios, instrument detection-to-containment metrics, and ensure significant incidents close with written RCAs.
  • Conduct security assessments of cloud configurations, API surfaces, and multi-tenant authorisation boundaries; identify architectural weaknesses and drive remediation to closure.
  • Review and assess the security posture of AI-agent products in production, covering prompt-injection risks, data isolation, tool-boundary abuse, and SSRF exposure aligned to OWASP LLM Top-10 and MITRE ATLAS.
  • Develop and maintain custom tooling, scripts, and automation to scale security coverage and reduce manual effort: agentic triage workflows, detection automation, and purpose-built scanners.
  • Champion secure-by-design practices across engineering, run security reviews at project intake, translate risk into developer-friendly guidance, and maintain a security culture grounded in 'complexity is the enemy of security. '
  • Stay current with emerging attack techniques, cloud security risks, AI-agent threat patterns, and detection strategies and actively share that knowledge with the team.

Requirements:

  • 5+ years of hands-on experience in a multi-domain security engineering role; cloud security, DevSecOps, and detection engineering are daily practice, not separate chapters.
  • Deep cloud security expertise: IAM, VPC and network security, cloud-native threat detection services, secrets management, and preventive cloud controls at scale.
  • Hands-on Kubernetes and container security: pod security standards, network policies, RBAC, admission controllers, runtime threat detection, and container image hardening.
  • Proven DevSecOps experience: integrating SAST, SCA, secrets scanning, and container scanning as enforcing gates in production CI/CD pipelines.
  • Detection engineering experience: authoring or tuning detection logic in an EDR, SIEM, or cloud security platform, not just consuming alert queues.
  • Vulnerability management: risk-based triage from multiple scanner sources, SLA enforcement with engineering teams, and leadership-level reporting.
  • Application security foundations: OWASP Top-10 API security, authorisation design (including multi-tenant patterns), and threat modelling (STRIDE).
  • Incident response: hands-on experience with alert triage, investigation, and post-incident review, including writing RCAs and running tabletop drills.
  • Strong scripting proficiency in Python or similar for automation, detection queries, and custom tooling.
  • Ability to work independently, take full ownership of domains, and collaborate across engineering and DevOps teams in a lean environment.
  • Strong attacker-and-defender mindset able to reason about real-world exploitability, not just scanner output.

Preferred Qualifications:

  • Relevant certifications: AWS Certified Security - Speciality, CKS (Certified Kubernetes Security Specialist), CCSP (Certified Cloud Security Professional), GCED, or equivalent.
  • Experience with infrastructure-as-code security identifying and remediating misconfigurations in Terraform, Pulumi, or similar.
  • Detection engineering depth: strong understanding of log sources, alert tuning, false-positive reduction, and MITRE ATT& CK mapping.
  • AI/LLM security experience: OWASP LLM Top-10 prompt injection, multi-agent security patterns, and MITRE ATLAS. Directly applicable: Locus runs AI-agent products in production.
  • Familiarity with policy-as-code frameworks and authorisation policy engines.
  • Multi-tenant SaaS security experience, understanding of cross-tenant isolation patterns and common failure modes.
  • Experience working in an ISO 27001 or SOC-2 audited environment alongside a GRC function.
  • Hands-on experience operating commercial CNAPP and SAST/SCA platforms.
  • Bug bounty programme operation or participation.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
$21k per year • In office • Contractor • Yekaterinburg
Python
SQL
Python
FastAPI
Flask
AI/ML
Claude
Claude Code
Embeddings
Function Calling
LLM
RAG
OpenAI
OpenAI Codex
Structured Outputs
DevOps
Docker
Git
Apply
$140k – $225k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree • Seattle
Python
TypeScript
Node JS
JavaScript
Python
FastAPI
Node JS
Fastify
Databases
PostgreSQL
Redis
Frontend
React.js
Vite
DevOps
Kubernetes
WebSockets
QA
Playwright
Vitest
Apply
$140k – $225k per year • Remote • Full-Time • 5+ years exp • Seattle
Python
Lua
Python
FastAPI
Celery
Pydantic
SQLAlchemy
Databases
pgvector
PostgreSQL
Redis
AI/ML
LLM
RAG
Hybrid Search
Reranking
Anthropic
LLM Evaluation
LLM Guardrails
OpenAI
Model Context Protocol
DevOps
OpenTelemetry
Apply
$98k – $132k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
R
SQL
Databases
Databricks
Snowflake
AI/ML
Embeddings
LangChain
LangGraph
LLM
NumPy
Pandas
Scikit-learn
Spark
TensorFlow
Transformers
Hugging Face
RAG
Analytics
Matplotlib
Seaborn
Apply
AI Product Manager 1 month ago
$32k – $66k per year (Estimated) • Remote • 5+ years exp • Bachelor's Degree
SQL
AI/ML
AI Agents
LLM
Prompt Engineering
RAG
DevOps
AWS
Azure
GCP
Vector
Apply
SDE - III - Backend 1 month ago
$22k – $59k per year (Estimated) • In office • 6+ years exp • Bachelor's Degree • Bengaluru
Java
Java
Spring Boot
Databases
Apache Kafka
Memcached
RabbitMQ
Redis
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Apply
$16k – $34k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Mumbai • Bengaluru
JavaScript
PowerShell
SQL
C#
C#
.NET
Databases
Azure SQL Database
MS SQL
DevOps
Azure
Rest API
Cybersecurity
Microsoft Entra ID
QA
Postman
Swagger
Apply
$41k – $89k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
C#
TypeScript
JavaScript
C#
.NET
Databases
Apache Kafka
AI/ML
Copilot
LLM
OpenAI
Frontend
Angular
GraphQL
DevOps
Azure
Azure AKS
Azure DevOps
CI/CD
Docker
GitHub
GitHub Actions
Grafana
Kubernetes
Prometheus
Rest API
Apply
$38k – $83k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Bengaluru
Databases
Oracle
DevOps
AWS
Platform Engineering
Apply
Data Architect 3 hours ago
$38k – $91k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru • Pune
Node JS
Python
SQL
JavaScript
Databases
Databricks
MongoDB
Redis
Apply
$28k – $71k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
DevOps
CI/CD
Platform Engineering
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.