AdTechTalent
security90 days agoOn-site

InMobi Advertising

Lead Application Security Engineer

application securitydevsecopspenetration testingsecurity engineeringSASTDASTSCACheckmarxOAuth2OIDCJWTmTLSAPI securityOWASP Top 10AI securityLLM securityRAG pipelinesPythonJavaNode.jsDockerKubernetesBurp SuiteOWASP ZAPSQLMapKaliLangChainprompt injectionsecurity automation

Key details

Salary

Not specified

Employment type

Full-time

Seniority

Senior

Years experience

5-10

Location

Bangalore, Karnataka, India

Full job description

InMobi Advertising is seeking a senior Application Security professional with 7+ years experience in Application Security, Penetration Testing, DevSecOps, or Security Engineering. The role involves performing security testing across Web, API, Mobile (Android & iOS), TV, and Cloud services, including vulnerability assessments and penetration testing. Responsibilities include managing CI/CD security controls (SAST, DAST, SCA, secrets scanning, IaC scanning), building security gates (e.g., Checkmarx), conducting manual security code reviews in Java, Python, and Node.js, reviewing application designs for security best practices, automating security workflows, and partnering with engineering teams for remediation. The role also focuses on AI/GenAI security, applying secure SDLC practices for LLM-based features, mitigating OWASP LLM Top 10 risks, maintaining secure prompt templates, implementing AI guardrails, performing AI red teaming and adversarial testing, reviewing RAG implementations, and conducting AI-focused threat modeling. Required skills include hands-on experience with security tools (Burp Suite, OWASP ZAP, SQLMap, Kali), scripting in Python and Bash/PowerShell, knowledge of Docker/Kubernetes and cloud-native patterns, and familiarity with OAuth2, OIDC, JWT, mTLS, and API gateways. Preferred qualifications include bug bounty recognition, experience deploying open-source security tools, and certifications such as OSCP, OSCE, GWAPT, GPEN, CSSLP. The position is based in Bangalore, Karnataka, India.

What you'll do

  • Perform application security testing across Web, API, Mobile (Android & iOS), TV and Cloud services, including vulnerability assessments and penetration testing
  • Validate and triage security findings through exploit verification and risk-based severity assessment
  • Own and operate CI/CD security controls, including SAST, DAST, SCA, secrets scanning, and IaC scanning
  • Build and maintain security gates (e.g., Checkmarx or equivalent) with a focus on automation, accuracy, and developer usability
  • Conduct manual security code reviews for APIs and services written in Java, Python, and Node.js
  • Review application designs for authentication, authorization, data protection, and API security best practices
  • Automate security workflows using scripts and APIs to standardize testing and reduce manual effort
  • Partner with engineering teams to drive timely, risk-appropriate remediation and prevent repeat vulnerabilities
  • Apply AI Secure SDLC practices for LLM-based features, including prompt design, tool/function usage, and safe integration patterns
  • Assess and mitigate OWASP LLM Top 10 risks
  • Review and maintain secure prompt templates, including system prompt hardening and context scoping
  • Implement practical AI guardrails (output validation, policy checks, basic jailbreak and abuse detection)
  • Perform AI red teaming and adversarial testing using tools such as Garak, PyRIT, and custom test cases
  • Review RAG implementations to ensure authorization-aware retrieval, tenant isolation, and reduced data leakage risk
  • Identify and reduce sensitive data exposure risks in embeddings and ingestion pipelines
  • Conduct AI-focused threat modeling using OWASP LLM Top 10, STRIDE, and MITRE ATLAS as reference frameworks

Requirements

  • Minimum 7 years of experience in Application Security, Penetration Testing, DevSecOps, or Security Engineering
  • Proven hands-on ability with SAST/DAST/SCA, CI/CD security gates, and vulnerability triage/remediation workflows
  • 2–3 years’ experience building and managing security gating in Checkmarx (or equivalent)
  • 2–3 years’ experience performing manual security code review (APIs/services; common languages: Java/Python/Node.js)
  • Familiarity with OAuth2, OIDC, JWT, mTLS, API gateways, and service-to-service identity
  • Strong knowledge of OWASP Top 10 Mobile, OWASP Top 10 LLM
  • Strong experience with common testing tools: Burp Suite, OWASP ZAP, SQLMap, Kali (and similar)
  • Scripting/automation skills using Python, plus Bash/PowerShell familiarity
  • Working knowledge of Docker/Kubernetes, cloud-native patterns, and secrets management basics
  • Solid communication skills—ability to write clear findings, influence engineering decisions, and partner effectively
  • Hands-on familiarity with LLM integrations and Python AI ecosystems (e.g., LangChain / orchestration frameworks)
  • Understanding of RAG pipelines and vector database concepts (e.g., Pinecone, FAISS, Milvus or equivalent)
  • Ability to design/validate guardrails (policy allow/deny, jailbreak detection, output validation, safe tool calling)
  • Familiarity with AI security testing patterns (prompt injection testing, data leakage testing, agent/tool abuse testing)

Tech stack

JavaPythonNode.jsSASTDASTSCASecrets scanningIaC scanningCheckmarxOAuth2OIDCJWTmTLSAPI gatewaysBurp SuiteOWASP ZAPSQLMapKaliBashPowerShellDockerKubernetesLangChainPineconeFAISSMilvusGarakPyRIT

Benefits

Continuous learning and career progression through InMobi Live Your Potential programEqual Employment Opportunity employerReasonable accommodations for qualified individuals with disabilities

Apply now

This MVP uses a placeholder application flow. In production, this section can connect to an external apply URL or a native application form.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.