About the company
Job Summary
Responsibilities:
šAssess and Review CoinSwitch products in detail to discover vulnerabilities and collaborate with the other security engineers to practically demonstrate the exploitability and risk factors. šBe on the forefront of emerging vulnerabilities / threats which could affect CoinSwitch and its operations. šSecure Architecture and SDLC: Design and build secure systems across all layers (Application, Infra, enterprise), implement AppSec and šSecure SDLC practices including SAST, DAST, and SCA. Decent understanding of AWS Cloud and Container security best practices for containerization, ECS, and Kubernetes, and managing secrets/key management. šAPI Security: Ensure the security of GraphQL and REST APIs. DevSecOps and Automation: Drive DevSecOps enablement by integrating security into CI/CD pipelines and implementing . šVulnerability Management and Testing: Lead internal/external VAPT, conduct penetration testing (web, API, mobile, cloud), and manage bug bounty programs and the Coordinated Vulnerability Disclosure (CVD) process. šVulnerability Remediation and Hardening: Drive post-VAPT remediation, manage vulnerability scanning, track mitigation. šCollaborate with engineering, DevOps, and IT to embed security in all the systems. šSecurity Automation : Automate security testing and improve productivity in security assessments.
Requirements:
š6-9 years of experience in Security Engineering, AppSec, Product Security DevSecOps, or a related security-focused role. šStrong understanding of secure architecture principles for network, OS, and application layers. šHands-on experience with AppSec tooling (SAST, DAST, SCA) and implementing Secure SDLC. šExperience in Mobile Application Security Testing and tools used. šDeep knowledge of secrets and key management solutions.
The crypto industry is evolving rapidly, offering new opportunities in blockchain, web3, and remote crypto roles ā donāt miss your chance to be part of it.




