Expert Security Engineer - Offensive Security
Bengaluru, India
Finastra
Finastra is one of the largest fintech companies in the world, offering the broadest portfolio of solutions for financial institutions of all sizes.
At Finastra, we are a dynamic global provider of open finance software solutions, dedicated to expanding access to financial services. Our innovative applications span Lending, Payments, Treasury and Capital Markets, and Universal Banking. Proudly serving over 8,000 customers, including 45 of the world's top 50 banks, we aim to boost financial inclusion for all. Join us and be part of a vibrant company that embraces diverse perspectives, and is committed to doing well by doing good.
What will you contribute?
As an Expert Offensive Security Engineer within the Cyber Defense Team, you'll lead offensive security assessments that strengthen our defense capabilities. Working closely with the larger InfoSec team, detection engineers, and external engineering partners, you'll identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You'll collaborate with various architecture and engineering teams to continuously validate and improve our security controls and detection capabilities, with a strong focus on developing repeatable testing frameworks and metrics-driven security improvements.
Responsibilities & Deliverables:
You will be responsible for the following:
Lead offensive security assessments: conduct full-stack security assessments across our entire technology stack.
Drive detection engineering partnerships: collaborate with detection engineers through purple team exercises, attack simulations, and threat emulation to improve detection coverage.
Develop custom tools and frameworks: build and maintain security testing tools, frameworks, and automation scripts that enable repeatable testing and quantifiable security improvements.
Build security metrics: design and implement frameworks to measure security control effectiveness, detection coverage, and improvement over time through consistent testing methodologies.
Research and innovate: stay current with the latest attack techniques, tools, and methodologies while building out both offensive and defensive security improvements.
Mentor and collaborate: share knowledge across security teams and foster a culture of continuous security improvement.
Required Experience:
5+ years: professional experience in offensive security, with demonstrated experience in red team and purple team exercises, penetration testing, and detection engineering teamwork.
Development experience: proficiency in Python or other programming language such as Bash,Regex,Power shell,etc for building security tooling and automation.
Security assessment expertise: performing full-stack security assessments of web and mobile applications, APIs, on-prem and cloud infrastructure, and backend systems..
Deep understanding: common attack techniques; exploit development; post-exploitation methodologies; security assessment frameworks (MITRE ATT&CK, PTES); and modern detection stack components (EDR, SIEM, XDR).
Knowledge: of networking, operating systems, security protocols, security concepts including reverse engineering, cloud security (AWS/Azure), container security, CI/CD pipeline security, API security, and security metrics development.
Certifications: such as OSCP, OSCE, GXPN, or equivalent practical experience.
Interpersonal skills: strong analytical and problem-solving abilities; excellent technical writing for detailed reports; ability to clearly communicate complex technical concepts; self-motivated with a passion for offensive security and detection engineering.
We are proud to offer a range of incentives to our employees worldwide. These benefits are available to everyone, regardless of grade, and reflect the values we uphold:
· Flexibility: Enjoy unlimited vacation, based on your location and business priorities. Hybrid working arrangements, and inclusive policies such as paid time off for voting, bereavement, and sick leave.
· Well-being: Access confidential one-on-one therapy through our Employee Assistance Program, unlimited personalized coaching via our coaching app, and access to our Gather Groups for emotional and mental support.
· Medical, life & disability insurance, retirement plan, lifestyle and other benefits*
· ESG: Benefit from paid time off for volunteering and donation matching.
· DEI: Participate in multiple DE&I groups for open involvement (e.g., Count Me In, Culture@Finastra, Proud@Finastra, Disabilities@Finastra, Women@Finastra).
· Career Development: Access online learning and accredited courses through our Skills & Career Navigator tool.
· Recognition: Be part of our global recognition program, Finastra Celebrates, and contribute to regular employee surveys to help shape Finastra and foster a culture where everyone is engaged and empowered to perform at their best.
*Specific benefits may vary by location.
At Finastra, each individual is unique, bringing their own ideas, thoughts, cultural beliefs, backgrounds, and experiences together. We learn from one another, embrace and celebrate our differences, and create an environment where everyone feels safe to be themselves.
Be unique, be exceptional, and help us make a difference at Finastra!
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Automation AWS Azure Banking Bash CI/CD Cloud Cyber defense EDR Exploit Finance Full stack GXPN MITRE ATT&CK Offensive security OSCE OSCP Pentesting Python Red team Reverse engineering Security assessment SIEM XDR
Perks/benefits: Career development Health care Insurance Medical leave Unlimited paid time off
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.