HighLevel logo
HighLevelPosted 3 weeks ago

Lead Security Engineer

RemoteIndia

Full TimeSenior LevelLarge

Job Summary

Lead application security initiatives across HighLevel's products and engineering teams by conducting architecture reviews, secure design assessments, and threat modeling for new features. Perform security assessments for Web, Mobile, and API-based applications while defining and driving secure SDLC practices. Partner with developers to identify, prioritize, and remediate vulnerabilities, including leading reviews for AI/LLM-powered applications and developing guardrails against prompt injection and data leakage. Improve security tooling to automate testing within CI/CD pipelines and champion secure coding through developer enablement and training. Mentor engineers to foster a security-first culture while communicating complex risks to stakeholders and influencing product roadmaps.

Required Qualifications

  • 8+ years of experience in Cybersecurity
  • deep expertise in Application Security
  • experience leading engineering-focused security initiatives
  • Comprehensive technical knowledge in securing Web, Mobile (Android/iOS), and API (REST/GraphQL) environments
  • knowledge of OWASP standards
  • knowledge of authentication protocols (OAuth 2.0, OIDC, JWT, SAML)
  • Proven experience performing security assessments
  • experience with threat modeling
  • experience with secure design/code reviews
  • experience with penetration testing
  • experience with architecture reviews
  • Hands-on DevSecOps proficiency
  • experience automating security in CI/CD pipelines
  • experience with container security (Kubernetes/Docker)
  • experience managing security tooling (SAST, DAST, SCA, Secret Scanning)
  • Specialized expertise in AI/LLM security
  • mitigation of prompt injection
  • mitigation of data leakage
  • mitigation of model misuse
  • mitigation of insecure agent/tool integration
  • Proficiency in programming/scripting (Python, Go, JavaScript, or Bash)
  • strong communication skills to influence technical stakeholders across product and engineering teams

Desired Qualifications

  • Experience securing workloads on Google Cloud Platform (GCP)
  • Experience with Infrastructure as Code security (Terraform)
  • Familiarity with CSPM/CNAPP solutions
  • Experience leading or participating in Red Teaming, adversary simulation, or purple team exercises
  • Experience with DevSecOps and security automation
  • Security certifications such as CEH, OSCP, GWAPT, CISSP, GCP Professional Cloud Security Engineer, or similar
  • Contributions to open-source security projects
  • Contributions to bug bounty programs
  • Contributions to security research

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce