InfoSec - Application & Cloud Security Engineer (L2)

Posted Yesterday
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Mid level
Fintech • Payments • Financial Services
Experience a better way to move money
The Role
Hybrid Application and Cloud Security engineer splitting time between AppSec (code review, SAST/DAST/SCA triage, threat modeling, CI/CD tooling) and CloudSec (AWS IAM, Kubernetes hardening, WAF tuning, GuardDuty/Security Hub monitoring). Contributes to automation, runbooks, incident playbooks, and on-call rotation while partnering with engineering pods to drive remediation and reduce risk.
Summary Generated by Built In
About Us

OpenFX is on a mission to move money as freely as data, unrestricted by time zones, banking hours, or legacy systems. We are building the infrastructure that will power the next generation of cross-border payment systems for institutions. The team's execution has been exceptional, and we're scaling at a remarkable pace. Our stellar early team comes with experience in companies like J.P. Morgan, Goldman Sachs, FalconX, PayPal, Affirm, Polygon, Kraken, Nium & others. We're backed by Accel, Faction, NfX, Accomplice, and other top-tier investors.

Role Overview

This is a hybrid Application + Cloud Security role for an engineer who has 2–4 years of hands-on security experience and is ready to grow into a specialist. You'll spend roughly half your time supporting AppSec (code review, secure SDLC tooling, threat modeling, findings triage) and half on CloudSec (AWS account security, IAM reviews, Kubernetes hardening, WAF tuning).

You'll partner closely with our Sr. Application Security Engineer and Cloud Security Engineer (both L3), picking up increasingly complex work as you ramp. The goal is for you to develop deep expertise in one of the two specializations within 12–18 months while remaining strong across both.

This role is ideal for someone who is technically curious, has shipped real security work (not just evaluated tools), and wants to grow fast in a high-stakes fintech environment.

Key ResponsibilitiesApplication Security (~50%)
  • Perform manual and automated code reviews alongside the Sr. AppSec engineer, with growing independence over time
  • Triage, reproduce, and drive remediation on findings from SAST, DAST, SCA, bug bounty, and internal reports
  • Support threat-modeling sessions for new services and features
  • Tune and maintain AppSec tooling in CI/CD to minimize noise and maximize signal
  • Partner with engineering pods to help developers fix issues the right way the first time
Cloud Security (~50%)
  • Support AWS account security: IAM policy reviews, least-privilege analysis, and guardrail enforcement via Config/SCPs
  • Help harden Kubernetes clusters — admission control (OPA/Gatekeeper, Kyverno), RBAC hygiene, secrets management
  • Tune WAF rules (AWS WAF / Cloudflare) to reduce false positives without creating blind spots
  • Run vulnerability scans against cloud infrastructure and containers; drive remediation with DevOps
  • Contribute to security automation: small tools and scripts that reduce manual work (Python / Go / Bash)
  • Monitor GuardDuty, Security Hub, and Config findings; triage and escalate as needed
Cross-cutting
  • Contribute to security policies, standards, runbooks, and incident playbooks
  • Participate in InfoSec on-call rotation
  • Research emerging threats and bring recommendations back to the team
What We're Looking ForRequired
  • 2–4 years of hands-on experience in Application Security, Cloud Security, or a closely related role
  • Solid grounding in security fundamentals: OWASP Top 10, TLS/PKI basics, OAuth/JWT, common cloud attack patterns
  • Hands-on exposure to both AppSec (at least one of SAST/DAST/manual review) and CloudSec (at least one of AWS/GCP/Azure) — you don't need to be expert in both, but you should have shipped work in both
  • Scripting ability in Python, Go, or Bash — you can write useful internal tools, not just one-liners
  • Clear communicator — can translate a finding into something an engineer will actually fix
  • Hunger to grow — you take feedback well, go deep on topics, and own your ramp
Preferred
  • Degree or equivalent experience in Computer Science, Information Security, or similar
  • Exposure to Kubernetes in production, even if not as the primary owner
  • Familiarity with IaC (Terraform) and how security gets enforced (or bypassed) in code
  • Bug bounty, CTF, or open-source security contributions — demonstrated curiosity outside the 9-to-5
  • Certifications a plus but not required: AWS Security Specialty, OSCP, CKS, CEH
What We Offer
  • Competitive salary and benefits package
  • Equity in a rapidly growing company
  • Opportunity to work in a fast-paced startup at the forefront of fintech innovation
  • A real growth path — this role is designed to develop you into an L3 specialist
  • Collaborative work culture with emphasis on personal and professional growth

We are committed to building a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Skills Required

  • 2-4 years hands-on experience in Application Security, Cloud Security, or a closely related role
  • Solid grounding in security fundamentals: OWASP Top 10, TLS/PKI, OAuth/JWT, common cloud attack patterns
  • Hands-on exposure to both AppSec (at least one of SAST/DAST/manual review) and CloudSec (at least one of AWS/GCP/Azure)
  • Scripting ability in Python, Go, or Bash to build internal tools and automation
  • Clear communication skills to translate findings into actionable developer guidance
  • Willingness to participate in InfoSec on-call rotation and incident response
  • Degree or equivalent experience in Computer Science, Information Security, or similar
  • Exposure to Kubernetes in production
  • Familiarity with Infrastructure as Code (Terraform) and security enforcement in IaC
  • Bug bounty, CTF, or open-source security contributions
  • Security certifications (AWS Security Specialty, OSCP, CKS, CEH)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, New York
15 Employees
Year Founded: 2024

What We Do

OpenFX is redefining the future of global money movement. We enable money to flow across borders as effortlessly as data, unbound by time zones, legacy systems, or banking hours. Our FX infrastructure transforms how finance teams operate, delivering cross-border transfers with industry-leading spreads, real-time settlement and 24/7 availability. We are a team of serial entrepreneurs from Affirm, BofA, Charles Schwab, Goldman Sachs, Intuit, JPM, Kraken, Microsoft, Meta, PayPal, Slack.

Similar Jobs

Atlassian Logo Atlassian

Data Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Atlassian Logo Atlassian

Principal Software Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Motive Logo Motive

Human Resource Business Partner

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
4000 Employees

Expedia Group Logo Expedia Group

Data Engineer

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
16000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account