Apply Edge Start your job search

Cyber Security Engineer

Recrew AI · Gurugram, Haryana, India

Apply & track with Apply Edge

Role: Cybersecurity EngineerFunction: Cybersecurity / Information Security

Location: Kolkata / GurugramType: Full-timeIndustry: AI, Medical SaaS, Dental TechnologyAbout CompanyThe company builds AI-powered SaaS for the U.S. dental market.Its platform unifies analytics, scheduling, communications, payments, and marketing automation.

Thousands of dental practices rely on it daily.It handles protected health information at scale, making security a core product requirement — not a compliance checkbox. Founded in 2015, the team is mission-driven, execution-oriented, and moves fast.Position OverviewAs a Cybersecurity Engineer, you will own the security posture of the company's AWS cloud infrastructure and its Python/Django, FastAPI, Node.js, and React applications. You will find real vulnerabilities, fix them or drive them to closure, and build the controls and automation that prevent the same class of issue from recurring. This is a hands-on, technical role. You will read code, review architecture, run tests against live systems, tune detections, respond to incidents, and carry the technical side of HIPAA and SOC 2 obligations — working directly with engineering rather than filing findings over a wall.Role & ResponsibilitiesPerform secure code reviews across Python/Django/FastAPI, Node.js, and React/TypeScript codebases; threat-model new features and services to identify design-level risks before they ship.Own SAST, DAST, dependency, secret, and container scanning — including triage, false-positive reduction, and driving fixes to closure.Run white-box (source-assisted), grey-box (authenticated, partial-knowledge), and black-box (external, zero-knowledge) security testing against applications and APIs; test authentication, authorization, multi-tenant isolation, and session handling; hunt for IDOR, privilege escalation, and tenant data leakage.Harden AWS infrastructure — IAM least privilege, VPC and network segmentation, security groups, encryption at rest and in transit, S3 and RDS controls; review Terraform and infrastructure-as-code for security defects and add policy-as-code guardrails.Secure containerized workloads (Docker, ECS/Fargate or EKS) — image hygiene, runtime configuration, secrets handling; own secrets management practices (AWS Secrets Manager, SOPS, Vault) and key rotation.Build and tune detection and alerting across cloud, application, and access logs; lead incident response — containment, forensics, root cause, and blameless post-incident review; run vulnerability management end to end: discovery, risk-based prioritization, SLA tracking, and verification.Own the engineering side of HIPAA and SOC 2 — implement controls, produce evidence, support audits, maintain audit logging, access review, data retention, and encryption controls; embed security checks into CI/CD (GitHub Actions) and write Python and shell automation for evidence collection, configuration auditing, and remediation.Must Have CriteriaBachelor's or Master's degree in Computer Science, Information Security, or a related discipline.6+ years in cybersecurity, with substantial application security or cloud security ownership.Strong AWS security experience — IAM, VPC networking, encryption, logging, and common misconfiguration patterns.Ability to read and reason about production code; Python strongly preferred, plus JavaScript/TypeScript.Hands-on web application and API security testing (OWASP Top 10, OWASP API Security Top 10) using black-box, grey-box, and white-box approaches.Practical experience with SAST/DAST/SCA and container scanning tooling, including triage and remediation.Working knowledge of Docker and container orchestration (ECS/Fargate or EKS).Experience with vulnerability management and incident response in production environments.Familiarity with HIPAA, SOC 2, or equivalent compliance frameworks.Nice to HaveSecurity certifications — OSCP, CISSP, AWS Security Specialty, GIAC (GWAPT, GCIH, GCSA), or CEH.Experience securing multi-tenant SaaS platforms and tenant-isolation models.Prior experience carrying a SOC 2 Type II audit or HIPAA program through to completion.Offensive security background — black-box penetration testing, red teaming, or bug bounty experience.Experience scoping and managing third-party black-box or grey-box penetration tests.Kubernetes security.Experience with event-driven architectures and message-broker security.Detection-as-code and security automation at scale.Exposure to healthcare technology or other regulated domains.Experience securing AI/LLM-integrated applications.What We OfferSecurity ownership of a healthcare platform where the stakes are real.Breadth across application, cloud, and operational security in one role.Modern stack: AWS, Terraform, GitHub Actions, Docker, Python, React, PostgreSQL, Kafka-compatible messaging.Direct influence on architecture and engineering practice — not a downstream audit function.