
Real job — pulled straight from Bazaarvoice’s careers page · Verified July 20, 2026 · No reposts.
Job description
Bazaarvoice is hiring a Senior Offensive Security Engineer — a full-time, based in Bengaluru role. Apply directly on Bazaarvoice's careers page below.
Senior Offensive Security Engineer(Cloud Operations)
Team: Security
Location: Bengaluru
Commitment: Full-time
Workplace Type: hybrid
We are looking for a Senior Offensive Security Engineer who is a "Jack of all trades, Master of some." You don’t need to be a world-class Red Teamer AND a Cloud Architect; rather, you need a solid foundation in offensive security, operational experience in cloud platforms (AWS/GCP) and the maturity to manage our external penetration testing and bug bounty programs. As a leader within our proactive security strategy, you will drive the identification of complex vulnerabilities through expert management of third-party tests and by leading sophisticated, in-depth internal assessments of our cloud infrastructure. You will operate with a high degree of autonomy, tackling significant security challenges while mentoring others to influence strategy across the organization.
Shift Hours: This position will have working hours of 1:00 PM to 10:00 PM IST (Indian Standard Time) and will allow for a mixture of in-office and work from home.
What You'll Be Doing:
-
Lead Offensive Security Engagements: Own and execute complex, end-to-end internal penetration tests against Bazaarvoice's most critical applications, infrastructure, and cloud environments. You will simulate advanced, multi-stage attack scenarios to uncover systemic security weaknesses before they can be exploited.
-
Program and Tooling Enhancement: Take a lead role in defining the strategy for our offensive security capabilities. You will research, prototype, and implement new tools, techniques, and automation to mature our testing processes and keep pace with the evolving threat landscape.
-
Strategic Third-Party Penetration Test Management: Act as the primary technical lead for our third-party penetration testing program. You will not only manage the engagement lifecycle but also define the strategic direction of our testing roadmap, ensuring we partner with providers to target the highest-risk areas of our business.
-
Bug Bounty Program Leadership: Design, lead, and operate all aspects of our bug bounty program, serving as the technical interface for third-party researchers and coordinating internal responses to submitted vulnerability findings, ensuring clear communication and timely resolution.
-
Mentorship and Technical Leadership: Mentor junior team members and act as a security champion and trusted advisor to engineering teams. You will elevate the security knowledge across the organization by leading training sessions, developing secure coding guidelines, and providing expert consultation on secure architecture.
-
Threat Modeling: Proactively engage with development teams early in the SDLC to conduct threat modeling exercises, helping them build more secure products from the ground up.
Required Skills and Experience:
-
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience with 10+ years of related experience.
-
7+ years of hands-on experience in offensive security, with a strong background in penetration testing, red teaming, or application security.
-
Operational Cloud Expertise: 3-5 years of hands-on experience operating in, managing, or performing manual penetration tests of cloud infrastructure (AWS preferred), with a deep understanding of cloud-native attack vectors (e.g., IAM exploitation, container escapes, and serverless security).
-
Expert-level knowledge in managing the lifecycle of penetration testing engagements and a proven track record of driving remediation efforts in a complex, multi-team environment.
-
Deep and practical understanding of common and advanced vulnerability classes (OWASP Top 10 and beyond) and the ability to architect solutions to remediate them at scale.
-
High proficiency in one or more scripting languages (e.g., Python, Go, Bash) for advanced tool development and automation of complex tasks.
-
Exceptional communication and interpersonal skills, with a demonstrated ability to influence technical and non-technical stakeholders at all levels, including senior leadership.
-
A proven history of mentorship and a passion for elevating the skills of those around you.
Desired Skills and Experience:
-
Advanced offensive security certifications such as OSCP, OSWE, OSEP, GPEN, GXPN, or equivalent.
-
Deep expertise in AWS cloud security operations and infrastructure-as-code security.
-
Experience building and maturing an offensive security program or function.
-
Demonstrated experience leading red team or purple team exercises.
-
Published security research, conference presentations, or active contributions to the open-source security community.
- Experience in a Security Development Lifecycle (SDL) environment and a history of implementing DevSecOps principles.
Why You’ll Love Working with Us?Work with cutting-edge tech in an innovative, collaborative environment.Competitive salary + good benefits (insurance, annual leave, bonuses, referral rewards, and more).We’reGreat Place to Work Certified (3 years in a row!).Hybrid work model (3 days in office – Prestige Tech Pacific, Kadubeesanahalli).Interview Process:Tech Round 1Tech Round 2Hiring Manager Meeting: Team, values & culture check.Final Round: Chat with HR/Senior Leadership.Ready to take on the challenge? Apply now!
Get Penetration Tester jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs



Frequently asked questions
What skills are required for Senior Offensive Security Engineer at Bazaarvoice?
The required skills for Senior Offensive Security Engineer at Bazaarvoice include: AWS, GCP, IAM, Python, Go, Bash, DevSecOps.
What is the seniority level for Senior Offensive Security Engineer at Bazaarvoice?
Senior Offensive Security Engineer at Bazaarvoice is a Senior / Staff level position.
How do I apply for Senior Offensive Security Engineer at Bazaarvoice?
You can view the full description and apply for Senior Offensive Security Engineer at Bazaarvoice on EchoJobs: https://echojobs.io/job/bazaarvoice-senior-offensive-security-engineer-cloud-operations-v8u2m.