
Real job — pulled straight from Spyne’s careers page · Verified July 13, 2026 · No reposts.
Job description
Spyne is hiring a Information Security Engineer — a full-time, based in Gurugram, India role. Apply directly on Spyne's careers page below.
Infosec Engineer
Location: Gurugram, India
Department: Technology
Who are we?
- 2020: Launched as a visual merchandising platform
- 2023: Pivoted to AI-driven automotive retail solutions
- 2024: Achieved 5× revenue growth in 15 months, aiming for 3–4× more
- Today: Driving the GenAI revolution with AI-powered sourcing, pricing, CRM, and Agentic AI for dealerships
- Studio AI Product
- Vini AI Product
- Series A Announcement on YourStory
- Series A Coverage in Economic Times
- Autocar Pro News
What Are We Looking For?
What Will You Do?
- AI & LLM Security: Secure conversational agents (Vini AI) against prompt injection and data poisoning attacks; protect computer vision pipelines (Studio AI) from adversarial evasion techniques and model theft.
- Code Security: Establish secure coding guidelines and integrate automated vulnerability scanning (SAST/SCA) directly into developer workflows and CI/CD pipelines.
- API Security: Safeguard critical data pipelines and third-party CRM/DMS integrations (e.g., Tekion ARC) against unauthorized access, broken object-level authorization, and business logic abuse.
- Application Security: Protect our Web App (Virtual Studio, Developer Hub) and Android/iOS mobile applications against reverse engineering, unauthorized access, and runtime exploits.
- VAPT & Penetration Testing: Own and manage continuous offensive security testing—both automated vulnerability assessments and manual penetration tests—across the full product suite.
- Compliance & Governance: Lead alignment with global data privacy regulations (GDPR, CCPA) and automotive industry security standards to support seamless enterprise onboarding in the US and EU.
- Cross-Functional Security Enforcement: Partner with the DevOps team to define and enforce security requirements for cloud infrastructure; ensure deployment pipelines and AWS architectures meet rigorous security standards without hindering development velocity.
- Security Culture: Drive security awareness programs, conduct training sessions, and build a security-first mindset across all engineering disciplines.
- Incident Response: Define, document, and lead the execution of incident response playbooks; conduct post-mortems and drive remediation.
What You Must Have?
- Experience: 3-5 years in an information security or application security role, preferably within a SaaS or AI-first product company.
- AI/ML Security: Demonstrated knowledge of LLM attack vectors (prompt injection, jailbreaking, data exfiltration) and computer vision model threats (adversarial inputs, model inversion).
- Application Security: Strong hands-on experience with OWASP Top 10 (Web & Mobile), API security testing, and mobile app security (Android/iOS).
- SAST/DAST/SCA Tools: Proficiency with tools such as Semgrep, Snyk, Burp Suite, OWASP ZAP, or equivalents.
- VAPT: Proven experience conducting or managing penetration tests across web, mobile, and API surfaces; familiarity with frameworks like PTES or OWASP WSTG.
- Cloud Security: Working knowledge of AWS security services and best practices (IAM, Security Groups, GuardDuty, CloudTrail, KMS, Secrets Manager); ability to audit cloud architectures for risk.
- Compliance: Practical experience with GDPR, CCPA, and/or relevant industry frameworks (SOC 2, ISO 27001); experience supporting enterprise security reviews and third-party audits.
- Scripting & Automation: Proficient in Python, Bash, or similar scripting languages for security automation and tooling.
- Collaboration: Ability to work closely with developers, DevOps, ML engineers, and product managers—translating complex security requirements into actionable engineering tasks without blocking velocity.
- Education: Bachelor's or master's degree in Computer Science, Information Security, or a related field. Relevant certifications (OSCP, CEH, CISSP, AWS Security Specialty) are a strong plus.
Why is Spyne an Employee-Centric Company? 🚀
- Comprehensive Health & Life Coverage – GMC, GPA, and GTLI benefits for you and your family
- Performance-Driven Growth – Fast career progression, ownership from Day 1, and stock options for top performers
- Elevate Learning & Development – Access LinkedIn Learning, mentorship programs, and hands-on AI security projects to upskill daily
- Collaborative Office Culture – Thrive in our energetic, innovation-first workplace
Why Spyne?
- Strong Culture: A supportive, transparent environment with high autonomy
- Competitive Compensation: Market-leading salary, equity, and benefits
- Dynamic Growth: Join us at a pivotal growth stage—shape our security posture, processes, and future
- Cutting-Edge Tech: Work on real-world AI/ML and GenAI security challenges that very few engineers get to tackle
Get Security Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for Information Security Engineer at Spyne?
The required skills for Information Security Engineer at Spyne include: AWS, Python, Bash, GDPR, CI/CD, IAM, SOC 2, ISO 27001, CISSP.
What is the seniority level for Information Security Engineer at Spyne?
Information Security Engineer at Spyne is a Mid Level / Senior level position.
How do I apply for Information Security Engineer at Spyne?
You can view the full description and apply for Information Security Engineer at Spyne on EchoJobs: https://echojobs.io/job/spyne-infosec-engineer-6yylm.