
Real job — pulled straight from Evolve’s careers page · Verified July 13, 2026 · No reposts.
Job description
Evolve is hiring a Product Security Engineer — a full-time, based in Bengaluru, India role. Apply directly on Evolve's careers page below.
Product Security Engineer
Location: Bengaluru, India
Department: Engineering
Experience: 3 - 7
Skills: security engineer, AWS
About Zenskar
Funding
The Problem We're Solving
What Customers Say
"We're saving 200+ hours/quarter on invoicing and receivables by completely automating our recurring billing."
- Noy Kalansky, Finance Controller, Pontera
"Zenskar automates revenue recognition accurately for our value-based billing: agents reducing manual hours by 70%."
- Matt Barnard, VP Finance, Vertice
"Zenskar’s agents automated 90% of our billing, integrated with our CRM, and accelerated revenue collection by a month."
- Ming Lui, VP Finance, Yembo
"Sardine had spent 4 years running billing in-house for high-volume, usage-based pricing. Zenskar took care of it all."
- Sardine team
"We launched our product 4 months faster instead of building an in-house system for our usage-based pricing."
- Kshitij Gupta, CEO, 100ms
About the role
What you'll do
- Threat model the paths that matter before code exists: webhook receivers, integrations, and AI agent access to customer data. Turn a feature into trust boundaries, actors, abuse cases and an authorisation model, and name what must never cross a tenant line
- Find real, exploitable bugs in real code (broken authorisation, IDOR, injection, SSRF, replay, races on money paths), write the request that proves it, and separate it from scanner noise
- Treat tenant isolation as a system property, not a filter someone remembered to add. Know where it silently degrades (caches, exports, analytics paths, background jobs) and build a way to prove it still holds
- Own the lifecycle of third-party credentials we store on customers' behalf: encryption, rotation, blast-radius limits, and detection when a credential is misused
- Tighten AWS IAM, network boundaries, secrets and CI/CD, and add guardrails such as policy checks in CI so a class of issue can't ship again. We do not want good intentions; we want reliable mechanisms
- Own identity and access end to end: session lifecycle, token issue and revoke, SSO and SCIM, service-to-service auth, API keys and their rotation, and the authorisation model behind them
- Lead security incidents. Build the logging and detections that let us find out sooner, and run a postmortem that actually changes something
- Decide what not to fix this quarter, and record the decision with an owner, a rationale and a date instead of leaving it in a backlog nobody reads
- Change how engineers work without any authority to make them: secure defaults, design reviews that engineers seek out rather than route around
- Carry SOC 2 Type 2 and ISO 27001 through real audit cycles: control design, evidence, auditor Q&A, and remediation of findings. Build controls that produce evidence, not quarterly screenshots
- Handle customer security reviews, DPAs and subprocessor lists with Sales, Customer Success, Legal and Finance, whose incentives genuinely differ from security's, without putting anything untrue on a questionnaire
- Stay current through real people and sources, and tie a recent shift in the threat landscape to a decision you actually changed
Who you are
- 3 to 7 years of experience in product or application security, with real, first-person evidence for everything below
- Turn a feature into trust boundaries, actors, abuse cases and an authorisation model, and review designs before code exists
- Have found real exploitable bugs and can write the request that proves it, and can tell a scanner finding from something an attacker can actually use
- Reason about tenant boundaries as a first-class property, and know where isolation silently degrades. Comfortable with data classification, encryption, key management, retention and deletion
- Have personally implemented and lived with least privilege in AWS, across IAM, network boundaries, secrets, and CI/CD and supply chain integrity
- Can reason about an authorisation model, not just an authentication one: token lifecycle, SSO and SCIM, service-to-service auth, API key rotation
- Have led a real security incident, know what would have had to be logged to find out sooner, and ran a postmortem that changed something
- Have decided what not to fix and recorded it with an owner, a rationale and a date, and have formally accepted a risk and can say what it cost
- Can name an engineer whose default behaviour changed because of you, and something you stopped or reshaped without escalating to get it stopped, that stayed stopped
- Have carried SOC 2, ISO 27001 or an equivalent through a real audit cycle, including at least one finding you had to remediate, and know the difference between a control that exists and one that produces evidence
- Have handled security questionnaires, DPAs or prospect security reviews, and unblocked a deal without saying anything untrue
- Follow specific people, sources and communities, and can name a recent shift and a decision of yours that changed because of it
You should not apply if
- Your security experience is entirely corporate IT (endpoints, helpdesk, device fleet)
- You want a policy-only role and don't want to read and write code
- You want to manage a team, now or in your first year
- You need final risk-acceptance authority. The CISO signs accepted risk; you produce the decision, the evidence and the recommendation
- You'd rather stay quiet than tell a colleague, a manager or a founder that something they own is broken
Good to have
- Offensive security background or a pentest certification (OSCP or similar)
- Experience as the first or only security hire
- Authorship of secure-by-default tooling or libraries
- Forensics depth
- Fintech, billing or payments exposure, or experience handling financial data
- Not taking yourself too seriously :)
Location
- Hybrid - 3 days per week
- Office Location: Indiranagar, Bengaluru.
- Address: 3rd Floor, A wing No 1, Carlton Towers, HAL Old Airport Rd, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008.
Interview process
- R0, Recruiter screen (30 min): Fit, motivation, and a quick check for real, specific experience behind your background across incidents, risk decisions, influence, compliance, customer security reviews and staying current. We recommend reviewing the job description and Apurv's recorded videos before this step.
- R1, Adversarial review: code and configuration (60 min): A small, Zenskar-shaped service and the cloud configuration it runs on. You find what's exploitable in each, rank it by blast radius, show the request or call that proves it, and fix it. No AI assistance in this round.
- R2, Threat modelling and secure design (60 min): A deliberately underspecified access problem. You design the trust boundary, authorisation model and credential lifecycle, then reason about a real, resolved Zenskar architecture decision.
- R3, Security operations, compliance and risk (60 min): A real incident you led, an audit you carried end to end, how you decide what not to fix, and a customer review where the honest answer was going to cost the deal. Come ready to walk through one incident in detail, including the timeline.
- R4, Bar raiser (60 min): Influence without authority, values, judgment, and a deeper probe on whatever came through thinnest earlier in the process.
- Reference Checks: We request contact details of two former direct managers. We'll ask them about a time you told the business no, and whether it held.
Get Security Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs
Frequently asked questions
What skills are required for Product Security Engineer at Evolve?
The required skills for Product Security Engineer at Evolve include: AWS, DevSecOps, CI/CD, SOC 2, GDPR, ISO 27001, CISSP.
What is the seniority level for Product Security Engineer at Evolve?
Product Security Engineer at Evolve is a Mid Level / Senior level position.
How do I apply for Product Security Engineer at Evolve?
You can view the full description and apply for Product Security Engineer at Evolve on EchoJobs: https://echojobs.io/job/zenskar-product-security-engineer-zd9x7.

