Senior Security Engineer- Java Security Engineer/intelligence

Toast Toast · Enterprise · Bangalore, India · R & D : Security : Cybersecurity

Senior Security Engineer role at Toast, focusing on actionable intelligence collection, analysis, and delivery to engineers, and hunting adversaries. The role involves selecting, implementing, designing, and building services and tools for security intelligence, triaging vulnerabilities, improving developer tooling for SSDLC, assisting incident response, threat modeling, and guiding architecture. Requires experience in security engineering, Java web services, Python scripting, and leveraging LLM AI features. Fintech application experience is required.

What you'd actually do

  1. Select, implement, design, and build services and tools to manage and deliver security intelligence across Toast platforms.
  2. Identify, triage, and provide remediation guidance for application vulnerabilities, with a specific focus on anti-abuse activities.
  3. Improve developer tooling and adoption to build a more robust SSDLC which integrates security and anti-abuse features.
  4. Practice a #OneTeam attitude to help other Toast teams make informed, security-conscious decisions when building new public-facing software.
  5. Assist incident response teams with application security expertise and tools, especially related to abuse and fraud.

Skills

Required

  • security engineering
  • Java web services
  • Python scripting
  • LLM AI features
  • cloud application architecture
  • fintech applications
  • privacy
  • security
  • cryptography patterns

Nice to have

  • Offensive security training and certifications (e.g. OSCP, OSWE, OSEP)
  • Edge Security solution like WAF, API Security
  • Adversary Emulation proficiency (red/purple teaming)
  • Cloud and container security technologies
  • SSDLC tooling (e.g., SAST/DAST/SCA)
  • Scaled data handling in RDBMS, streaming, and columnar stores
  • Metrics and charting software proficiency
  • Mobile apps/threats (iOS, Android), and their particular abuse vectors
  • Knowledge in security of operating systems, networking and protocols
  • Securing financial technologies and associated requirements

What the JD emphasized

  • Minimum 5+ years of experience in security engineering.
  • Experience building and maintaining scaled Java web services in production.
  • Experience developing script applications in Python for scheduling and backend data handling.
  • Experience leveraging LLM AI features for software development and/or security operations.
  • Previous security experience working with fintech applications and associated requirements.