Skip to main content
Zobhira
Home
Jobs
Zobhira
JobsTodayAbout
Zobhira

New job and contest openings, updated every morning on one searchable board.

Find work

  • All jobs
  • Fresher roles
  • Remote roles

Compete

  • Added today

Popular cities

  • Bengaluru, Karnataka, India
  • India
  • Chennai, Tamil Nadu, India
  • Hyderabad, Telangana, India
  • Pune Division, Maharashtra, India
  • Noida, Uttar Pradesh, India

Company

  • About
  • Contact
  • Privacy
  • Terms

Stay updated

One email a week with new roles.

Secure infrastructure
Free to use, no account needed to search

Board updated daily · © 2026 Zobhira. All rights reserved.

Privacy PolicyTerms of Service
Home / Jobs / Interactive Brokers

Security Engineer III

Interactive Brokers

Mumbai, Maharashtra, IndiaPosted 2 days ago
Interactive Brokers logo

Skill Required

FulltimeSecurity EngineerPythonCI/CDOWASP

Key highlights

  • Performance based annual bonus (cash and stocks)
  • 5-7 years in application security, DevSecOps, or a security engineering role with tooling focus
  • Hybrid working model (3 days office/week)
  • Proficiency in Python or Go strongly preferred

Role overview

Interactive Brokers Group, Inc. (NASDAQ: IBKR), a global financial services company and S&P 500 member, seeks an Application Security Engineer to build, tune, and scale security scanning infrastructure for its software delivery pipeline. This hands-on role focuses on owning SAST, DAST, and SCA tooling end-to-end, reducing false positives, and embedding security gates into CI/CD workflows. The ideal candidate will have a deep technical understanding of vulnerabilities and work in a complex, regulated environment to create a trusted, automated scanning program that engineers act upon.

Responsibilities

  • Own and operate static, dynamic, and software composition analysis scanning platforms across all engineering pipelines — onboarding new repositories, tuning rulesets, and maintaining coverage metrics
  • Build and maintain CI/CD security gates that enforce scan policies at pull request, merge, and release stages across engineering workflows
  • Write custom detection rules tailored to the organization's tech stack and threat model — covering vulnerability classes specific to the languages and frameworks in use
  • Triage and prioritize scan findings with a deep understanding of actual exploitability — distinguish true positives from noise, explain the real-world impact of each finding, and build suppression workflows that reduce false positive rates without creating blind spots
  • Develop automation to ticket, deduplicate, and route findings to the right engineering teams with enough context for developers to understand and act on them
  • Integrate dynamic scanning into pre-production environments with authenticated coverage — understanding what attack surface is actually reachable versus what scanners miss
  • Partner with engineering teams on remediation — provide exploit context, reproduce findings where necessary, and give concrete fix guidance grounded in how the vulnerability actually works
  • Support software composition analysis and dependency security programs — tying third-party vulnerabilities back to actual reachability and exploitability in the codebase rather than treating every CVE as equal severity
  • Contribute to the security champions program — help developers understand not just what is flagged but why it matters and how an attacker would use it
  • Run structured evaluations of new tooling and drive buy vs build decisions with documented PoC results

Requirements

  • 5-7 years in application security, DevSecOps, or a security engineering role with tooling focus
  • Strong foundational knowledge of how web application vulnerabilities work at a technical level — injection classes, broken authentication patterns, insecure deserialization, XXE, SSRF, IDOR, race conditions, and business logic flaws — not just awareness of their names
  • Ability to read a scan finding and independently reason about whether it is exploitable in context — understanding data flow, trust boundaries, and what an attacker would actually need to trigger it
  • Hands-on experience deploying and tuning SAST platforms — writing or modifying rules, understanding AST-based and dataflow analysis, and knowing where static analysis fundamentally cannot reach
  • Experience integrating security tooling into CI/CD pipelines and enforcing policy at key delivery gates
  • Proficiency in at least one scripting language — Python or Go strongly preferred — for automation and tooling development
  • Experience with DAST tooling in authenticated scan configurations — understanding what authenticated coverage requires and how session handling, CSRF tokens, and multi-step flows affect scan fidelity
  • Familiarity with SCA concepts — dependency graphs, transitive vulnerabilities, license risk, reachability analysis, and SBOM formats including CycloneDX and SPDX
  • Ability to read and reason about code across multiple languages

Nice to have

  • Development background — candidates who have written production code and personally addressed security vulnerabilities in a codebase bring a fundamentally different perspective to this role; they understand why developers make the choices they do, where fixes break things, and how to give remediation guidance that engineers will actually implement
  • Background that spans both sides of the SDLC — having sat in a developer role before moving into security means stronger partnerships with engineering teams and more credible guidance during code review and triage conversations
  • Experience writing custom detection logic for organization-specific vulnerability patterns beyond out-of-the-box scanner coverage

Benefits

  • Competitive salary package
  • Performance based annual bonus (cash and stocks)
  • Hybrid working model (3 days office/week)
  • Group Medical & Life Insurance
  • Modern offices with free amenities & fully stocked cafeterias
  • Monthly food card & company paid snacks
  • Hardship/shift allowance with company provided pickup & drop facility*
  • Attractive employee referral bonus
  • Frequent company sponsored team building events and outings

Additional details

  • Depending upon the shifts
  • The benefits package is subject to change at the management's discretion

Similar jobs open now

Hive logo
remote
Senior Software Developer
Hive
RemoteCAD 124000 - 188000
View details
Noora Health logo
Lead, Engineer
Noora Health
Bengaluru, KA, IN / Bengaluru, Karnataka, IN
View details
Noora Health logo
remote
Chief Technology Officer
Noora Health
Bengaluru, KA, IN / Bengaluru, Karnataka, IN / Remote
View details
Ooak Data logo
remote
Senior Software Engineer
Ooak Data
Paris, IDF, FR / Paris, Île-de-France, FREUR 55000 - 80000
View details
Apply now
LocationMumbai, Maharashtra, India
TypeFulltime
Posted7/31/2026
Apply byOpen

Links are checked every day. If this one stops working, tell us and we'll pull it.

More like this

View all
Hive logo
Senior Software Developer
Hive
Noora Health logo
Lead, Engineer
Noora Health
Noora Health logo
Chief Technology Officer
Noora Health
Apply now