HighLevel
Posted 5mo ago

Lead Security Engineer (Cloud Security & Architecture)

HighLevel
India
RemoteFull Time
Responsibilities
  • perform testing
  • drive threat modeling
  • collaborate with infra
Requirements
  • 8+ years in application security
  • Security engineering, or penetration testing
  • Experience with threat modeling
  • Secure architecture reviews, and cloud security
Technical tools mentioned
Burp SuiteZAPSnykMetasploitSemgrepNode.jsJavaScriptGoPHP

Job description

About Us
HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses to elevate their digital presence and drive growth. We are proud to support a global and growing community of over 1 million businesses, comprised of agencies, consultants, and businesses of all sizes and industries. HighLevel empowers users  with all the tools needed to capture, nurture, and close new leads into repeat customers. As of mid 2025, HighLevel processes over 4 billion API hits and handles more than 2.5 billion message events every day. Our platform manages over 470 terabytes of data distributed across five databases, operates with a network of over 250 microservices, and supports over 1 million hostnames.
 
Our People
With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment. We are building more than software; we are building a global community rooted in creativity, collaboration, and impact. We take pride in cultivating a culture where innovation thrives, ideas are celebrated, and people come first, no matter where they call home.
 
Our Impact
As of mid 2025, our platform powers over 1.5 billion messages, helps generate over 200 million leads, and facilitates over 20 million conversations for the more than 1 million businesses we serve each month. Behind those numbers are real people growing their companies, connecting with customers, and making their mark - and we get to help make that happen.
 
Learn more about us on our YouTube Channel or Blog Posts


About Us
HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses to elevate their digital presence and drive growth. We are proud to support a global and growing community of over 1 million businesses, comprised of agencies, consultants, and businesses of all sizes and industries. HighLevel empowers users  with all the tools needed to capture, nurture, and close new leads into repeat customers. As of mid 2025, HighLevel processes over 4 billion API hits and handles more than 2.5 billion message events every day. Our platform manages over 470 terabytes of data distributed across five databases, operates with a network of over 250 microservices, and supports over 1 million hostnames.
 
Our People
With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment. We are building more than software; we are building a global community rooted in creativity, collaboration, and impact. We take pride in cultivating a culture where innovation thrives, ideas are celebrated, and people come first, no matter where they call home.
 
Our Impact
As of mid 2025, our platform powers over 1.5 billion messages, helps generate over 200 million leads, and facilitates over 20 million conversations for the more than 1 million businesses we serve each month. Behind those numbers are real people growing their companies, connecting with customers, and making their mark - and we get to help make that happen.
 
Learn more about us on our YouTube Channel or Blog Posts


About Us
HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses to elevate their digital presence and drive growth. We are proud to support a global and growing community of over 1 million businesses, comprised of agencies, consultants, and businesses of all sizes and industries. HighLevel empowers users  with all the tools needed to capture, nurture, and close new leads into repeat customers. As of mid 2025, HighLevel processes over 4 billion API hits and handles more than 2.5 billion message events every day. Our platform manages over 470 terabytes of data distributed across five databases, operates with a network of over 250 microservices, and supports over 1 million hostnames.
 
Our People
With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment. We are building more than software; we are building a global community rooted in creativity, collaboration, and impact. We take pride in cultivating a culture where innovation thrives, ideas are celebrated, and people come first, no matter where they call home.
 
Our Impact
As of mid 2025, our platform powers over 1.5 billion messages, helps generate over 200 million leads, and facilitates over 20 million conversations for the more than 1 million businesses we serve each month. Behind those numbers are real people growing their companies, connecting with customers, and making their mark - and we get to help make that happen.
 
Learn more about us on our YouTube Channel or Blog Posts


What You’ll Be Doing:
  • Demonstrated expertise in cloud security architecture across AWS/GCP/Azure, including designing secure, scalable cloud environments with a strong focus on identity, network security, encryption, and compliance best practices.
  • Extensive experience conducting security architecture reviews for distributed systems and cloud-native applications, identifying design risks early and recommending secure, scalable architectural patterns aligned with business and engineering goals.
  • Perform and lead manual and automated penetration testing across applications, APIs, and cloud services
  • Drive threat modeling and secure architecture reviews across app and infrastructure layers
  • Collaborate with Infra/DevOps on cloud network architecture, including VPC design, security groups, routing, and segmentation
  • Design and advise on cloud-native security controls — IAM hardening, role boundaries, secrets management, least privilege
  • Evaluate and improve Kubernetes and container security posture (runtime, image, and network layers)Implement secure-by-default patterns across SDLC, CI/CD, and Infrastructure-as-CodeMonitor emerging threats, CVEs, and vulnerabilities relevant to our stack (web, cloud, infra)
  • Influence internal security tooling, automation pipelines, and security review processes
  • Serve as a security advisor to engineering, SRE, and product teams across key projects


  • What You’ll Bring:
  • 8+ years of experience in Application Security, Product Security, or Cloud Security, with a strong focus on securing large-scale cloud-native applications.
  • Strong hands-on experience with threat modeling, secure architecture reviews, and pen testing
  • Familiar with OWASP Top 10, STRIDE, and modern security frameworks
  • Experience with tools like Burp Suite, ZAP, Snyk, Metasploit, Semgrep
  • Ability to read and analyze code (e.g., JavaScript, Go, PHP, or Node.js)Working knowledge of cloud security principles (preferably AWS)


  • Preferred Qualifications
  • Experience with multi-tenant SaaS platforms or white-labeled architectures
  • Familiarity with network-level security concepts: VPC design, IAM, zero-trust networksExposure to container security (Docker, Kubernetes)
  • Background in B2B SaaS, especially servicing regulated industries (health, legal, finance)
  • Hands-on with IaC security and CI/CD pipelines (e.g., GitHub Actions, Terraform)


  • Equal Employment Opportunity Information
     
    The company is an Equal Opportunity Employer. As an employer subject to affirmative action regulations, we invite you to voluntarily provide the following demographic information. This information is used solely for compliance with government record keeping, reporting, and other legal requirements. Providing this information is voluntary and refusal to do so will not affect your application status. This data will be kept separate from your application and will not be used in the hiring decision.

    About HighLevel

    Provides an all-in-one sales and marketing automation platform.

    Year founded
    2018
    Employees
    1500
    Organization type
    Private
    Latest investment
    Raised $62.00M Private Equity (2024) — led by General Atlantic
    Headquarters
    US

    Similar jobs

    Lead Security Engineer roles
    5mo
    Save
    Mark Applied
    Hide
    Lead Security Engineer
    Bangalore, Karnataka, India
    HybridFull Time
    Huron
    HuronNasdaq: HURN: Professional services firm providing management consulting and digital transformation.
    Lead security engineer with expertise in AppSec, vulnerability management, and penetration testing using Tenable; guide secure coding and remediation.
    Tenable, Burp Suite, OWASP ZAP, Nmap, Metasploit, Python, Bash, PowerShell
    5mo
    Save
    Mark Applied
    Hide
    Lead Security Engineer
    Bengaluru, Karnataka, India
    OnsiteFull Time
    Amtech Software
    Amtech Software: Provides integrated enterprise software for packaging and manufacturing industries.
    10+ YOE8-12 years in security engineering; 5+ years securing AWS; IAM, encryption, logging; SOC 2/ISO 27001 experience; scripting and IaC.
    AWS, SIEM, EDR, Vulnerability Scanners, CSPM, Terraform
    6mo
    Save
    Mark Applied
    Hide
    Lead Security Engineer
    Pune, Maharashtra, India
    OnsiteFull Time
    Qualys
    QualysNASDAQ: QLYS: Provides cloud-based platform for cybersecurity and compliance management.
    5+ YOEBS in computer science with 5+3 years of InfoSec experience or MS in computer science or cyber security; knowledge of TCP/IP, HTTP, DNS, FTP, SSH, TLS/SSL, SMTP; vulnerability management and pen testing; scripting (Python, Bash); network analysis; regex; Windows/Unix admin; VPN/Firewalls/IDS; strong communication.
    Python, Bash, TCP/IP, HTTP, DNS, FTP, SSH, TLS/SSL, SMTP, Vulnerability scanners, IDS, Docker, Kubernetes, VMware, Cloud platforms (AWS, Azure), Linux, Windows
    7mo
    Save
    Mark Applied
    Hide
    Lead Security Engineer - Secure Web Gateway
    Mumbai or Hyderabad or Chennai or Bengaluru
    OnsiteFull Time
    IDFC First Bank
    IDFC First BankNational Stock Exchange of India / BSE Limited: IDFCFIRSTB / 539437: Provides universal banking and financial services to individuals and businesses.
    10+ YOESenior Network Security Engineer with 10+ years experience in Secure Web Gateway, SWG policies, and banking security standards.
    Netskope, SIEM, Secure Web Gateway, HTTP/HTTPS, SSL/TLS inspection, DNS, Web traffic analysis, DLP, SaaS security, IaaS security, PaaS security, ISO 27001, NIST, GDPR, Firewall, ZTNA, SASE, SSE, Identity providers
    1y
    Save
    Mark Applied
    Hide
    Lead Security Engineer
    India
    HybridFull Time
    Arcana Analytics
    Arcana Analytics: Platform for institutional portfolio risk and investment performance analytics.
    5+ YOE5+ years in security/compliance for cloud-native, fintech, and hybrid setups; strong GCP and Kubernetes security; IaC (Terraform); GitOps; Python; policy-as-code; strong communicator.
    Terraform, ArgoCD, Flux, Python, OPA, Gatekeeper, GCP, Kubernetes, KMS, VPC
    5mo
    Save
    Mark Applied
    Hide
    Lead AWS Security Engineer
    Chennai, Tamil Nadu, India
    HybridFull Time
    Hapag-Lloyd
    Hapag-LloydFrankfurt Stock Exchange: HLAG: Global container shipping and maritime logistics services provider.
    6+ YOE5-6 years tech experience; 3-5 years AWS cloud security operations; expert AWS security knowledge; cloud security tooling; AWS security services configuration; scripting; security automation; AWS certifications preferred.
    AWS, GuardDuty, Security Hub, CloudTrail, AWS Config, Inspector, Macie, EventBridge, Lambda, Step Functions, Cloud WAF, Bot Management Technologies, Python, Java, Ruby, Splunk, ELK
    5mo
    Save
    Mark Applied
    Hide
    Lead Cloud Security Engineer
    Bengaluru, Karnataka, India
    OnsiteFull Time
    InMobi
    InMobi: Mobile advertising and AI-powered content discovery platform.
    4+ YOE4-6 years in cloud security; hands-on Azure/AWS/GCP; Kubernetes, containers; CSPM; vulnerability and risk management; CI/CD security; infra as code; strong communication.
    Terraform, Kubernetes, Docker, Cloud Providers (Azure AWS GCP), CSPM, GKE, EKS, AKS, OpenID, OAuth, TLS, CI/CD, Network security
    6mo
    Save
    Mark Applied
    Hide
    Lead Cyber Security Engineer
    Gurugram, Haryana, India
    OnsiteFull Time
    FNZ
    FNZ: Provides an end-to-end wealth management platform for financial institutions.
    5+ YOE5+ years in cyber security; hands-on across multiple domains; proven technical lead; experience with enterprise IT and cloud; global teams.
    EDR, WAF, SIEM, Email security, Vulnerability management