Sun King Logo

Sun King

Application Security Engineer

Posted 16 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in India
Junior
Remote
Hiring Remotely in India
Junior
Own application security across mobile apps, APIs, microservices, cloud infrastructure, AI products, and third-party integrations. Responsibilities include threat modeling, architecture reviews, penetration testing, secure coding, vulnerability management, incident response, SSDLC onboarding, CI/CD security tool integration, cloud hardening, developer training, and communicating risk. The role also assesses AI and LLM security risks and develops production guardrails and automation.
The summary above was generated by AI
Job location: Remote

About the role:
We are looking for an Application Security Engineer to own the end-to-end security posture of our
product platform — spanning mobile applications, REST APIs, microservices, cloud infrastructure, and
third-party integrations. In this role, the Application Security Engineer will be involved into the
product and engineering lifecycle early, shaping secure design decisions before code is written, and
validating them through rigorous assessment.


What you will be expected to do
● Own application security responsibility for assigned business functions by performing threat
modeling, architecture reviews, penetration testing, secure coding programs, and vulnerability
management.
● Perform manual penetration testing and vulnerability assessments on web applications, APIs,
and android mobile applications.
● Perform security reviews for AI‐native products, models, pipelines, and inference services.
● Onboard applications into the SSDLC program and be a security point of contact for the
application product.
● Own security incident response for product-layer issues, define remediation plans, and track
fixes through to closure.
● Integrate and tune SAST/DAST/IAST/SCA tools in CI/CD, create custom rules where needed and
actively triage false positives.
● Review and harden cloud infrastructure — Kubernetes RBAC, pod security, network policies,
Istio service mesh, Keycloak/OIDC configurations, and IAM across AWS, DigitalOcean, GCP, and
Firebase.
● Communicate vulnerabilities and risk clearly to developers, product managers, and leadership
— in language that drives actionable results.
● Conduct application security training for engineers, product managers etc.



You might be a strong candidate if you have/are
●Bachelor's degree in Computer Science, Cyber Security, or any related fields.
● At least 2 years of hands-on application security experience, ideally in product‐based or SaaS
companies working directly with engineering teams.
● Good understanding of OWASP Top 10, API Security Top 10, and common authorization flaws
including BOLA, BFLA, and privilege escalation.
● Experience in manually testing web apps, APIs, and Android apps, manual code reviews
(beyond just running tools).
● Familiarity with OAuth2, OIDC, JWT, and typical misconfigurations in providers such as Keycloak
and Firebase.
● Experience integrating and tuning SAST/DAST (and optionally SCA/IAST) tools within CI/CD
pipelines.
● Exposure to cloud‐native security: Kubernetes, containers, service mesh (Istio mTLS and
policies), and IAM concepts across at least one major cloud provider.
● Experience with Cloudflare WAF, perimeter security scanning, and/or red‐team testing is a
plus.
● Familiarity with AI/LLM security risks (e.g., OWASP LLM Top 10).
● Practical experience implementing guardrails, prompt validation, output filtering, or other
safety controls in production AI features, or assessing insecure use of third‐party AI APIs.
● Ability to script/automate (e.g., Python, Bash) to streamline testing, data collection, and
reporting.
● Interest in or experience with building AI based security tools that improve coverage or reduce
manual toil.

What Sun King offers
  • Professional growth in a dynamic, rapidly expanding, high-social-impact industry
  • An open-minded, collaborative culture made up of enthusiastic colleagues who are driven by the challenge of innovation towards profound impact on people and the planet.
  • A truly multicultural experience: you will have the chance to work with and learn from people from different geographies, nationalities, and backgrounds.
  • Structured, tailored learning and development programs that help you become a better leader, manager, and professional through the Sun King Center for Leadership.

About
Sun King is the world’s leading off-grid solar energy company, combining cutting-edge product design, fintech, and field operations to deliver energy access for the 1.8 billion people who live without an affordable and reliable electric-grid connection.Sun King has built a new kind of energy utility: distributed, green, customer-centric, and affordable. We bring clean, reliable, decentralized energy directly into people’s lives — from solar kits that provide first-time energy access to multi-kilowatt systems that serve both off-grid users and grid-connected customers powering larger homes, schools, hospitals, farms, offices, and light manufacturing.Already, 25 million homes and businesses rely on Sun King for electricity supply and the appliances and services it enables: lighting, televisions, fans, refrigeration, and smartphones. Sun King combines energy generation, energy-efficient appliances, installation, and financing into one seamless offering. Think of it as a distributed utility, designed for wherever energy is needed and designed to scale with its users as incomes and energy needs grow.Sun King makes solar products affordable to low-income households and businesses via ‘pay-as-you-go’ (PAYG) purchase financing. Sun King installs solar after customers pay a small deposit. Customers then make small, manageable payments of as little as US $0.14 a day via mobile money or cash.Instead of paying for expensive, polluting, and health-damaging kerosene for lighting or diesel for power, customers unlock savings through accessing solar power and after one to two years of payments, customers own their solar equipment outright.Sun King collects payments digitally through mobile money systems and its 35,000 field agents — over 1 million payments each day. To date, Sun King has extended more than $1.4 billion in PAYG loans to customers.Sun King began by powering homes and businesses with solar systems delivered through PAYG financing. Now, we’re using the same model to make smartphones and clean cooking equipment affordable: helping households connect to the digital economy and transition from wood-based fuels to modern, sustainable alternatives.Sun King employs 3,500 full-time staff in 14 countries, with specialties spanning product design, data science, logistics, customer service, sales, software, operations, and more — all with a passion to serve off-grid families. Sun King is committed to gender diversity in the workplace. Women represent 42% of Sun King’s workforce.

Similar Jobs

Yesterday
Remote
Karpura, Bangalore, Karnataka, IND
Mid level
Mid level
Healthtech • Pharmaceutical • Manufacturing
Administer and enhance application security tools, execute and tune DAST scans for web applications and APIs, validate and prioritize vulnerabilities, eliminate false positives, and partner with development teams on remediation. Maintain vulnerability records, verify fixes, support compliance with security standards, and build solutions that present vulnerability and compliance data to leadership.
Top Skills: AWSAzureDastPostmanPythonQualys AppsecQualys VmRestful ApisSwaggerWebinspect
2 Days Ago
Remote
India
Senior level
Senior level
Edtech • Information Technology • Software
Identify, triage, and remediate vulnerabilities in web applications and proprietary software. Refactor .NET/C# code, implement secure coding standards, conduct code reviews, support secure SDLC practices, and assess SAST, DAST, penetration testing, and bug bounty findings. Monitor emerging threats and OWASP Top 10 updates while supporting compliance with FERPA, COPPA, GDPR, UK GDPR, and other data protection standards. The role is fully remote but requires permanent residency in India and specified IST working hours.
Top Skills: .NetAWSAzureC#DastGCPObject-Relational Mapping (Orm)Owasp Top 10Sast
17 Days Ago
Remote
India
Entry level
Entry level
Security • Cybersecurity
Curate, triage, validate, and assess vulnerability submissions for managed bug bounty programs. Evaluate validity, accuracy, and severity; communicate with clients and security researchers; escalate critical vulnerabilities through incident response; and contribute to tooling that improves the triage and validation process. The role requires strong application security knowledge, especially OWASP Top Ten vulnerabilities, and proficiency with security testing tools.
Top Skills: Burp SuiteKali LinuxNmapOwasp Top TenSqlmap

What you need to know about the Delhi Tech Scene

Delhi, India's capital city, is a place where tradition and progress co-exist. While Old Delhi is known for its rich history and bustling markets, New Delhi is defined by its modern architecture. It's clear the region places a strong emphasis on preserving its cultural heritage while embracing technological advancements, particularly in artificial intelligence, which plays a central role in shaping the city's tech landscape, fueled by investments in research and development.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account