Chargebee logo

Senior Security Engineer

Chargebee · Posted Oct 6

Subscription management, recurring billing, and revenue growth infrastructure services

Bengaluru, Karnataka, IndiaFull-timeRemote · India-wideSenior Level3+ years₹30.0L–₹45.0L yearly100+ applicants
SaaSBillingPaymentsSubscription ManagementFinTechRecurring BillingLate Stage
Full time

Get a personal compatibility score

Add a resume for personal matches

About the role

Chargebee is a subscription billing and revenue management platform powering SaaS and subscription-first businesses, with 500+ team members working remotely across four continents. The role operates at a cross section of cloud infrastructure and product engineering in a data-intensive environment using AWS and Azure stacks. The Senior Security Engineer will perform manual penetration testing and DAST across web applications and APIs, conduct AI red teaming on GenAI features such as LLM applications and MCP servers, triage SAST and SCA findings, and build security automation.

What you will do

  • Perform manual penetration testing and automated dynamic application security testing (DAST) across web applications and APIs.
  • Understand application architecture, business workflows, authentication, authorization, and data flows to define testing scope and identify attack paths.
  • Assess business logic flaws, access control weaknesses, injection vulnerabilities, and other application security risks.
  • Develop reproducible proofs of concept and document findings with clear business impact, risk assessments, and actionable remediation guidance.
  • Work with engineering teams to drive remediation and retest fixes to confirm closure.
  • Retest fixed vulnerabilities to confirm effective remediation and close the finding
  • Support external VA/PT engagements and responsible disclosure investigations by reproducing findings, assessing impact, and validating fixes
  • Conduct adversarial testing of GenAI-powered features, including LLM applications, agentic workflows, and MCP servers and integrations.
  • Test for prompt injection, sensitive data disclosure, unauthorized tool invocation, and misuse of connected tools or data sources.
  • Assess authentication, authorization, trust boundaries, and data access across AI components, backend services, and MCP integrations.
  • Develop repeatable attack scenarios and test cases based on relevant OWASP guidance and internal security playbooks.
  • Collaborate with engineering teams to validate guardrails and verify remediation of AI security findings.
  • Analyze and triage findings from SAST and SCA tools to support secure development.
  • Collaborate with developers to prioritise and fix vulnerabilities.
  • Collaborate with developers, understand the codebase and guide on secure coding practices
  • Build scripts and reusable tooling to improve testing coverage, repeatability, and efficiency.
  • Integrate dynamic security testing into development and release workflows.
  • Support application security incident investigations through targeted testing and attack-path analysis.
  • Maintain testing methodologies, playbooks, and high-quality technical documentation.

Skills used in this role

Penetration TestingDASTSASTSCAVulnerability AssessmentAI Red TeamingBurp SuiteOWASP ZAPPostmanPythonJavaScriptOWASPLLMMCPAWSAzureJiraConfluenceSecure Coding

What the employer is looking for

  • 3+ years of product security experience, with substantial hands-on experience in manual web application and API penetration testing.
  • Strong understanding of application vulnerabilities and remediation, including authentication, authorization, business logic, and OWASP Web and API Top 10 risks.
  • Proficiency with tools such as Burp Suite, OWASP ZAP, and Postman.
  • Experience configuring authenticated DAST scans and validating automated findings.
  • Ability to independently scope and execute assessments, develop proofs of concept, explain exploitability and business impact, and retest fixes.
  • Working knowledge of Python, JavaScript, or a similar language for security testing and automation.
  • Ability to read application code to investigate vulnerabilities and provide practical remediation guidance.
  • Foundational understanding of LLM and agentic application security, including prompt injection, tool access, and data exposure risks, with a strong interest in developing hands-on AI red teaming expertise.
  • Strong written and verbal communication skills, including clear security reports and effective collaboration with developers.
  • Ability to journal & create high quality wiki documentation for related work.
  • Experience working in Agile environments using Jira and Confluence or equivalent tools.

Preferred qualifications

  • Domain experience in payments / banking / platform based products.
  • Hands-on experience in AI red teaming or security testing of LLM applications, agentic systems, or MCP servers and integrations.
  • Familiarity with OWASP guidance for GenAI and agentic application security.
  • Familiarity with AWS or Azure environments and their application security implications.
  • Certifications such as OSCP, OSWE, GPEN, or equivalent.

Benefits and support

  • Compensation and benefits are detailed in the job posting

About Chargebee

Chargebee is a subscription management and recurring billing platform that automates revenue operations, invoicing, payments, and compliance for high-growth businesses. Its platform helps enterprises manage complex subscription lifecycles, usage-based pricing, and global tax configurations. Trusted by thousands of global innovators, Chargebee streamlines financial workflows from early-stage operations to multi-year enterprise contracts.

Industry
SaaS
Company size
1000-5000 employees
Founded
2011
Location
San Francisco, California, USA
Funding stage
Series H

Funding

Series H · $475M raised

Tiger Global ManagementInsight PartnersAccelSequoia CapitalSteadview CapitalFelicis Ventures
  • 2024-03-08Series H$5M
  • 2022-02-01Series H$250M
  • 2021-04-01Series G$125M
  • 2020-10-01Series F$55M
  • 2019-08-01Series D$14M
  • 2018-03-01Series C$18M

Leadership

KS
Krish Subramanian

CEO & Co-Founder

RS
Rajaraman Santhanam

CPO & Co-Founder

SK
Saravanan KP

CTO & Co-Founder

MB
Mike Beach

Chief Financial Officer