
Senior Security Engineer
Chargebee · Posted Oct 6
Subscription management, recurring billing, and revenue growth infrastructure services
Get a personal compatibility score
Add a resume for personal matches
About the role
Chargebee is a subscription billing and revenue management platform powering SaaS and subscription-first businesses, with 500+ team members working remotely across four continents. The role operates at a cross section of cloud infrastructure and product engineering in a data-intensive environment using AWS and Azure stacks. The Senior Security Engineer will perform manual penetration testing and DAST across web applications and APIs, conduct AI red teaming on GenAI features such as LLM applications and MCP servers, triage SAST and SCA findings, and build security automation.
What you will do
- Perform manual penetration testing and automated dynamic application security testing (DAST) across web applications and APIs.
- Understand application architecture, business workflows, authentication, authorization, and data flows to define testing scope and identify attack paths.
- Assess business logic flaws, access control weaknesses, injection vulnerabilities, and other application security risks.
- Develop reproducible proofs of concept and document findings with clear business impact, risk assessments, and actionable remediation guidance.
- Work with engineering teams to drive remediation and retest fixes to confirm closure.
- Retest fixed vulnerabilities to confirm effective remediation and close the finding
- Support external VA/PT engagements and responsible disclosure investigations by reproducing findings, assessing impact, and validating fixes
- Conduct adversarial testing of GenAI-powered features, including LLM applications, agentic workflows, and MCP servers and integrations.
- Test for prompt injection, sensitive data disclosure, unauthorized tool invocation, and misuse of connected tools or data sources.
- Assess authentication, authorization, trust boundaries, and data access across AI components, backend services, and MCP integrations.
- Develop repeatable attack scenarios and test cases based on relevant OWASP guidance and internal security playbooks.
- Collaborate with engineering teams to validate guardrails and verify remediation of AI security findings.
- Analyze and triage findings from SAST and SCA tools to support secure development.
- Collaborate with developers to prioritise and fix vulnerabilities.
- Collaborate with developers, understand the codebase and guide on secure coding practices
- Build scripts and reusable tooling to improve testing coverage, repeatability, and efficiency.
- Integrate dynamic security testing into development and release workflows.
- Support application security incident investigations through targeted testing and attack-path analysis.
- Maintain testing methodologies, playbooks, and high-quality technical documentation.
Skills used in this role
What the employer is looking for
- 3+ years of product security experience, with substantial hands-on experience in manual web application and API penetration testing.
- Strong understanding of application vulnerabilities and remediation, including authentication, authorization, business logic, and OWASP Web and API Top 10 risks.
- Proficiency with tools such as Burp Suite, OWASP ZAP, and Postman.
- Experience configuring authenticated DAST scans and validating automated findings.
- Ability to independently scope and execute assessments, develop proofs of concept, explain exploitability and business impact, and retest fixes.
- Working knowledge of Python, JavaScript, or a similar language for security testing and automation.
- Ability to read application code to investigate vulnerabilities and provide practical remediation guidance.
- Foundational understanding of LLM and agentic application security, including prompt injection, tool access, and data exposure risks, with a strong interest in developing hands-on AI red teaming expertise.
- Strong written and verbal communication skills, including clear security reports and effective collaboration with developers.
- Ability to journal & create high quality wiki documentation for related work.
- Experience working in Agile environments using Jira and Confluence or equivalent tools.
Preferred qualifications
- Domain experience in payments / banking / platform based products.
- Hands-on experience in AI red teaming or security testing of LLM applications, agentic systems, or MCP servers and integrations.
- Familiarity with OWASP guidance for GenAI and agentic application security.
- Familiarity with AWS or Azure environments and their application security implications.
- Certifications such as OSCP, OSWE, GPEN, or equivalent.
Benefits and support
- Compensation and benefits are detailed in the job posting
About Chargebee
Chargebee is a subscription management and recurring billing platform that automates revenue operations, invoicing, payments, and compliance for high-growth businesses. Its platform helps enterprises manage complex subscription lifecycles, usage-based pricing, and global tax configurations. Trusted by thousands of global innovators, Chargebee streamlines financial workflows from early-stage operations to multi-year enterprise contracts.
- Industry
- SaaS
- Company size
- 1000-5000 employees
- Founded
- 2011
- Location
- San Francisco, California, USA
- Funding stage
- Series H
Funding
Series H · $475M raised
- 2024-03-08Series H$5M
- 2022-02-01Series H$250M
- 2021-04-01Series G$125M
- 2020-10-01Series F$55M
- 2019-08-01Series D$14M
- 2018-03-01Series C$18M
Leadership
CEO & Co-Founder
CPO & Co-Founder
CTO & Co-Founder
Chief Financial Officer
Recent coverage
GlobeNewswire
Chargebee Named a Leader in 2026 Gartner® Magic Quadrant™ for Recurring Billing Applications for the Third Consecutive Year2026-08-17
Chargebee News
Chargebee and Twikey Partner to Connect Billing Directly With Bank Payments2026-07-15
Chargebee News
Agicap Selects Chargebee to Power Its Next Phase of Global Growth2026-03-10
Chargebee News
Chargebee Acquires Inai to Supercharge AI-Powered Payments Intelligence2025-09-15