freehire launches on Product Hunt on 26 August.

Follow →

Founding Security Engineer (Product Security)

Open 16d

Summary

Build and own Seekho’s product security program: secure APIs, mobile apps, AI surfaces, and cloud infrastructure while automating SAST/DAST/SCA in CI/CD and running incident response.

Our first dedicated security hire. You will be an individual contributor building the function.

Seekho is built on one simple belief: make learning fun and easy for everyone.

We are India's #1 video edutainment platform, helping people learn real-world skills through short, expert-led videos across digital services, business, Spoken English, and much more. Founded in 2020 by IIT Kanpur alumni Rohit Choudhary, Keertay Agarwal and Yash Banwani, we are trusted by 4M+ paid subscribers and were ranked No. 2 in Google Play's Top Trending App 2025 list.

Your Role:

You'll own security across all of our products. With a large engineering team shipping daily, that means building secure defaults and tooling that scale rather than reviewing everything by hand — security that's automatic, continuous and owned. It's a high-ownership role with significant independence, and you'll succeed by partnering closely with engineering teams.

  1. Enforce server-side authorization; defend against account takeover, promo abuse, payment tampering, and content piracy.
  2. Secure our mobile and AI surfaces, and keep children's, health, and payment data least-privilege and audited.
  3. Make SAST, DAST, SCA and secret scanning default in CI/CD, and keep results trustworthy so engineers act on them.
  4. Own our cloud posture — VPCs, security groups, IAM, secrets management, and threat detection.
  5. Run vulnerability management — the VAPT cadence and a channel for outside researchers to report issues and see fixes through.
  6. Build security incident management end to end, detection to postmortem, against India's short breach-reporting clock.
  7. Build Seekho's security platform — the internal libraries and guardrails engineers build on.

Requirements

Must Have:

  1. 4+ years in security, with real depth in application and API security.
  2. You think in terms of how systems get exploited, not just vulnerability categories.
  3. You can explain an authorization flaw in unfamiliar code, and code in Python or Go to build tooling.
  4. Working knowledge of cloud security — IAM, secrets, network controls, and threat detection.
  5. You've found real vulnerabilities yourself — a bounty, a VAPT finding, a CVE, or in your own product.
  6. Practical incident management, detection through postmortem — you've worked a real incident, not just written the plan.
  7. You've owned security in-house for a shipping product, as the first or only security person.

Bonus:

  1. India's data-protection landscape (DPDP, SPDI/IT Act) and comfort partnering with legal/DPO
  2. Payments and subscription fraud, RBI autopay and tokenization;
  3. Children's-data obligations and Play Families / Apple Kids compliance;
  4. AI/LLM application security
  5. Exposure to ISO 27001 or SOC 2.

Benefits

Curious about life at Seekho?

We invite you to explore our Team & Culture page to learn more about our values, vibrant teams, and what makes working at Seekho a truly rewarding experience.

What this application asks

workable

First name, Last name, Email, Phone, Current State/UT, Current City/District, Marital Status, Expected CTC (in LPA) - e.g. If you earn 360000 per annum write "3.6", 1200000 per annum write "12" and if you are a fresher write 0, Resume, Current/Previous CTC (in LPA) - e.g. If you earn 360000 per annum write "3.6", 1200000 per annum write "12" and if you are a fresher write 0, How soon you can join?, Current/Previous Organization's Name, What is your preferred mode of working?, What is your preferred time to start the workday?, How frequently do you think you should be talking to the users (customers)?

  • Describe a vulnerability you found that a scanner would've missed. What was your PoC? written answer
  • Share an example of custom tooling you've written for testing. Why wasn't an existing tool enough? written answer
  • Tell us about a bug that led you into the cloud layer. What did you find? written answer
  • Have you tested an AI or LLM-powered feature? What did you find? written answer

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available