Security Engineer
Software Engineering
Bengaluru, Karnataka, India
About KGeN
KGeN is building the Verified Distribution Protocol (VeriFi) for AI, DeFi, and Gaming - built on real users and real commerce to accelerate growth for projects across these industries.
Since its founding by global leaders in the consumer and gaming sectors, KGeN has grown to become the dominant growth engine in the Global South. With 45.7 million users, 6.7 million monthly active users, and $64 million in annualized revenue, KGeN delivers verified user acquisition, on-chain loyalty programs, and decentralized storefronts via its POGE, the identity and reputation framework and a global clan network spanning more than 60 countries.
The role
You'll partner with the Head of Security to run our recurring security audits and reviews — across applications, cloud, and infrastructure. This is a hands-on technical role: you find real risk, explain it clearly to the engineers who can fix it, and make sure it actually gets fixed. You'll have the room to shape how security reviews work here as we scale.
In your first few months
- Get up to speed on our application and cloud architecture and run your first end-to-end security review, from findings to tracked remediation.
- Establish a repeatable cadence for security and architecture reviews rather than one-off checks.
- Build a clear, prioritized view of our current vulnerabilities and drive down the ones that matter most.
What you'll do
- Run application and architecture security reviews across our products.
- Perform code and configuration reviews, penetration tests, and give engineering teams concrete, actionable feedback.
- Review our cloud security posture across AWS and Cloudflare — configuration, identity, network, and data controls.
- Run and coordinate VAPT — hands-on testing where it counts, managing external pentests where it makes sense, and triaging findings.
- Guide secure-SDLC practices — help teams build security in, not bolt it on.
- Own vulnerability management: track, prioritize, and drive remediation to closure.
- Threat-model new and existing systems to find weaknesses before attackers do.
- Support incident response when something needs investigating.
What you bring
- 3–7 years in security engineering or application security. (We're open on level — strong mid-career and senior candidates are both welcome.)
- Strong web and application security fundamentals (you know the OWASP Top 10 in practice, not just by name).
- Real cloud security depth in AWS and Cloudflare — deep in at least one, comfortable across both.
- Hands-on experience with SAST/DAST/VAPT tooling and manual testing — you don't rely on scanners alone.
- Comfort with threat modeling and reasoning about attacker behavior.
- Scripting ability (Python or similar) to automate and build your own tooling.
- The ability to explain risk clearly to engineers and get fixes shipped — influence without authority.
Bonus points
- Relevant certifications (OSCP, GWAPT, CCSP, or similar).
- Bug bounty, CTF, or independent security research experience.
- DevSecOps / secure-SDLC automation experience.
- Container and Kubernetes security.
Why join
You'll work directly with the Head of Security on real, high-impact security work with the autonomy to shape how we do reviews as we grow. If you like finding the risk that matters and actually seeing it fixed — not writing reports that gather dust — this is that role.
